Gunra Ransomware Gang Exploits Fortinet Firewall CVEs to Target Critical Infrastructure
What Happened — The FBI and South Korea’s National Policy Agency warned that the Gunra ransomware group is leveraging two known Fortinet firewall vulnerabilities (CVE‑2024‑55591 and CVE‑2025‑24472) to gain privileged access, steal data and deploy ransomware against healthcare, financial services and government entities worldwide.
Why It Matters for Compliance & Audit Readiness
- The scenario underscores the need for continuous vulnerability‑management and patch‑verification controls required by SOC 2 CC6.1 (Risk Mitigation).
- Demonstrating timely remediation and evidence of firewall configuration reviews satisfies the “Change Management” and “System Operations” criteria of a SOC 2 audit.
- Mapping these exploit‑prevention controls to Verisq’s Control Mapping capability provides auditable proof that your organization is actively monitoring and remediating high‑severity vulnerabilities.
Who Is Affected – Healthcare providers, banks, government agencies, and any organization that relies on Fortinet firewalls for perimeter security.
Recommended Actions
- Verify that all Fortinet firewalls are patched for CVE‑2024‑55591 and CVE‑2025‑24472; apply vendor‑released updates immediately.
- Implement continuous configuration‑assessment tooling that logs patch status and firewall rule changes as audit evidence.
- Map the remediation steps to SOC 2 CC6.1 and CC7.1 controls, and capture evidence in your Trust Center for future audits.
Source: The Record
Technical Notes – Gunra exploits remote‑code execution flaws in Fortinet’s FortiOS (CVE‑2024‑55591, CVSS 9.8; CVE‑2025‑24472, CVSS 9.3). The ransomware operates via a Windows payload and a newer Linux variant; a recent weakness in the Linux variant allows key reconstruction from file timestamps. Source: same