diff --git a/_cases/2024/DIVD-2024-00044.md b/_cases/2024/DIVD-2024-00044.md index acd0d136..3cabe91e 100644 --- a/_cases/2024/DIVD-2024-00044.md +++ b/_cases/2024/DIVD-2024-00044.md @@ -41,6 +41,12 @@ timeline: - start: 2024-11-28 end: event: "DIVD starts scanning the internet for vulnerable instances." +- start: 2024-12-21 + end: + event: "DIVD performed a rescan to retrieve the latest vulnerable instances" +- start: 2024-12-21 + end: + event: "DIVD starts notifying network owners with a vulnerable instance in their network." --- ## Summary A missing authentication for critical function vulnerability [CWE-306] in FortiManager fgfmd daemon may allow a remote unauthenticated attacker to execute arbitrary code or commands via specially crafted requests. Reports have shown this vulnerability is exploited in the wild.