• News/
  • https://www.theregister.com/2024/02/06/fortinet_fortisiem_vulns/

Double trouble for Fortinet as it issues critical FortiSIEM vulns

The Register
·
Connor Jones
·
Published Feb 6, 2024
·
Updated

Updated Fortinet's FortiSIEM product is vulnerable to two maximum-severity security vulnerabilities that allow for remote code execution, or at least according to two freshly published CVEs.* Both CVE-2024-23108 and CVE-2024-23109 have been assigned scores of 10 on the CVSS scale, suggesting exploits can be carried out remotely by unauthenticated attackers, are low in complexity, and require no user interaction to pull off. In registering the CVE identities for the vulnerabilities, Fortinet linked to its own advisory to provide more information, but the link directs users to an older issue that was addressed in early October 2023. "Multiple improper neutralization of special elements used in an OS Command vulnerability [CWE-78] in FortiSIEM supervisor may allow a remote unauthenticated attacker to execute unauthorized commands via crafted API requests," the advisory's description of the vulnerability reads. Taking a glance at older, cached versions of the same advisory, we can see that the list of affected products has been recently updated, adding additional FortiSIEM versions. Despite Fortinet's advisory not being officially updated (yet), it suggests the two new vulnerabilities may be similar in nature to the one fixed in October, affecting newer versions of FortiSIEM. The Register asked Fortinet for clarity on the matter but did not receive a response. We also spoke to application security expert Sean Wright, who said the most recent two vulnerabilities in FortiSIEM will ...

Read full article

Affected Software

25 affected components
Fortinet FortiSIEM=7.1.0
Fortinet FortiSIEM=7.1.1
Fortinet FortiSIEM=7.0.0
Fortinet FortiSIEM=7.0.1
Fortinet FortiSIEM=7.0.2
Fortinet FortiSIEM=6.7.0
Fortinet FortiSIEM=6.7.1
Fortinet FortiSIEM=6.7.2
Fortinet FortiSIEM=6.7.3
Fortinet FortiSIEM=6.7.4
Fortinet FortiSIEM=6.7.5
Fortinet FortiSIEM=6.7.6
Fortinet FortiSIEM=6.7.7
Fortinet FortiSIEM=6.7.8
Fortinet FortiSIEM=6.6.0
Fortinet FortiSIEM=6.6.1
Fortinet FortiSIEM=6.6.2
Fortinet FortiSIEM=6.6.3
Fortinet FortiSIEM=6.5.0
Fortinet FortiSIEM=6.5.1
Fortinet FortiSIEM=6.5.2
Fortinet FortiSIEM=6.4.0
Fortinet FortiSIEM=6.4.1
Fortinet FortiSIEM=6.4.2
Fortinet FortiSIEM=7.1.2
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What critical vulnerabilities were found in Fortinet's FortiSIEM?

Two maximum-severity vulnerabilities, CVE-2024-23108 and CVE-2024-23109, allow for remote code execution.

2

Which versions of FortiSIEM are affected by these vulnerabilities?

Affected versions include FortiSIEM 6.4.0 to 7.1.2.

3

What is the severity level of these vulnerabilities in FortiSIEM?

The vulnerabilities are classified as critical with a maximum severity level.

4

What are the potential impacts of these FortiSIEM vulnerabilities?

The vulnerabilities could allow attackers to execute arbitrary code remotely, posing a significant threat to system security.

5

How should FortiSIEM users respond to these vulnerabilities?

Users should apply the necessary patches and updates provided by Fortinet to mitigate the risks.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203