CVE-2024-23109
📊 10.0 CRITICAL⚡ 5.0%🎯 0 exploits
📅 Published Feb 5, 2024
📋 Status: Modified
An improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiSIEM version 7.1.0 through 7.1.1 and 7.0.0 through 7.0.2 and 6.7.0 through 6.7.8 and 6.6.0 through 6.6.3 and 6.5.0 through 6.5.2 and 6.4.0 through 6.4.2 allows attacker to execute unauthorized code or commands via via crafted API requests.
CVSS v3.1 • [email protected]
🎯 Affected Products & Systems
7 product configurations affected
Filter by type:
| Type | Vendor | Product | Version Range | Status | CPE String |
|---|---|---|---|---|---|
📱App | fortinet | fortisiem | ≥ 6.4.0 ∧ ≤ 6.4.2 | Vulnerable | cpe:2.3:a:fortinet:fortisiem:*:*:*:*:*:*:*:* |
📱App | fortinet | fortisiem | ≥ 6.5.0 ∧ ≤ 6.5.2 | Vulnerable | cpe:2.3:a:fortinet:fortisiem:*:*:*:*:*:*:*:* |
📱App | fortinet | fortisiem | ≥ 6.6.0 ∧ ≤ 6.6.3 | Vulnerable | cpe:2.3:a:fortinet:fortisiem:*:*:*:*:*:*:*:* |
📱App | fortinet | fortisiem | ≥ 6.7.0 ∧ ≤ 6.7.8 | Vulnerable | cpe:2.3:a:fortinet:fortisiem:*:*:*:*:*:*:*:* |
📱App | fortinet | fortisiem | ≥ 7.0.0 ∧ ≤ 7.0.2 | Vulnerable | cpe:2.3:a:fortinet:fortisiem:*:*:*:*:*:*:*:* |
📱App | fortinet | fortisiem | 7.1.0 | Vulnerable | cpe:2.3:a:fortinet:fortisiem:7.1.0:*:*:*:*:*:*:* |
📱App | fortinet | fortisiem | 7.1.1 | Vulnerable | cpe:2.3:a:fortinet:fortisiem:7.1.1:*:*:*:*:*:*:* |
Version: ≥ 6.4.0 ∧ ≤ 6.4.2
CPE:
cpe:2.3:a:fortinet:fortisiem:*:*:*:*:*:*:*:*
Version: ≥ 6.5.0 ∧ ≤ 6.5.2
CPE:
cpe:2.3:a:fortinet:fortisiem:*:*:*:*:*:*:*:*
Version: ≥ 6.6.0 ∧ ≤ 6.6.3
CPE:
cpe:2.3:a:fortinet:fortisiem:*:*:*:*:*:*:*:*
Version: ≥ 6.7.0 ∧ ≤ 6.7.8
CPE:
cpe:2.3:a:fortinet:fortisiem:*:*:*:*:*:*:*:*
Version: ≥ 7.0.0 ∧ ≤ 7.0.2
CPE:
cpe:2.3:a:fortinet:fortisiem:*:*:*:*:*:*:*:*
Version: 7.1.0
CPE:
cpe:2.3:a:fortinet:fortisiem:7.1.0:*:*:*:*:*:*:*
7 products•scroll for more
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Attack Vector:
NETWORK
Complexity:
LOW
Privileges:
NONE
User Interaction:
NONE
Confidentiality:
HIGH
Integrity:
HIGH
Availability:
HIGH
Scope:
CHANGED
🔍 Technical Details
Analysis Status
ModifiedCVSS Details
10.0 (CRITICAL)v3.1
Source: [email protected]
EPSS Details
5.0% (Minimal)89.2th percentile
Last updated: Oct 31, 2025
Exploitation probability within 30 days
Published Date
Feb 5, 2024 (1 year ago)
Last Modified
Nov 21, 2024 (11 months ago)
Security Weaknesses2
CWE-78
References2
NVDgeneral