CVE-2024-21762 and CVE-2024-23113: Multiple Critical Vulnerabilities in Fortinet, One Likely Under Active Exploitation
ID: d05f5bb9-28a4-5e42-9686-945ffabccc5b
STIX ID: report--d05f5bb9-28a4-5e42-9686-945ffabccc5b
Feed Name: Arctic Wolf
On 2024-02-08 FortiGuard disclosed two critical FortiOS vulnerabilities — CVE-2024-23113 (format-string) and CVE-2024-21762 (out-of-bounds write) — that could allow unauthenticated actors to execute arbitrary code or commands; FortiGuard noted potential exploitation of CVE-2024-21762 though Arctic Wolf had not found public PoCs. The advisory also documents recent FortiSIEM bypass patches related to CVE-2023-34992 (tracked as CVE-2024-23108 and CVE-2023-24109), lists affected and fixed product versions, and recommends upgrading to patched releases or applying temporary mitigations (remove fgfm access, disable SSL VPN) until patched.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
