Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

Fortinet disclosed a critical FortiManager zero-day, CVE-2024-47575, in October 2024 after confirming evidence of active exploitation. The vulnerability could be exploited remotely without authentication to access sensitive files or take control of an affected system. Administrators should check their FortiManager version against Fortinet’s advisory, apply its fixed release or documented workaround, and investigate for compromise before trusting stored credentials, configurations, or backups.

What was the Fortinet zero-day?

CVE-2024-47575 affected FortiManager, Fortinet’s centralized platform for administering Fortinet devices. The California Cybersecurity Integration Center rated the flaw critical with a CVSS score of 9.8. CERT-EU described it as a critical zero-day that could allow remote, unauthenticated command or code execution.

On October 30, 2024, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that an unauthenticated remote attacker could exploit the vulnerability “to gain access to sensitive files or take control of an affected system.” CISA added it to its Known Exploited Vulnerabilities catalog after Fortinet confirmed evidence of active exploitation.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The disclosure establishes that exploitation was occurring; it does not establish that every FortiManager installation was targeted or compromised. “Limited attacks” should not be read as proof that an unpatched system is safe.

#1 Best Overall
FortiGate-40F Firewall Appliance - 5 Gigabit Ethernet RJ45 Ports, Ideal for Small Businesses (Appliance Only, No Subscription) (FG-40F)
  • Compact and Efficient Design: The FortiGate 40F is designed for small to mid-sized businesses and enterprise branch offices, featuring a compact, fanless desktop form factor that ensures quiet operation and minimizes space usage.
  • Robust Connectivity Options: Equipped with 5 GE RJ45 ports, including 1 WAN port and 4 internal ports, this model provides essential connectivity and flexibility for various network configurations in a small-scale environment.
  • High-Performance Security: Offers up to 1 Gbps IPS throughput and 600 Mbps threat protection throughput, using Fortinet’s purpose-built security processor technology to deliver industry-leading performance and protection for SSL encrypted traffic.
  • Advanced Threat Protection: Integrated with Fortinet’s AI-powered FortiGuard Labs, the FortiGate 40F offers comprehensive cybersecurity, identifying and mitigating both known and unknown threats to maintain robust security across your network.
  • Simplified Management and Deployment: Features a user-friendly management console that provides comprehensive network automation and visibility, coupled with Zero Touch Integration with Fortinet’s Security Fabric for easy deployment.

Is your FortiManager affected?

Check the exact FortiManager version and build in your environment against Fortinet’s advisory for CVE-2024-47575. The available reporting summarized here does not specify affected version ranges or fixed build numbers, so do not infer them from the CVE number or install a release chosen without checking the product-specific guidance.

If your installed version is affected, apply the fixed release or the workaround Fortinet documents for that version. CISA reported that patches were available by October 30, 2024. If you cannot patch immediately, use the vendor’s documented workaround and treat the system as exposed until remediation is verified.

Rank #2
Sale
FortiGate-40F Network Security Appliance Plus 3 Year FortiGuard Unified Threat Protection (UTP) and FortiCare Premium (FG-40F-BDL-950-36)
  • INTEGRATED FIREWALL APPLIANCE AND SECURITY SERVICES: Comes with FortiGate-40F Firewall Appliance, 3 years of FortiCare Premium, and FortiGuard Unified Threat Protection.
  • UTP SECURITY FEATURES: Offers protection from advanced threats with DNS filtering, URL filtering, video filtering, and controls against botnets.
  • IDEAL FOR SMALLER SETTINGS: Best suited for small to mid-sized businesses needing reliable security without the complexity of larger systems.
  • CONTINUOUS SUPPORT AND MAINTENANCE: FortiCare Premium ensures that technical help is readily available to manage and troubleshoot issues.
  • COMPACT AND EFFECTIVE: Provides a powerful, yet compact security solution that effectively protects against a wide range of cyber threats.

What should administrators do first?

  1. Identify exposure. Inventory FortiManager instances, record their versions and builds, and compare each with Fortinet’s version-specific advisory and remediation instructions.
  2. Patch or apply the documented workaround. Prioritize affected systems that remain unpatched. Confirm the change took effect and that the deployed build or workaround matches Fortinet’s instructions.
  3. Hunt for indicators of compromise. Review Fortinet’s indicators and investigate the management systems and connected devices. If your team cannot conduct that review, engage a qualified incident-response provider.
  4. Assess what may have been exposed. If indicators point to compromise, handle credentials and managed-device configurations as potentially exposed. Rotate affected secrets and validate device configurations through an incident-response process.
  5. Review backups before restoring. Health-ISAC warned that restoring a backup from a compromised system could reintroduce tampered data. Establish that a backup is trustworthy and validate its contents before using it for recovery.
  6. Assess service-provider exposure and reporting obligations. Determine whether a provider manages affected systems or holds related access, coordinate the investigation, and report confirmed findings to CISA as directed in its alert.

Could attackers have stolen FortiGate credentials or configurations?

