logo

Exploit for Fortinet Critical RCE Bug Allows SIEM Root Access

ID: e3756d15-c725-5490-aaca-d32160a14fbb

STIX ID: report--e3756d15-c725-5490-aaca-d32160a14fbb

Feed Name: Dark Reading

Threat Score
90/100

Date Published: 2024-05-29

Date Updated: 2026-04-21

Author: Dark Reading Staff

...
...

A public proof-of-concept exploit for two critical FortiSIEM vulnerabilities (CVE-2024-23108 and CVE-2024-23109, CVSS 10) enables unauthenticated command injection and remote code execution as root; researchers used the PoC to deploy a remote-access tool. Multiple FortiSIEM versions are impacted and users are advised to apply the vendor patches immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.