PTA Issues Urgent Cybersecurity Advisory for Fortinet Vulnerability

Published:

xPakistan Telecommunication Authority (PTA) has issued a critical cybersecurity advisory warning about a major vulnerability affecting Fortinet devices. The flaw, identified as CVE-2024-21762, poses a high-risk Remote Code Execution (RCE) threat to Fortinet’s FortiOS, FortiProxy, FortiSwitchManager, and FortiAnalyzer systems.

The vulnerability allows attackers to remotely execute malicious code on vulnerable devices by exploiting a flaw in how these systems handle file paths. With an estimated 150,000 devices potentially impacted worldwide, the urgency to address this issue is paramount.

PTA recommends organizations immediately install the official patches released by Fortinet to mitigate the risk. As a temporary measure, disabling the HTTP/HTTPS administrative interface or restricting access to trusted IPs can provide some protection, but PTA emphasizes that these measures are not a substitute for patching the vulnerability.

Organizations are urged to monitor their systems for suspicious activity and ensure timely updates are applied. Regularly checking Fortinet’s official advisories for the latest information is crucial. In case of a security incident, PTA recommends reporting it through their CERT Portal or via email for a swift response.

Related articles

spot_img