HomeSecurityHacker shared exploits for approximately 50,000 vulnerable Fortinet VPNs!

Hacker shared exploits for about 50,000 vulnerable Fortinet VPNs!

A hacker has published a list of one-line exploits aimed at stealing credentials from approximately 50,000 Fortinet VPN devices. The list of vulnerable targets includes domains belonging to banks and government organizations from around the world. The vulnerability reported is CVE-2018-13379, a path-traversal vulnerability affecting a large number of unpatched Fortinet FortiOS SSL VPN. By exploiting this vulnerability, hackers can gain access to system files via specially crafted HTTP requests.

Hacker shared exploits for about 50,000 vulnerable Fortinet VPNs!

The exploits published by the hacker allow access to sslvpn_websession from Fortinet VPNs and the theft of login credentials. The stolen credentials can then be used to compromise a network, as well as deploy ransomware. Although the 2018 vulnerability was publicly disclosed a year ago, researchers have identified approximately 50,000 targets that are still vulnerable to attacks.

Last week, threat intelligence analyst “Bank_Security” found a thread on a hacking forum in which a cybercriminal shared a list of devices with approximately 50,000 such exploitable targets. After analyzing the list, it was found that the vulnerable targets include government sectors from around the world, including banks and financial services companies.

Hacker shared exploits for about 50,000 vulnerable Fortinet VPNs!

According to BleepingComputer, of the 50,000 domains, most belonged to banking, financial and government organizations. Additionally, Bank Security analyst told BleepingComputer that after seeing the hacker’s post on the forum, he began analyzing the list of IPs to determine if and to what extent the targeted organizations were affected. The analyst tried to identify domain names associated with high-profile organizations and banks.

Hacker shared exploits for about 50,000 vulnerable Fortinet VPNs!

The analyst also pointed out that although this is an old and known vulnerability whose exploitation is relatively trivial, organizations have "a very slow" patching process, which allows attackers to continue exploiting known vulnerabilities.

It is worth noting that hackers recently exploited the same vulnerability to compromise US election systems . Therefore , network administrators and security professionals are advised to immediately patch this serious vulnerability to prevent potential attacks.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS