Ivanti has recently disclosed a high-severity security flaw, tracked as CVE-2024-22024, affecting its Connect Secure, Policy Secure, and ZTA gateway devices. This vulnerability, rated 8.3 out of 10 on the CVSS scoring system, enables attackers to bypass authentication through an XML external entity (XXE) weakness in the SAML component of the affected products. The flaw was discovered during an internal review as part of an ongoing investigation into multiple security weaknesses in the products.
The impacted Ivanti product versions include:
Ivanti has released patches for the vulnerability in various product versions. Users are urged to update to the latest patched versions immediately. While there is currently no evidence of active exploitation, given the history of abuse for other vulnerabilities (CVE-2023-46805, CVE-2024-21887, CVE-2024-21893), prompt application of the patches is crucial to ensure security.
Fortinet has disclosed a critical security flaw, CVE-2024-21762, impacting FortiOS SSL VPN, with a CVSS score of 9.6. This vulnerability allows for the unauthenticated execution of arbitrary code and commands through an out-of-bounds write weakness in FortiOS. The company acknowledges the potential exploitation of this vulnerability in the wild.
The affected FortiOS versions include:
Fortinet recommends users and administrators of the affected product versions to update to the latest versions immediately to mitigate the risk of remote code execution. If not able to update, a workaround, it is also advised to disable SSL VPN (disable webmode is NOT a valid workaround).
Fortinet has disclosed another critical security flaw, CVE-2024-23113, impacting FortiOS fgfmd daemon, with a CVSS score of 9.8. It is an externally-controlled format string vulnerability that allows a remote unauthenticated attacker to execute arbitrary code or commands via specially crafted requests.
The affected FortiOS versions include:
Fortinet recommends users and administrators of the affected product versions to update to the latest versions immediately to mitigate the risk of remote code execution.