LIVE MONITORING
Critical Advisory CVE-2024-23113

High: FortiOS SSL VPN Authentication Bypass

Affected Systems

FortiOS 7.0.x through 7.4.x

A critical authentication bypass vulnerability in FortiOS SSL VPN allows remote attackers to gain super-admin privileges through crafted HTTP requests. Active exploitation has been observed in the wild.

Mitigation Steps

  1. Update FortiOS to latest patched version
  2. Disable SSL VPN if not needed
  3. Implement IP allowlisting for VPN access