Exploit for Fortinet Critical RCE Bug Allows SIEM Root AccessExploit for Fortinet Critical RCE Bug Allows SIEM Root Access
Corporate admins should patch the max-severity CVE-2024-23108 immediately, which allows unauthenticated command injection.
![A bunch of blocks, one red with an image of a bug on it A bunch of blocks, one red with an image of a bug on it](https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/blte1070b24fbf6dc63/659dbf58902244040ace8329/bugs_Andrii_Yalanskyi_shutterstock.jpg?width=1280&auto=webp&quality=95&format=jpg&disable=upscale)
A proof-of-concept exploit (PoC) for a critical vulnerability in Fortinet's FortiSIEM product has emerged, paving the way for broad exploitation.
The vulnerability, tracked under CVE-2024-23108, was disclosed and patched in February, along with a related bug, CVE-2024-23109. Both carry max-severity scores of 10 on the CVSS scale, and are unauthenticated command injection flaws that could potentially let threat actors use crafted API requests for remote code execution (RCE).
According to researchers at Horizon3AI, the exploit, which they dubbed "NodeZero," allows users to "blindly execute commands as root on vulnerable FortiSIEM appliances." In their PoC, they used the exploit to load a remote-access tool for post-exploitation activities.
FortiSIEM is Fortinet's security information and event management (SIEM) platform, used for enabling enterprise cybersecurity operations centers. As such, a compromise could offer a significant beachhead for launching further incursions into corporate environments.
FortiSIEM versions impacted by the flaws include version 7.1.0 through 7.1.1; 7.0.0 through 7.0.2; 6.7.0 through 6.7.8; 6.6.0 through 6.6.3; 6.5.0 through 6.5.2; and 6.4.0 through 6.4.2. Users should patch immediately to avoid compromise.
About the Author
You May Also Like
Uncovering Threats to Your Mainframe & How to Keep Host Access Secure
Feb 13, 2025Securing the Remote Workforce
Feb 20, 2025Emerging Technologies and Their Impact on CISO Strategies
Feb 25, 2025How CISOs Navigate the Regulatory and Compliance Maze
Feb 26, 2025Where Does Outsourcing Make Sense for Your Organization?
Feb 27, 2025