From c43d923bd6a9bec298304a1a99ebd327b783f5e8 Mon Sep 17 00:00:00 2001 From: KoenS Date: Thu, 5 Dec 2024 23:50:34 +0100 Subject: [PATCH] Update DIVD-2024-00044.md Add timeline items --- _cases/2024/DIVD-2024-00044.md | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/_cases/2024/DIVD-2024-00044.md b/_cases/2024/DIVD-2024-00044.md index a35648e0..a9b0d3a7 100644 --- a/_cases/2024/DIVD-2024-00044.md +++ b/_cases/2024/DIVD-2024-00044.md @@ -9,6 +9,7 @@ researchers: - Alwin Warringa - Max van der Horst - Oscar Vlugt +- Koen Schagen cves: - CVE-2024-47575 product: @@ -34,6 +35,12 @@ timeline: - start: 2024-10-24 end: event: "DIVD starts researching the vulnerability to determine a fingerprint" +- start: 2024-11-28 + end: + event: "DIVD finds fingerprint, preparing to scan." +- start: 2024-11-28 + end: + event: "DIVD starts scanning the internet for vulnerable instances." --- ## Summary A missing authentication for critical function vulnerability [CWE-306] in FortiManager fgfmd daemon may allow a remote unauthenticated attacker to execute arbitrary code or commands via specially crafted requests. Reports have shown this vulnerability is exploited in the wild.