The FBI and CISA have issued a joint warning about attacks carried out by APT hackers targeting Fortinet FortiOS servers, using multiple exploits. Malicious actors are actively exploiting the vulnerabilities CVE-2018-13379, CVE-2020-12812 and CVE-2019-5591.
The FBI and CISA warning states the following:
“In March 2021, the FBI and CISA observed APT hackers scanning devices on ports 4443, 8443, and 10443 for the CVE-2018-13379 vulnerability, and numbered devices for the CVE-2020-12812 and CVE-2019-5591 vulnerabilities. It is possible that malicious actors are seeking these vulnerabilities to gain access to government, commercial, and technology service networks.”
Read also: Approximately 80,000 Exchange servers contain exploitable vulnerabilities!

The two services warn that APT hackers may use any or all of the above vulnerabilities to gain access to networks and critical infrastructures of many sectors. Once they gain access to target networks, the attackers can prepare the ground for future malicious activities, such as data theft or data encryption attacks. Additionally, the hackers can use other vulnerabilities or common exploitation techniques – such as spear phishing – to gain access to critical infrastructure networks for subsequent attacks.
See also: Portable VPN protects your online data
The warning also includes mitigation measures to secure systems from ongoing attacks that exploit these vulnerabilities:
- Patch the CVE 2018-13379, 2020-12812 and 2019-5591 vulnerabilities immediately.
- If FortiOS is not used by your organization, add the key artifact files used by FortiOS to your organization's execution denial list. Any attempts to install or execute this program and its related files must be avoided.
- Create regular backups and apply password protection to offline backups. Ensure that copies of critical data are not accessible for modification or deletion from the primary system where the data resides.
- Implement network segmentation.
- Require credentials to install software.
- Implement a recovery program to restore sensitive or proprietary data from a physically separate, segmented, secure location (e.g., hard drive, storage device, the cloud).
- Apply updates/patches to operating systems, software and firmware as soon as they are released.
- Use multi-factor authentication (MFA) wherever possible.
- Regularly change passwords on network systems and accounts and avoid reusing passwords across different accounts. Implement the shortest acceptable time frame for password changes.
- Disable remote access ports / Remote Desktop Protocol (RDP) and monitor remote access/RDP log files.
- Check user accounts with administrator privileges and configure access control settings taking the principle of least privilege into account.
- Install and regularly update antivirus and malware protection software on all central computers.
- Consider adding email banners to emails received outside your organization.
- Disable hyperlinks in received emails.
- Focus on awareness and training. Provide users with training on information security principles and techniques, especially for recognizing and avoiding phishing emails.

This is not the first time that the FBI and CISA have issued joint security advisory for attacks that exploit vulnerabilities in Fortinet systems. In October 2020, the American agencies warned that APT hackers were exploiting vulnerabilities in VPN products (Fortinet, Pulse Secure) and Windows ZeroLogon in attacks that targeted both governmental networks and services as well as non-governmental networks.
Suggestion: Cicada group exploits ZeroLogon in its new attacks
The FBI and CISA also observed attacks that were carried out by APT hackers exploiting two vulnerabilities – CVE-2018-13379 and CVE-2020-1472.
Information source: securityaffairs.co
