logo

Fortinet warns of new FortiSIEM RCE bugs in confusing disclosure

ID: 7482c50c-8ec0-55d6-9e5e-bea29c00c594

STIX ID: report--7482c50c-8ec0-55d6-9e5e-bea29c00c594

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2024-02-08

Date Updated: 2026-04-20

Author: Ax Sharma

...
...

Fortinet added two CVEs (CVE-2024-23108 and CVE-2024-23109) as patch-bypass variants of the critical FortiSIEM RCE vulnerability CVE-2023-34992; the flaws allow unauthenticated command execution via crafted API requests, Fortinet has listed fixed or upcoming fixed FortiSIEM versions and says there is no confirmed active exploitation, but urgent upgrade is recommended due to high risk and common targeting of Fortinet products.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.