CVE-2024-23108
published 2024-02-05CVE-2024-23108: An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet allows attacker to execute unauthorized…
PriorityP197critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
ITWEXPLOITVulnCheck KEVRansomwareInitial access
Exploited in the wild
EPSS
78.38%
99.5th percentile
An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet allows attacker to execute unauthorized code or commands via via crafted API requests.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortinet | — | — |
| fortinet | fortisiem | — | — |
| fortinet | fortisiem | — | — |
| fortinet | fortisiem | — | — |
| fortinet | fortisiem | 6.4.0 – 6.4.2 | — |
| fortinet | fortisiem | 6.5.0 – 6.5.2 | — |
| fortinet | fortisiem | 6.6.0 – 6.6.3 | — |
| fortinet | fortisiem | 6.7.0 – 6.7.8 | — |
| fortinet | fortisiem | 7.0.0 – 7.0.2 | — |
| fortinet | fortisiem | 7.1.0 – 7.1.1 | — |
Detection & IOCsextracted from sources · hover to see the quote
snort
alert tcp any any -> $HOME_NET 7900 (msg:"ET EXPLOIT Fortinet FortiSIEM Unauthenticated Command Injection CVE-2024-23108"; flow:established,to_server; content:"|51 00 00 00|"; startswith; content:"]*>[^\x3b/Rsi"; reference:url,horizon3.ai/attack-research/cve-2024-23108-fortinet-fortisiem-2nd-order-command-injection-deep-dive/; reference:cve,2024-23108; classtype:misc-attack; sid:2052889; rev:1; metadata:attack_target Server, created_at 2024_05_28, cve CVE_2024_23108, deployment Perimeter, deployment Internal, confidence High, signature_severity Major, tag Exploit, updated_at 2024_05_28, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique_name Exploit_Public_Facing_Application;)
bytes↗
\x51\x00\x00\x00\x74\x00\x00\x00\x6f\x42\x1e\x40\x00\x00\x00\x00
bytes
|51 00 00 00|
- →Monitor TCP port 7900 (Phoenix Monitor service) for inbound connections, especially from untrusted/external sources. Exploit traffic begins with the byte sequence 51 00 00 00.
- →Search FortiSIEM logs for 'PHL_ERROR' entries referencing 'datastore.py nfs test' — this is the specific log artifact left by exploitation attempts. ↗
- →Inspect /opt/phoenix/log/phoenix.logs for 'PHL_ERROR' lines that include a payload URL and a target file path, indicating active exploitation of the phMonitor service. ↗
- →The vulnerability is triggered via XML parsing of TEST_STORAGE elements where the mount_point field is injected with shell metacharacters (e.g., semicolons). Look for crafted XML with unsanitized mount_point values in traffic to port 7900.
- →Use Shodan/FOFA queries to identify exposed FortiSIEM instances: search for port 7900, favicon hash -1341442175, or the HTML string 'var hst = location.hostname'.
- →The exploit is a second-order command injection bypassing the wrapShellToken() fix applied for CVE-2023-34992. Detection should account for parameters passed to datastore.py, not just direct shell invocations. ↗
- ·The Nuclei template targets TLS-wrapped TCP on port 7900 specifically. Ensure TLS inspection is enabled on network monitoring tools to decode and inspect this traffic.
- ·The Snort/ET rule uses 'startswith' on the |51 00 00 00| byte sequence, meaning it only fires on the very beginning of the TCP stream. Ensure your IDS/IPS is configured for stream reassembly and startswith matching on port 7900.
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vulncheck10.0CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Fortinet
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet...
vendor_fortinet·2023-10-10·CVSS 10.0
CVE-2023-34992 [CRITICAL] CWE-78 A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet...
FG-IR-23-130: A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet...
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet allows attacker to execute unauthorized code or commands via crafted API requests.
An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet allows attacker to execute unauthorized code or commands via via crafted API requests.
