logo

CVE-2024-21762 and CVE-2024-23113: Multiple Critical Vulnerabilities in Fortinet, One Likely Under Active Exploitation

ID: bb9b004c-d7b4-5608-8d12-ba0a5ec9008a

STIX ID: report--bb9b004c-d7b4-5608-8d12-ba0a5ec9008a

Feed Name: Arctic Wolf

Threat Score
75/100

Date Published: 2024-02-12

Date Updated: 2026-07-26

Author: Andres Ramos

...
...

On 8 February 2024 FortiGuard disclosed two critical FortiOS vulnerabilities (CVE-2024-23113 — format string; CVE-2024-21762 — out-of-bounds write) that could allow unauthenticated actors to execute arbitrary code; FortiGuard is aware of potential exploitation for CVE-2024-21762 though no public PoC has been identified. Arctic Wolf recommends upgrading affected FortiOS and FortiSIEM versions to the listed fixed releases and provides temporary mitigations (remove fgfm access for CVE-2024-23113, disable SSL VPN for CVE-2024-21762).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.