Double trouble for Fortinet as it issues critical FortiSIEM vulns
ID: ce2dc2ea-8025-50b3-a9f2-149d65eb52d6
STIX ID: report--ce2dc2ea-8025-50b3-a9f2-149d65eb52d6
Feed Name: The Register (Security)
Threat Score
Fortinet FortiSIEM has two high-severity vulnerabilities (CVE-2024-23108 and CVE-2024-23109) rated CVSS 10 that permit remote unauthenticated command execution via crafted API requests; multiple FortiSIEM versions are affected and Fortinet has released or will release patches (upgrade to 7.1.2 where available), while public exploit code is not currently known and vendor communications have been inconsistent about whether these CVEs duplicate an earlier October 2023 fix.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
