bishopfox.com
Mass Exploitation of FortiManager Vulnerability CVE-2024-47575 Confirmed
Article Content
CVE-2024-47575, known as FortiJump, has been actively exploited since June 2024, affecting over 50 FortiManager devices across various industries. The vulnerability allows unauthorized control of FortiManager appliances, enabling threat actors to execute arbitrary commands and exfiltrate sensitive configuration data. Mandiant identified a threat cluster, UNC5820, responsible for these exploits, which included staging configuration files and user credentials. The first observed exploitation attempt occurred on June 27, 2024, with subsequent attempts noted in September 2024. Organizations with exposed FortiManager devices are urged to conduct forensic investigations immediately. The vulnerability was officially published on October 23, 2024, and is included in CISA's KEV list due to active exploitation.
Key Points: • CVE-2024-47575 allows unauthorized access to FortiManager devices. • Over 50 devices have been compromised, with sensitive data exfiltrated. • Mandiant tracks the exploiting group as UNC5820, active since June 2024.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.