CVEs: CVE-2023-34992, CVE-2024-23108, CVE-2024-23109
CWEs: CWE-78
CVSS: 10.0 (critical)
Affected products: FortiSIEM, Fortinet
GHSA
GHSA-chj3-8q43-rcc8: An improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiSIEM version 7
ghsa_unreviewed·2024-02-05
CVE-2024-23108 [CRITICAL] CWE-78 GHSA-chj3-8q43-rcc8: An improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiSIEM version 7
An improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiSIEM version 7.1.0 through 7.1.1 and 7.0.0 through 7.0.2 and 6.7.0 through 6.7.8 and 6.6.0 through 6.6.3 and 6.5.0 through 6.5.2 and 6.4.0 through 6.4.2 allows attacker to execute unauthorized code or commands via via crafted API requests.
VulnCheck
Fortinet FortiSIEM Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
vulncheck·2024·CVSS 10.0
CVE-2024-23108 [CRITICAL] Fortinet FortiSIEM Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Fortinet FortiSIEM Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet allows attacker to execute unauthorized code or commands via via crafted API requests.
Affected: Fortinet FortiSIEM
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Known Ransomware Campaign Use: Known
Exploitation References: https://blog.qualys.com/vulnerabilities-threat-research/2025/02/25/defense-lessons-from-the-black-basta-ransomware-playbook; https://www.trustwave.com/hubfs/Web/Library/Documents_pdf/A_Deep_Dive_into_the_Leaked_Black_Basta_Chat_Log
Suricata
ET EXPLOIT Fortinet FortiSIEM Unauthenticated Command Injection CVE-2024-23108
suricata·2024-05-28·CVSS 10.0
CVE-2024-23108 [CRITICAL] ET EXPLOIT Fortinet FortiSIEM Unauthenticated Command Injection CVE-2024-23108
ET EXPLOIT Fortinet FortiSIEM Unauthenticated Command Injection CVE-2024-23108
Rule: alert tcp any any -> $HOME_NET 7900 (msg:"ET EXPLOIT Fortinet FortiSIEM Unauthenticated Command Injection CVE-2024-23108"; flow:established,to_server; content:"|51 00 00 00|"; startswith; content:"]*>[^\x3b/Rsi"; reference:url,horizon3.ai/attack-research/cve-2024-23108-fortinet-fortisiem-2nd-order-command-injection-deep-dive/; reference:cve,2024-23108; classtype:misc-attack; sid:2052889; rev:1; metadata:attack_target Server, created_at 2024_05_28, cve CVE_2024_23108, deployment Perimeter, deployment Internal, confidence High, signature_severity Major, tag Exploit, updated_at 2024_05_28, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique_name Exploit_Public_
Nuclei
Fortinet FortiSIEM - OS Command Injection
nuclei·CVSS 9.8
CVE-2024-23108 [CRITICAL] Fortinet FortiSIEM - OS Command Injection
Fortinet FortiSIEM - OS Command Injection
FortiSIEM versions 6.4.0 through 7.1.1 contain an OS command injection vulnerability in the Phoenix Monitor service. The vulnerability exists in the XML parsing of TEST_STORAGE elements where the mount_point field is not properly sanitized before being passed to shell commands, allowing unauthenticated remote code execution.
Template:
id: CVE-2024-23108
info:
name: Fortinet FortiSIEM - OS Command Injection
author: 0x_Akoko
severity: critical
description: |
FortiSIEM versions 6.4.0 through 7.1.1 contain an OS command injection vulnerability in the Phoenix Monitor service. The vulnerability exists in the XML parsing of TEST_STORAGE elements where the mount_point field is not properly sanitized before being passed to shell commands, allowing unaut
Bleepingcomputer
Exploit code public for critical FortiSIEM command injection flaw
blogs_bleepingcomputer·2026-01-14·CVSS 10.0
CVE-2025-64155 [CRITICAL] Exploit code public for critical FortiSIEM command injection flaw
## Exploit code public for critical FortiSIEM command injection flaw
## Bill Toulas
Technical details and a public exploit have been published for a critical vulnerability affecting Fortinet's Security Information and Event Management (SIEM) solution that could be leveraged by a remote, unauthenticated attacker to execute commands or code.
