NVD published two advisories this week for critical command injection vulnerabilities purportedly impacting Fortinet's FortiSIEM products, but there's more to what meets the eye. BleepingComputer has confirmed that these CVEs are not "new," but duplicates of a previously known FortiSIEM vulnerability and were issued in error. Two critical severity vulnerability advisories have emerged on NVD, implicating ForiSIEM, Fortinet's SIEM solution. These OS command injection vulnerabilities, tracked as CVE-2024-23108 and CVE-2024-23109 were each scored as a 10/10, the highest on the CVSS scale that is used to define the severity associated with a vulnerability. Confusingly enough, Fortinet's advisory associated with these CVEs bears a publication date of "Oct 10, 2023"—not yesterdaty's, and additionally lists a previously known CVE-2023-34992, also a critical FortiSIEM OS command injection flaw. BleepingComputer reached out to the vendor for clarification and turns out, there's nothing to see here—the two new CVE IDs, CVE-2024-23108 and CVE-2024-23109 have been generated in error. "A modification was made to the original FG-IR-23-130 - which commonly happens to ensure ongoing accuracy of information and updates are pushed to the NVD Database in parallel to keep the two systems in sync," a Fortinet spokesperson told BleepingComputer. "In this instance, due to an issue with the API which we are currently investigating, rather than an edit, this resulted in two new CVEs being created, d...
Fortinet snafu: Critical FortiSIEM CVEs are duplicates, issued in error
BleepingComputer
·Ax Sharma
·Published Feb 7, 2024
·Updated
Affected Software
1 affected component
Fortinet FortiSIEM
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a mistake by NVD regarding critical vulnerabilities in Fortinet's FortiSIEM products.
2
What security implications are discussed in the article?
The article highlights that the critical command injection vulnerabilities listed are duplicates and were issued in error.
3
What products or software are affected?
The affected product mentioned is Fortinet's FortiSIEM.
4
Who confirmed the error regarding the CVEs?
BleepingComputer confirmed that the CVEs published were duplicates issued in error.
5
What should FortiSIEM users do in light of this news?
FortiSIEM users should verify their systems against official Fortinet advisories and remain vigilant for any authentic vulnerabilities.