This vulnerability underscores the importance of regular patch management and proactive security measures in safeguarding critical infrastructure against emerging threats. Fortinet’s swift response in addressing this issue reflects its commitment to protecting its customers from evolving cyber threats while reinforcing the importance of maintaining up-to-date systems in today’s dynamic threat landscape. Cyber Security News is a Dedicated News Platform For Cyber News, Cyber Attack News, Hacking News & Vulnerability Analysis. The vulnerability, identified as an unverified password change vulnerability (CWE-620), could allow remote, unauthenticated attackers to modify administrative passwords via specially crafted requests. This vulnerability poses significant risks to organizations relying on FortiSwitch for secure network management. Fortinet has issued a critical advisory regarding a newly discovered vulnerability in its FortiSwitch product line. By exploiting this flaw, attackers can modify administrative passwords without proper verification, potentially gaining unauthorized access to sensitive systems. The vulnerability affects FortiSwitch’s graphical user interface (GUI) and allows attackers to bypass authentication mechanisms. Daniel Rozeboom, a member of the FortiSwitch web UI development team, internally discovered and reported the vulnerability. In light of this discovery, cybersecurity experts emphasize the need for robust monitoring and incident response capabilities to detect and respond swiftly to unauthorized access attempts. Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. Cybersecurity researchers have uncovered a disturbing campaign targeting software developers through malicious Visual Studio Code extensions that have collectively amassed millions of installations. The advisory was officially published on April 8, 2025, and users are encouraged to act promptly to secure their systems against potential exploitation. Organizations using FortiSwitch should prioritize applying the recommended updates or implementing workarounds to mitigate risks. Fortinet has acknowledged the vulnerability and released patches for affected versions.
This Cyber News was published on cybersecuritynews.com. Publication date: Tue, 08 Apr 2025 14:40:13 +0000