Long list of vulnerable Fortinet SSL VPNs published

By
Follow google news

Unpatched after more than a year.

A large list of almost 50,000 internet-reachable Fortinet FortiGate virtual private networking systems that contain an easily exploitable vulnerability has been published on the web and social media.

Long list of vulnerable Fortinet SSL VPNs published

Attackers can exploit the the path traversal vulnerability to download FortiOS system files remotely with no authentication required, if the secure sockets layer (SSL) VPN service is enabled.

It is possible to obtain the credentials of logged in SSL VPN users this way, Fortinet warned.

The flaw was reported to Fortinet in December 2018, with Taiwanese researchers Meh Chang and Orange Tsai documenting it along with several other vulnerabilities.

Fortinet has issued patched versions of its FortiOS operating system which have been available since May last year.

iTnews was able to find the list of unpatched servers through a vulnerability indexing service.

It is also possible to find potentially vulnerable systems through Google searches, so-called dorking, which find the Fortinet SSL VPN login pages.

The list contains several internet protocol addresses which appear to be assigned to Australian registered domains.

Add iTnews as your trusted source

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © iTnews.com.au . All rights reserved.
Tags:

Most Read Articles

Apple overhauls security with iOS and macOS 27

Apple overhauls security with iOS and macOS 27

ASD warns Aussie Adobe Commerce and Magento stores under attack

ASD warns Aussie Adobe Commerce and Magento stores under attack

OpenAI rogue agent activity wider-ranging than disclosed

OpenAI rogue agent activity wider-ranging than disclosed

Hundreds of old, vulnerable Exchange servers remain in Australia

Hundreds of old, vulnerable Exchange servers remain in Australia

Log In

  |  Forgot your password?