EXECUTIVE SUMMARY:
Researchers have identified and investigated the widespread exploitation of FortiManager appliances, with over 50 compromised devices observed across various industries. The vulnerability, tracked as CVE-2024-47575, enables threat actors to use an unauthorized, controlled FortiManager to execute arbitrary code, putting managed FortiGate devices at risk. Mandiant attributed this campaign to UNC5820, first observed exploiting FortiManager on June 27, 2024. Through this exploitation, UNC5820 accessed and exfiltrated detailed configuration data, including FortiOS256-hashed passwords and settings, from managed FortiGate devices. This data could enable UNC5820 to compromise FortiManager, move laterally to other Fortinet devices, and potentially infiltrate enterprise environments. Although Mandiant’s analysis didn’t detect evidence of further malicious activity, critical artifacts, including device identifiers and network connections, indicate a well-coordinated threat. Notably, UNC5820 registered its device in FortiManager’s Global Objects database, further embedding its presence within the environment. Forensic investigation revealed outbound traffic from FortiManager shortly after data staging, corroborating data exfiltration. Mandiant and Fortinet recommend immediate forensic analysis for organizations with internet-exposed FortiManager instances. Limiting FortiManager's access to authorized IP addresses and denying associations with unknown devices are essential steps to prevent further exploitation. As investigations continue, Fortinet has proactively notified customers, and Mandiant will update its findings as new data surfaces.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY:
Researchers have identified and investigated the widespread exploitation of FortiManager appliances, with over 50 compromised devices observed across various industries. The vulnerability, tracked as CVE-2024-47575, enables threat actors to use an unauthorized, controlled FortiManager to execute arbitrary code, putting managed FortiGate devices at risk. Mandiant attributed this campaign to UNC5820, first observed exploiting FortiManager on June 27, 2024. Through this exploitation, UNC5820 accessed and exfiltrated detailed configuration data, including FortiOS256-hashed passwords and settings, from managed FortiGate devices. This data could enable UNC5820 to compromise FortiManager, move laterally to other Fortinet devices, and potentially infiltrate enterprise environments. Although Mandiant’s analysis didn’t detect evidence of further malicious activity, critical artifacts, including device identifiers and network connections, indicate a well-coordinated threat. Notably, UNC5820 registered its device in FortiManager’s Global Objects database, further embedding its presence within the environment. Forensic investigation revealed outbound traffic from FortiManager shortly after data staging, corroborating data exfiltration. Mandiant and Fortinet recommend immediate forensic analysis for organizations with internet-exposed FortiManager instances. Limiting FortiManager's access to authorized IP addresses and denying associations with unknown devices are essential steps to prevent further exploitation. As investigations continue, Fortinet has proactively notified customers, and Mandiant will update its findings as new data surfaces.[emaillocker id="1283"]
RECOMMENDATION:
We strongly recommend you update Fortinet products as below version:
| Version | Affected | Solution |
| FortiManager 7.6 | 7.6.0 | Upgrade to 7.6.1 or above |
| FortiManager 7.4 | 7.4.0 through 7.4.4 | Upgrade to 7.4.5 or above |
| FortiManager 7.2 | 7.2.0 through 7.2.7 | Upgrade to 7.2.8 or above |
| FortiManager 7.0 | 7.0.0 through 7.0.12 | Upgrade to 7.0.13 or above |
| FortiManager 6.4 | 6.4.0 through 6.4.14 | Upgrade to 6.4.15 or above |
| FortiManager 6.2 | 6.2.0 through 6.2.12 | Upgrade to 6.2.13 or above |
| FortiManager Cloud 7.6 | Not affected | Not Applicable |
| FortiManager Cloud 7.4 | 7.4.1 through 7.4.4 | Upgrade to 7.4.5 or above |
| FortiManager Cloud 7.2 | 7.2.1 through 7.2.7 | Upgrade to 7.2.8 or above |
| FortiManager Cloud 7.0 | 7.0.1 through 7.0.12 | Upgrade to 7.0.13 or above |
| FortiManager Cloud 6.4 | 6.4 all versions | Migrate to a fixed release |
REFERENCES:
The following reports contain further technical details:
https://cybersecuritynews.com/fortimanager-devices-mass-compromise/