Exploit released for maximum severity Fortinet RCE bug, patch now
ID: dd522da2-48e2-57cf-bfca-127f33125af5
STIX ID: report--dd522da2-48e2-57cf-bfca-127f33125af5
Feed Name: Bleeping Computer
Security researchers published a proof-of-concept for CVE-2024-23108, a critical unauthenticated command-injection in Fortinet FortiSIEM enabling remote root execution; Fortinet patched the issue on Feb 8 but the PoC can compromise unpatched, Internet-exposed appliances. The report also references a related RCE (CVE-2024-23109), disclosure confusion with an earlier fix (CVE-2023-34992), and highlights that Fortinet flaws are frequently exploited in ransomware and espionage operations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
