bishopfox.com Mass Exploitation of FortiManager Vulnerability CVE-2024-47575 Confirmed
Article Content
- •CVE-2024-47575 allows unauthorized access to FortiManager devices.
- •Over 50 devices have been compromised, with sensitive data exfiltrated.
- •Mandiant tracks the exploiting group as UNC5820, active since June 2024.
CVE-2024-47575, known as FortiJump, has been actively exploited since June 2024, affecting over 50 FortiManager devices across various industries. The vulnerability allows unauthorized control of FortiManager appliances, enabling threat actors to execute arbitrary commands and exfiltrate sensitive configuration data. Mandiant identified a threat cluster, UNC5820, responsible for these exploits, which included staging configuration files and user credentials. The first observed exploitation attempt occurred on June 27, 2024, with subsequent attempts noted in September 2024. Organizations with exposed FortiManager devices are urged to conduct forensic investigations immediately. The vulnerability was officially published on October 23, 2024, and is included in CISA's KEV list due to active exploitation.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track UNC5820 and CVE-2024-23113 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
CISA Mandates Urgent Patching of Five Critical Flaws Exploited by Flax Typhoon The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch five critical vulnerabilities by October 11, 2026, following exploitation by the China-linked hacking group Flax Typhoon. The vulnerabilities, added to CISA's Known Exploited Vulnerabilities (KEV) catalog, include…