logo

Twin Max-Severity Bugs Open Fortinet's SIEM to Code Execution

ID: cf2d24fd-d736-57fc-9bfb-33a7967bb760

STIX ID: report--cf2d24fd-d736-57fc-9bfb-33a7967bb760

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2024-02-06

Date Updated: 2026-04-21

Author: Becky Bracken, Editor, Dark Reading

...
...

Two critical command-injection vulnerabilities (CVE-2024-23108 and CVE-2024-23109) have been reported in Fortinet FortiSIEM with provisional CVSS scores of 10; they may allow attackers to execute unauthorized code via crafted API requests across multiple FortiSIEM versions, but technical details and evidence of active exploitation are currently limited and Fortinet has not issued additional public information.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.