• News/
  • https://www.bleepingcomputer.com/news/security/fortinet-warns-of-new-fortisiem-rce-bugs-in-confusing-disclosure/

Fortinet warns of new FortiSIEM RCE bugs in confusing disclosure

BleepingComputer
·
Lawrence Abrams
·
Published Feb 8, 2024
·
Updated

Fortinet is warning of two new unpatched patch bypasses for a critical remote code execution vulnerability in FortiSIEM, Fortinet's SIEM solution. Fortinet added the two new vulnerabilities tracked as CVE-2024-23108 and CVE-2024-23109 to the original advisory for the CVE-2023-34992 flaw in a very confusing update. Earlier today, BleepingComputer published an article that the CVEs were released by mistake after being told by Fortinet that they were duplicates of the original CVE-2023-34992. "In this instance, due to an issue with the API which we are currently investigating, rather than an edit, this resulted in two new CVEs being created, duplicates of the original CVE-2023-34992," Fortinet told BleepingComputer. "There is no new vulnerability published for FortiSIEM so far in 2024, this is a system level error and we are working to rectify and withdraw the erroneous entries." However, it turns out that CVE-2024-23108 and CVE-2024-23109 are actually patch bypasses for the CVE-2023-34992 flaw discovered by Horizon3 vulnerability expert Zach Hanley. On X, Zach stated that the new CVEs are patch bypasses for CVE-2023-34992, and the new IDs were assigned to him by Fortinet.

After contacting Fortinet once again, we were told their previous statement was “misstated” and that the two new CVEs are variants of the original flaw. "The PSIRT team followed its process to add two similar variants of the previous CVE (CVE-2023-34992), tracked as CVE-2024-23108 and CVE-2024-23109 to our p...

Read full article

Affected Software

3 affected components
Fortinet FortiSIEM
JetBrains TeamCity
atlassian Confluence
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses Fortinet's warning of newly disclosed unpatched remote code execution vulnerabilities in FortiSIEM.

2

What security implications are discussed in the article?

The article highlights two critical remote code execution vulnerabilities, CVE-2024-23108 and CVE-2024-23109, that pose significant risks to FortiSIEM users.

3

What products or software are affected by the vulnerabilities mentioned?

The vulnerabilities specifically affect Fortinet's FortiSIEM, as well as JetBrains TeamCity and Atlassian Confluence.

4

Are the vulnerabilities mentioned in the article patched?

No, the article indicates that the newly disclosed vulnerabilities are unpatched.

5

Why is the disclosure of these vulnerabilities considered confusing?

The disclosure is deemed confusing due to the lack of clarity surrounding the critical vulnerabilities and their potential impacts.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203