CVE-2024-23108: OS Command Injection
An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet allows attacker to execute unauthorized code or commands via via crafted API requests.
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-23108?
CVE-2024-23108 is considered a critical vulnerability due to its potential for remote code execution.
How do I fix CVE-2024-23108?
To fix CVE-2024-23108, upgrade FortiSIEM to the latest version that is not affected by this vulnerability.
Which versions of FortiSIEM are affected by CVE-2024-23108?
CVE-2024-23108 affects FortiSIEM versions 6.4.0 through 7.1.1 inclusive.
What type of vulnerability is CVE-2024-23108?
CVE-2024-23108 is an os command injection vulnerability, allowing attackers to execute unauthorized commands.
Is there an exploit available for CVE-2024-23108?
Details about specific exploits for CVE-2024-23108 have not been publicly disclosed, but the vulnerability's nature poses significant risks.