CVE-2024-23109: OS Command Injection
An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet allows attacker to execute unauthorized code or commands via via crafted API requests.
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-23109?
CVE-2024-23109 is considered to have a critical severity level due to its potential for remote code execution.
How do I fix CVE-2024-23109?
To fix CVE-2024-23109, it is recommended to upgrade FortiSIEM to versions 7.1.2 or higher, 7.0.3 or higher, 6.8.0 or higher, or apply the necessary patches provided by Fortinet.
Which versions of FortiSIEM are affected by CVE-2024-23109?
CVE-2024-23109 affects FortiSIEM versions 6.4.0 through 7.1.1.
What type of vulnerability is CVE-2024-23109?
CVE-2024-23109 is classified as an OS command injection vulnerability.
Can CVE-2024-23109 lead to data breaches?
Yes, CVE-2024-23109 can potentially lead to unauthorized access and data breaches if exploited.