CVE-2024-23108
100Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actcvss 9.7epss 78%
from disclosure to weapon105 days
Published on NVDFeb 5
1st PoC+105d
VulnCheck+386d
exploitation probability
78%top 1% of all CVEs
observed exploitation
yesVulnCheck
4 public exploit(s)
In short
A security flaw in Fortinet allows attackers to run unauthorized commands on the system by sending specially crafted requests to an API. This is critical because attackers can take complete control of the affected device.
Technical detail
OS command injection vulnerability in Fortinet API endpoints due to improper input sanitization of special characters. Unauthenticated or low-privileged attackers can inject arbitrary shell commands through crafted API requests, leading to remote code execution with system-level privileges.
Summary generated and translated by AI from the official description.
An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet allows attacker to execute unauthorized code or commands via via crafted API requests.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:F/RL:X/RC:X
Affected products
Fortinet · FortiSIEMpublic PoCs found — 4
cve_referencegithub.com/horizon3ai/CVE-2024-23108★ 34githubgithub.com/hitem/CVE-2024-23108★ 5vulncheckvulncheck.com/xdb/451a60979117unverifiedvulncheckvulncheck.com/xdb/5781d9dd8fd1unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.