The vulnerability is tracked as CVE-2025-64155, and is a combination of two issues that permit arbitrary write with admin permissions and privilege escalation to root access.
Researchers at penetration testing company Horizon3.ai reported the security issue in mid-August 2025, but it was only fixed on January 13, 2026.
Fortinet describes the CVE-2025-64155 vulnerability as "an improper neutralization of special elements used in an OS command vulnera
Greynoiseio
GreyNoise Detects Active Exploitation of CVEs Mentioned in Black Basta’s Leaked Chat Logs
blogs_greynoiseio·2025-02-26·CVSS 9.8
[CRITICAL] GreyNoise Detects Active Exploitation of CVEs Mentioned in Black Basta’s Leaked Chat Logs
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
Qualys
Defense Lessons From the Black Basta Ransomware Playbook
blogs_qualys·2025-02-25
Defense Lessons From the Black Basta Ransomware Playbook
## Table of Contents
Know Your Enemys Playbook
Attackers Move Fast
How Qualys Can Help
The cybersecurity world was rocked last week by a massive leak of Black Basta’s internal communications that emerged from the group’s chat logs. Triggered by internal conflicts and a retaliatory data dump following attacks on Russian banks, the exposed records offer a rare glimpse into Black Basta’s tactics, operations, and leadership.
We’ve analyzed these newly unveiled tactics, and in this blog, we equip security teams with clear, actionable insights. We aim to highlight the key lessons learned—like immediate patching, tighter access controls, and rapid incident response—and provide an urgent call to action. This practical guide aims to help organizations strengthen their defenses against evolving
Qualys
Defense Lessons From the Black Basta Ransomware Playbook | Qualys
blogs_qualys·2025-02-25
Defense Lessons From the Black Basta Ransomware Playbook | Qualys
#### Table of Contents
- Know Your Enemys Playbook
- Attackers Move Fast
- How Qualys Can Help
The cybersecurity world was rocked last week by a massive leak of Black Basta’s internal communications that emerged from the group’s chat logs. Triggered by internal conflicts and a retaliatory data dump following attacks on Russian banks, the exposed records offer a rare glimpse into Black Basta’s tactics, operations, and leadership.
We’ve analyzed these newly unveiled tactics, and in this blog, we equip security teams with clear, actionable insights. We aim to highlight the key lessons learned—like immediate patching, tighter access controls, and rapid incident response—and provide an urgent call to action. This practical guide aims to help organizations strengthen their defenses against ev
Bleepingcomputer
Exploit released for maximum severity Fortinet RCE bug, patch now
blogs_bleepingcomputer·2024-05-28·CVSS 10.0
CVE-2024-23108 [CRITICAL] Exploit released for maximum severity Fortinet RCE bug, patch now
## Exploit released for maximum severity Fortinet RCE bug, patch now
## Sergiu Gatlan
Security researchers have released a proof-of-concept (PoC) exploit for a maximum-severity vulnerability in Fortinet's security information and event management (SIEM) solution, which was patched in February.
Tracked as CVE-2024-23108 , this security flaw is a command injection vulnerability discovered and reported by Horizon3 vulnerability expert Zach Hanley that enables remote command execution as root without requiring authentication.
"Multiple improper neutralization of special elements used in an OS Command vulnerability [CWE-78] in FortiSIEM supervisor may allow a remote unauthenticated attacker to execute unauthorized commands via crafted API requests," Fortinet says .
CVE-2024-23108 impacts
Wiz
Crying Out Cloud - March 2024 Newsletter | Wiz
blogs_wiz·2024-03-01·CVSS 8.6
CVE-2024-21626 [HIGH] Crying Out Cloud - March 2024 Newsletter | Wiz
Welcome back! In this edition, we bring you the latest in cloud security – crucial vulnerabilities, exclusive data, and noteworthy incidents. Stay informed and stay secure. Let's delve in.
Here are our cloud security highlights!
## 🐞 High Profile Vulnerabilities
Leaky Vessels: Docker and runc Container Escape Vulnerabilities
Several vulnerabilities have been revealed in the runC command line tool (CVE-2024-21626, CVE-2024-23651, CVE-2024-23652, and CVE-2024-23653). These flaws pose a risk of container escape, exploiting these vulnerabilities could grant unauthorized access to the host operating system, potentially compromising sensitive data and facilitating further attacks, particularly with superuser privileges.
