
CVE-2024-21762 is an out-of-bounds write in FortiOS SSL VPN. Remote attackers can execute code on the firewall without authentication on vulnerable firmware — a classic edge-device pre-auth RCE pattern seen in mass exploitation campaigns.
Affected FortiOS
- FortiOS 7.4.0 through 7.4.2 (fixed in 7.4.3+)
- FortiOS 7.2.0 through 7.2.6 (fixed in 7.2.7+)
- FortiOS 7.0.x and 6.4.x — see Fortinet PSIRT FG-IR-24-015
- SSL VPN enabled and exposed to internet
Check firmware
get system status | grep Version
show vpn ssl settingsRemediation
- Upgrade FortiOS to vendor-fixed build
- Disable SSL VPN temporarily if patch window is delayed
- Restrict VPN portal to known IP ranges
- Hunt for unknown admin accounts and cron jobs after patch
Note: CISA KEV listed. Assume active exploitation on unpatched units.