Fortinet snafu: Critical FortiSIEM CVEs are duplicates, issued in error
ID: 2603fbb2-a554-5d3f-a487-e544f63ab7f7
STIX ID: report--2603fbb2-a554-5d3f-a487-e544f63ab7f7
Feed Name: Bleeping Computer
Fortinet has listed two new CVEs (CVE-2024-23108 and CVE-2024-23109) as variants/patch-bypasses of a previously disclosed critical unauthenticated RCE in FortiSIEM (CVE-2023-34992). Fortinet initially said the new CVEs were created in error but later confirmed they are similar variants; fixes are available or planned for multiple FortiSIEM versions (including 7.1.2+ and upcoming 7.2.0+, 7.0.3+, etc.). While Fortinet reports no observed active exploitation, the advisory stresses upgrading to patched versions promptly because Fortinet products are commonly targeted by threat actors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
