CISA adds fresh Ivanti vuln, critical Fortinet bug to hall of shame
ID: 03936b29-a703-5a0d-99d0-9baadaf30d7f
STIX ID: report--03936b29-a703-5a0d-99d0-9baadaf30d7f
Feed Name: The Register (Security)
The article reports that CISA has added multiple actively exploited vulnerabilities to its KEV catalog: a critical Fortinet format-string RCE (CVE-2024-23113) impacting FortiOS, FortiPAM, FortiProxy, and FortiWeb, and several Ivanti CSA flaws (SQLi, command injection and path traversal) being exploited—notably against EOL CSA 4.6. Vendors recommend immediate patching or mitigations (removing fgfm access for Fortinet, rebuilding Ivanti appliances to 5.0.2) and additional protections such as EDR and restrictive policies while investigations continue.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
