Fortinet Fortios In Ongoing Attacks Targeting Commercial Government And Technology Services Networks Cybers Guards
Following the recent release of security patches covering critical security vulnerabilities in Fortinet’s flagship FortiOS product, the FBI and the Cybersecurity and Infrastructure Security Agency (CISA) released a joint advisory. Threat actors have been found targeting three Fortinet FortiOS vulnerabilities in the last month, according to the two agencies: CVE-2018-13379 (a path traversal vulnerability in the FortiOS SSL VPN web portal), CVE-2020-12812 (FortiOS SSL VPN 2FA bypass), and CVE-2019-5591 (a path traversal vulnerability in the FortiOS SSL VPN web portal) (lack of LDAP server identity verification in default configuration)....