This alert has been written for the IT teams of organisations and government.
Background / What has happened?
- The ASD's ACSC is tracking a vulnerability in FortiManger devices.
- Fortinet are aware of active exploitation of vulnerable instances.
- This vulnerability has been allocated a CVSSv3 score of 9.8
Mitigation / How do I stay secure?
- Australian organisations should review their networks for use of vulnerable instances of FortiManager devices and implement the mitigation advice provided by the vendor.
- Patch information is available at PSIRT | FortiGuard Labs. ASD's ACSC strongly recommends that affected Australian organisations patch this vulnerability as a matter of high priority.
Assistance / Where can I go for help?
The ASD's ACSC is monitoring the situation and is able to provide assistance and advice as required. Organisations that have been impacted or require assistance can contact us via 1300 CYBER1 (1300 292 371).