Resources · CVE-2024-21762, Fortinet, CISA KEV, Vulnerability management

CVE-2024-21762 in FortiOS and FortiProxy: the SSL-VPN link needs verification

CVE-2024-21762 has been in the CISA KEV catalog as actively exploited since February 2024. The vendor advisory could not be read during this research, so this note keeps strictly to what the primary records state — including why the usual “RCE via SSL-VPN” phrasing stays unconfirmed.

Since 9 February 2024, CVE-2024-21762 has been listed in the CISA KEV catalog as actively exploited. What follows separates what the primary records state from what they do not.

Affected versions

  • FortiOS: 6.0.0–6.0.17, 6.2.0–6.2.15, 6.4.0–6.4.14, 7.0.0–7.0.13, 7.2.0–7.2.6 and 7.4.0–7.4.2.
  • FortiProxy: 1.0.0–1.0.7, 1.1.0–1.1.6, 1.2.0–1.2.13, 2.0.0–2.0.13, 7.0.0–7.0.14, 7.2.0–7.2.8 and 7.4.0–7.4.2.

In the Fortinet record the defect is classified as CWE-787, an out-of-bounds write. Specially crafted requests can allow unauthorized code or commands to be executed.

What the vector states, and what it does not prove

The Fortinet vector contains AV:N, PR:N and UI:N. For a practical assessment this means considering network reachability of an affected device without prior authentication and without user interaction. It does not prove that the device is reachable from the internet: the CVE record names no external address, no port and no specific HTTP endpoint.

The vendor advisory could not be read

The official record references the vendor advisory FG-IR-24-015. Its substantive content was not available during this research because of a FortiGuard connection check.

Where an external check stops

From this follows the boundary of an external check. It can find FortiOS and FortiProxy instances responding on public addresses and match them against a version inventory and against KEV. It cannot confirm CVE-2024-21762 from an external response alone: the published CVE record provides no signature and no endpoint for such a check. Which services are actually published on each gateway found, standby devices included, has to be established separately from the configuration.

Fixed versions

  • FortiOS: 6.2.16+, 6.4.15+, 7.0.14+, 7.2.7+, 7.4.3+ or 7.6.0+.
  • FortiProxy: 2.0.14+, 7.0.15+, 7.2.9+ or 7.4.3+.

For US federal civilian agencies the KEV entry set a due date of 16 February 2024. For other organizations that date is not a separate regulatory deadline, but the active status means prioritization should take into account the external instances actually found, not only a static equipment register.

Checks and actions

  • CVE-2024-21762 in KEV since 9 February 2024 — record the active exploitation status when prioritizing.
  • FortiOS or FortiProxy responds on a public address — match the address to its owner, product and installed version.
  • The version falls within an affected range — update to a fixed version listed by Fortinet.
  • SSL-VPN is assumed to be published — check the configuration and the wording of FG-IR-24-015; do not infer a vulnerable path from an external response alone.
  • The KEV due date for US federal agencies is 16 February 2024 — verify that the mandated update was applied or that the product was discontinued.
  • Standby gateways are missing from the inventory — keep external scanning running and reconcile discovered assets against KEV.

Your first step

Request an initial review of your company.

Share your company website and a work email. We'll send your request to the IntruForce team. Tell us if you want to discuss a specific assessment instead.

  • Nothing to install
  • No access to your internal network
  • You approve active testing separately
Only if you’d prefer us to reply there.

This form sends a review request to the IntruForce team. Sending it commits you to nothing; our team replies to the work email you provide.