Engage Report: Console Chaos – Fortinet FortiGate Firewall Exploitation

  1. Threat actors scan for publicly exposed FortiGate firewall management interfaces.
  2. They exploit a probable zero-day vulnerability (later identified as CVE-2024-55591) to gain unauthorized access.
  3. Threat actors establish jsconsole sessions, often spoofing IP addresses like loopback addresses or public DNS resolvers.
  4. They make various configuration changes, create new admin accounts, and enable SSL VPN access.