OVERVIEW OF 2024 ●
Number of reported vulnerabilities 2015–2024
40 000
40,008
30 00
25,043
20 000
14,643
10 000
0
6,487
6,447
2015
2016
2017
16,509
17,305
18,349
2018
2019
2020
Source: nvd.nist.gov
Magento. Hundreds of notifications were also
sent to owners of network devices and management systems with critical vulnerabilities.
EXPLOITING A ZERO-DAY
VULNERABILITY IN ESTONIA
On 23 October, information about a zero-day
vulnerability in FortiManager (CVE-202447575) was made public. This vulnerability in a
critical FortiManager function allowed attackers
to execute arbitrary commands within the system due to the absence of authentication. Fortinet had warned its clients about the potential
vulnerability a few days earlier, advising them to
update the software and implement additional
protective measures. However, in Estonia, this
vulnerability was already exploited on 22 October, with attackers gaining control of two servers
belonging to one organisation.
GLOBAL TRENDS
In 2024, the number of reported vulnerabilities
grew significantly. The number of reported vulnerabilities surged in 2024, reaching 40,008
globally – a one-third increase from the 28,817
identified in 2023.
Global trends included the exploitation of
zero-day vulnerabilities in the firmware of network devices and network management systems. For example, two zero-day vulnerabilities
in Ivanti software (CVE-2023-46805 and CVE2024-21887) were exploited by groups linked to
China. These vulnerabilities allowed attackers to
bypass authentication and inject commands.
CYBER SECURITY IN ESTONIA 2025
28,817
20,155
2021
2022
2023
2024
CERT-EE discovered
a critical vulnerability
in Palo Alto software
CERT-EE identified and documented a critical
vulnerability (CVE-2024-3393) in devices
running Palo Alto Networks’ operating system,
PAN-OS. The vulnerability allowed attackers to
send a specially designed malicious network
packet that caused the firewall to freeze,
rendering it unusable in a denial-of-service
state. When in a denial-of-service state, the
firewall halts all network traffic, which disrupts
internet connectivity and disables online
services reliant on the network. Working in
collaboration, CERT-EE and Palo Alto engineers identified the root cause of the issue,
and Palo Alto released an updated version
of PAN-OS to address the vulnerability.
Cybercriminals also continued to target devices with older, known vulnerabilities, often
exploiting them for ransomware attacks or adding them to botnets.
As in previous years, numerous critical vulnerabilities were discovered in web content
management systems and e-commerce software.
The prevalence of zero-day vulnerabilities and
the ongoing exploitation of older vulnerabilities
highlight the need for a systematic approach to
this issue. Organisations must establish and follow vulnerability management processes and
bolster their network security with additional
protective measures. ●
35