cbcvebase.
CVE-2024-23109
published 2024-02-05

CVE-2024-23109: An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet allows attacker to execute unauthorized…

PriorityP191critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
ITWVulnCheck KEVRansomware
Exploited in the wild
EPSS
3.22%
86.8th percentile
An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet allows attacker to execute unauthorized code or commands via via crafted API requests.

Affected

9 ranges
VendorProductVersion rangeFixed in
fortinetfortinet
fortinetfortisiem
fortinetfortisiem
fortinetfortisiem
fortinetfortisiem6.4.0 – 6.4.2
fortinetfortisiem6.5.0 – 6.5.2
fortinetfortisiem6.6.0 – 6.6.3
fortinetfortisiem6.7.0 – 6.7.8
fortinetfortisiem7.0.0 – 7.0.2

Detection & IOCsextracted from sources · hover to see the quote

  • Attempts to exploit CVE-2024-23108/CVE-2024-23109 will leave a log message containing a failed command with datastore.py nfs test — monitor FortiSIEM logs for this pattern as an exploitation indicator.
  • The root cause is a second-order command injection when certain parameters to datastore.py are sent; inspect process execution logs on FortiSIEM appliances for unexpected child processes spawned by datastore.py.
  • ·A public PoC exploit has been released by Horizon3's Attack Team, enabling command execution as root on any internet-exposed unpatched FortiSIEM appliance, significantly raising exploitation risk.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vulncheck10.0CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.