cbcvebase.
CVE-2024-23113
published 2024-02-15

CVE-2024-23113: A use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, FortiProxy versions…

PriorityP195critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2024-10-30
Exploited in the wild
EPSS
61.72%
99.1th percentile
A use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, FortiProxy versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0.14, FortiPAM versions 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiSwitchManager versions 7.2.0 through 7.2.3, 7.0.0 through 7.0.3 allows attacker to execute unauthorized code or commands via specially crafted packets.

Affected

16 ranges
VendorProductVersion rangeFixed in
fortinetfortinet
fortinetfortios
fortinetfortios7.0.0 – 7.0.13
fortinetfortios7.2.0 – 7.2.6
fortinetfortios7.4.0 – 7.4.2
fortinetfortipam
fortinetfortipam
fortinetfortipam1.0.0 – 1.0.3
fortinetfortipam1.1.0 – 1.1.2
fortinetfortiproxy
fortinetfortiproxy7.0.0 – 7.0.14
fortinetfortiproxy7.2.0 – 7.2.8
fortinetfortiproxy7.4.0 – 7.4.2
fortinetfortiswitchmanager
fortinetfortiswitchmanager7.0.0 – 7.0.3
fortinetfortiswitchmanager7.2.0 – 7.2.3

Detection & IOCsextracted from sources · hover to see the quote

processfgfmd
  • Monitor for anomalous or specially crafted packets targeting the fgfmd daemon on FortiGate/FortiManager devices; fgfmd handles all authentication requests and keep-alive messages and is the direct attack surface for CVE-2024-23113.
  • Alert on unauthenticated inbound FGFM protocol connections from unexpected or untrusted IP addresses; a local-in policy restricting FGFM connections to specific IPs reduces attack surface but does not fully prevent exploitation.
  • Detect exploitation attempts by monitoring for anomalous HTTP activity including requests originating from suspicious IP ranges or users without corresponding session logs, as well as changes in configuration files, unauthorized system reboots, or the presence of unrecognized executables.
  • Use HIDS and SIEM custom rules to identify known exploit signatures targeting FortiOS HTTP/HTTPS request patterns consistent with CVE-2024-23113 exploitation.
  • Adversaries actively scan for exposed FortiGate interfaces on the internet before exploiting CVE-2024-23113; monitor for internet-facing FortiGate management interface exposure and inbound scanning activity.
  • ·Restricting FGFM via local-in policy to a specific IP is only a partial mitigation — exploitation is still possible from that allowed IP and should not be treated as a complete workaround.
  • ·CVE-2024-23113 only affects more recent product versions dating back to March 2022; older FortiOS versions are not impacted.
  • ·FortiSwitchManager versions 7.2.0–7.2.3 and 7.0.0–7.0.3 are also affected by CVE-2024-23113 but are not listed in all advisories; ensure these are included in patching scope.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vulncheck9.8CRITICAL
cisa9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.