logo

Fortinet snafu: Critical FortiSIEM CVEs are duplicates, issued in error

ID: 2603fbb2-a554-5d3f-a487-e544f63ab7f7

STIX ID: report--2603fbb2-a554-5d3f-a487-e544f63ab7f7

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2024-02-07

Date Updated: 2026-04-20

Author: Ax Sharma

...
...

Fortinet has listed two new CVEs (CVE-2024-23108 and CVE-2024-23109) as variants/patch-bypasses of a previously disclosed critical unauthenticated RCE in FortiSIEM (CVE-2023-34992). Fortinet initially said the new CVEs were created in error but later confirmed they are similar variants; fixes are available or planned for multiple FortiSIEM versions (including 7.1.2+ and upcoming 7.2.0+, 7.0.3+, etc.). While Fortinet reports no observed active exploitation, the advisory stresses upgrading to patched versions promptly because Fortinet products are commonly targeted by threat actors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.