Potentially, if an attacker accessed a compromised FortiManager. Health-ISAC reported that observed scripts automated the exfiltration of FortiManager data, including IP addresses, credentials, and configurations of managed devices. Those records could include information relating to FortiGate devices managed through the platform.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

This is evidence of a possible exposure path, not proof that credentials or configurations were taken from every exploited system. CISA’s alert also described access to sensitive files and possible control of an affected system. If compromise indicators are present, assume relevant stored secrets and device configurations may be exposed until the investigation establishes their scope; do not wait for proof of misuse before beginning containment and credential rotation.

Rank #3
Sale
FortiGate-60F Firewall Appliance - 10 Gigabit Ethernet RJ45 Ports, Includes DMZ, WAN & Internal Ports (Appliance Only, No Subscription) (FG-60F)
  • Extensive Connectivity Options: The FortiGate 60F is designed with 10 GE RJ45 ports, including 2 WAN ports, 1 DMZ port, and 7 internal ports, offering broad flexibility and high-density connections for diverse enterprise networking needs.
  • Superior Performance for Secure Networks: Features powerful system-on-a-chip acceleration to deliver top-tier security with 1.4 Gbps IPS throughput and 700 Mbps threat protection throughput, ensuring effective defense against advanced threats.
  • Enhanced SSL Inspection and SD-WAN Capabilities: Utilizes purpose-built security processor technology to provide the industry's highest SSL inspection performance and robust SD-WAN functionality for secure, high-speed network operations.
  • Simple and Effective Management: Comes equipped with a user-friendly management console that supports comprehensive network automation and visibility, alongside Zero Touch Integration with Fortinet's Security Fabric for streamlined deployment.
  • Advanced Security Features: Leverages continuous threat intelligence from AI-powered FortiGuard Labs, identifying and mitigating both known and unknown threats, enhancing security across all network traffic, whether encrypted or not.

How should you choose a response path?

Response depends on the installed version, whether a fixed release or workaround is available for it, and whether there is evidence of compromise. Use the following distinctions to set priorities:

Situation Priority
Affected version, no known compromise indicators Apply the applicable Fortinet fix or workaround, then review indicators and connected devices.
Compromise indicators found Contain and investigate the management system and connected devices; assess potentially exposed credentials and configurations, rotate secrets, and validate device settings.
Backup restoration is being considered Verify the backup’s integrity and contents before restoring; a backup from a compromised system could carry tampered data back into service.
Internal team lacks investigation capacity Engage a qualified incident-response provider to hunt for indicators and assess exposure; coordinate with any service provider responsible for the environment.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What is established—and what is not?

The public advisories establish a critical FortiManager vulnerability, confirmed active exploitation, and the availability of patches by October 30, 2024. Health-ISAC’s account describes automated data-exfiltration scripts and warns about compromised backups. These findings justify treating a confirmed compromise as a potential exposure of managed-device information.

Rank #4
FortiGate-40F Firewall Appliance plus 1 Year FortiCare Premium and FortiGuard Unified Threat Protection (UTP) (FG-40F-BDL-950-12)
  • INTEGRATED FIREWALL APPLIANCE AND SECURITY SERVICES: Comes with FortiGate-40F Firewall Appliance, 1 year of FortiCare Premium, and FortiGuard Unified Threat Protection.
  • UTP SECURITY FEATURES: Offers protection from advanced threats with DNS filtering, URL filtering, video filtering, and controls against botnets.
  • IDEAL FOR SMALLER SETTINGS: Best suited for small to mid-sized businesses needing reliable security without the complexity of larger systems.
  • CONTINUOUS SUPPORT AND MAINTENANCE: FortiCare Premium ensures that technical help is readily available to manage and troubleshoot issues.
  • COMPACT AND EFFECTIVE: Provides a powerful, yet compact security solution that effectively protects against a wide range of cyber threats.

The available reporting does not provide affected-version ranges, a count of victims, or evidence that every attack extracted credentials or configurations. Those details must be determined from Fortinet’s version-specific guidance and an investigation of the individual environment.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
FortiGate-60F Network Security Appliance Plus 1 Year FortiGuard Unified Threat Protection (UTP) and FortiCare Premium (FG-60F-BDL-950-12)
  • HARDWARE PLUS SECURITY SERVICES: FortiGate-60F Firewall Appliance bundled with 1 year of FortiCare Premium and FortiGuard Unified Threat Protection.
  • UNIFIED THREAT PROTECTION (UTP): Secures against advanced online threats with comprehensive web filtering and anti-botnet technologies.
  • OPTIMIZED FOR MEDIUM-SIZED BUSINESSES: Tailored for businesses needing robust security without the infrastructure of larger enterprises.
  • RELIABLE CUSTOMER SUPPORT: FortiCare Premium ensures high-quality support and service continuity.
  • EFFECTIVE PROTECTION: Employs advanced filtering technologies to safeguard against sophisticated threats.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.