• Hello and welcome! Register to enjoy full access and benefits:

    • Advertise in the Marketplace section for free.
    • Get more visibility with a signature link.
    • Company/website listings.
    • Ask & answer queries.
    • Much more...

    Register here or log in if you're already a member.

  • 🎉 WHV has crossed 72000 (72k) monthly views (unique) and 272000 clicks per month, as per Google Analytics! Thank you for your support! 🎉

Over 25,000 FortiCloud SSO Devices Exposed to Remote Cyber Attacks

johny899

Member
Content Writer
Messages
1,069
Reaction score
3
Points
43
Balance
$122.4USD
If you could simply leave your office with the door open, this is what is currently happening to your Fortinet Devices. Currently, according to security researchers there are more than 25,000 Fortinet devices exposed to remote attack via FortiCloud SSO. All the attackers need to gain access is to log into the network from anywhere at any time.

What’s The Issue?​

FortiCloud SSO has made it easy for administrators to log into their Fortinet devices from anywhere. But because of a vulnerability that has been exposed, anyone can use FortiCloud SSO to gain administrative access remotely without permission. Once the attacker gains administrative access to the Fortinet device they can view, as well as download, sensitive information regarding the system.

So What Information Can An Attacker Download?​

If an attacker gains access they have access to:
  • Network Settings
  • Firewall Rules
  • Passwords stored in the system
  • Details regarding the company's internal systems
This type of sensitive information enables an attacker to plan larger attacks in the future. Have you ever wondered why cybercriminals can move so quickly once inside a corporate network? This is one reason why!

How Big Is the Risk?​

Security researchers found that there are upwards of 25,000 exposed Fortinet devices worldwide, most of which are located in the following geographical regions:
  • United States
  • India
  • Europe and other areas
Therefore, every organization, no matter how large or small, may become victim to remote attacks.

What Actions Should You Take Immediately?​

If you own any Fortinet product, then you should do these things:
  • Look to see if there are any available Security Updates (SU) available for you and install all applicable Security Updates.
  • Disable FortiCloud SSO service until Security Updates have been installed.
  • Review your Administrators' access permissions.

Closing Remarks​

This example demonstrates the significant risk that can result from one minor configuration error. By simply putting in a few minutes to update your Fortinet products, your entire network can be safeguarded.
 
Top