According to Wiz data, 18% percent of cloud environments have resources
Bleepingcomputer
New Fortinet RCE bug is actively exploited, CISA confirms
blogs_bleepingcomputer·2024-02-09·CVSS 10.0
CVE-2024-21762 [CRITICAL] New Fortinet RCE bug is actively exploited, CISA confirms
## New Fortinet RCE bug is actively exploited, CISA confirms
## Sergiu Gatlan
CISA confirmed today that attackers are actively exploiting a critical remote code execution (RCE) bug patched by Fortinet on Thursday.
The flaw (CVE-2024-21762) is due to an out-of-bounds write weakness in the FortiOS operating system and the FortiProxy secure web proxy that can let unauthenticated attackers execute arbitrary code remotely using maliciously crafted HTTP requests.
Admins who can't immediately deploy security updates to patch vulnerable appliances can remove the attack vector by disabling SSL VPN on the device.
CISA's announcement comes one day after Fortinet published a security advisory saying the flaw was "potentially being exploited in the wild."
While the company has yet to share more d
Bleepingcomputer
Fortinet warns of new FortiSIEM RCE bugs in confusing disclosure
blogs_bleepingcomputer·2024-02-07·CVSS 10.0
CVE-2024-23108 [CRITICAL] Fortinet warns of new FortiSIEM RCE bugs in confusing disclosure
## Fortinet warns of new FortiSIEM RCE bugs in confusing disclosure
## Lawrence Abrams
Fortinet is warning of two new unpatched patch bypasses for a critical remote code execution vulnerability in FortiSIEM, Fortinet's SIEM solution.
Fortinet added the two new vulnerabilities tracked as CVE-2024-23108 and CVE-2024-23109 to the original advisory for the CVE-2023-34992 flaw in a very confusing update.
Earlier today, BleepingComputer published an article that the CVEs were released by mistake after being told by Fortinet that they were duplicates of the original CVE-2023-34992.
"In this instance, due to an issue with the API which we are currently investigating, rather than an edit, this resulted in two new CVEs being created, duplicates of the original CVE-2023-34992," Fortinet told Ble
Sentinelone
Black Basta
blogs_sentinelone·2022-11-30
Black Basta
How It Works The Singularity XDR Difference
Singularity Marketplace One-Click Integrations to Unlock the Power of XDR
Pricing & Packaging Comparisons and Guidance at a Glance
Purple AI Accelerate SecOps with Generative AI
Singularity Hyperautomation Easily Automate Security Processes
AI-SIEM The AI SIEM for the Autonomous SOC
Singularity Data Lake AI-Powered, Unified Data Lake
Singularity Data Lake for Log Analytics Seamlessly Ingest Data from On-Prem, Cloud or Hybrid Environments
Singularity Endpoint Autonomous Prevention, Detection, and Response
Singularity XDR Native & Open Protection, Detection, and Response
Singularity RemoteOps Forensics Orchestrate Forensics at Scale
Singularity
Threat Intelligence Comprehensive Adversary Intelligence
Singularity Vulnerability Management
Sentinelone
Black Basta
blogs_sentinelone
Black Basta
# Black Basta Ransomware: In-Depth Analysis, Detection, and Mitigation
## Summary of Black Basta Ransomware
Black Basta first emerged in early 2022. The ransomware family is an evolution of the Hermes/Ryuk/Conti families. Black Basta was heavily advertised in underground cybercrime markets. Black Basta practices double extortion – demanding payment for a decryptor, as well as for the non-release of stolen data. There are Windows and LInux variants of Black Basta ransomware. The group is responsible for hundreds of attacks against global targets of varying sectors.
February 2025 Update: Nearly a year’s worth of Black Basta chat logs have been released on Telegram, providing detailed insight into the groups operational workflow, reconnaissance activities, and specific userID and details o
2024-02-05
Published
Exploited in the wild