CVE-2024-23113
published 2024-02-15CVE-2024-23113: A use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, FortiProxy versions…
PriorityP195critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2024-10-30
Exploited in the wild
EPSS
61.72%
99.1th percentile
A use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, FortiProxy versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0.14, FortiPAM versions 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiSwitchManager versions 7.2.0 through 7.2.3, 7.0.0 through 7.0.3 allows attacker to execute unauthorized code or commands via specially crafted packets.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortinet | — | — |
| fortinet | fortios | — | — |
| fortinet | fortios | 7.0.0 – 7.0.13 | — |
| fortinet | fortios | 7.2.0 – 7.2.6 | — |
| fortinet | fortios | 7.4.0 – 7.4.2 | — |
| fortinet | fortipam | — | — |
| fortinet | fortipam | — | — |
| fortinet | fortipam | 1.0.0 – 1.0.3 | — |
| fortinet | fortipam | 1.1.0 – 1.1.2 | — |
| fortinet | fortiproxy | — | — |
| fortinet | fortiproxy | 7.0.0 – 7.0.14 | — |
| fortinet | fortiproxy | 7.2.0 – 7.2.8 | — |
| fortinet | fortiproxy | 7.4.0 – 7.4.2 | — |
| fortinet | fortiswitchmanager | — | — |
| fortinet | fortiswitchmanager | 7.0.0 – 7.0.3 | — |
| fortinet | fortiswitchmanager | 7.2.0 – 7.2.3 | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor for anomalous or specially crafted packets targeting the fgfmd daemon on FortiGate/FortiManager devices; fgfmd handles all authentication requests and keep-alive messages and is the direct attack surface for CVE-2024-23113. ↗
- →Alert on unauthenticated inbound FGFM protocol connections from unexpected or untrusted IP addresses; a local-in policy restricting FGFM connections to specific IPs reduces attack surface but does not fully prevent exploitation. ↗
- →Detect exploitation attempts by monitoring for anomalous HTTP activity including requests originating from suspicious IP ranges or users without corresponding session logs, as well as changes in configuration files, unauthorized system reboots, or the presence of unrecognized executables. ↗
- →Use HIDS and SIEM custom rules to identify known exploit signatures targeting FortiOS HTTP/HTTPS request patterns consistent with CVE-2024-23113 exploitation. ↗
- →Adversaries actively scan for exposed FortiGate interfaces on the internet before exploiting CVE-2024-23113; monitor for internet-facing FortiGate management interface exposure and inbound scanning activity. ↗
- ·Restricting FGFM via local-in policy to a specific IP is only a partial mitigation — exploitation is still possible from that allowed IP and should not be treated as a complete workaround. ↗
- ·CVE-2024-23113 only affects more recent product versions dating back to March 2022; older FortiOS versions are not impacted. ↗
- ·FortiSwitchManager versions 7.2.0–7.2.3 and 7.0.0–7.0.3 are also affected by CVE-2024-23113 but are not listed in all advisories; ensure these are included in patching scope. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vulncheck9.8CRITICAL
cisa9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
Fortinet Multiple Products Format String Vulnerability
cisa·2024-10-09·CVSS 9.8
CVE-2024-23113 [CRITICAL] CWE-134 Fortinet Multiple Products Format String Vulnerability
Vulnerability: Fortinet Multiple Products Format String Vulnerability
Affected: Fortinet Multiple Products
Fortinet FortiOS, FortiPAM, FortiProxy, and FortiWeb contain a format string vulnerability that allows a remote, unauthenticated attacker to execute arbitrary code or commands via specially crafted requests.
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Notes: https://www.fortiguard.com/psirt/FG-IR-24-029 ; https://nvd.nist.gov/vuln/detail/CVE-2024-23113
Remediation Due Date: 2024-10-30
CISA ICS
Siemens RUGGEDCOM APE1808
cisa_ics·2024-03-14
Siemens RUGGEDCOM APE1808
ICS Advisory
##
Siemens RUGGEDCOM APE1808
Release DateMarch 14, 2024
Alert CodeICSA-24-074-05
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v4 8.7
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: RUGGEDCOM APE1808
- Vulnerabilities: Heap-based Buffer Overflow, External Control of File Name or Path, Improper Privilege Management, Uncontrolled Resource Consumption, Improper Certificate Validation, Out-of-bounds Write,
Fortinet
Format String Bug in fgfmd
vendor_fortinet·2024-02-15·CVSS 9.8
CVE-2024-23113 [CRITICAL] CWE-134 Format String Bug in fgfmd
FG-IR-24-029: Format String Bug in fgfmd
A use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, FortiProxy versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0.14, FortiPAM versions 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiSwitchManager versions 7.2.0 through 7.2.3, 7.0.0 through 7.0.3 allows attacker to execute unauthorized code or commands via specially crafted packets.
CVEs: CVE-2024-23113
CWEs: CWE-134
CVSS: 9.8 (critical)
Affected products: FortiOS, FortiPAM, FortiProxy, FortiSwitchManager, FortiSwitchmanager, Fortinet
GHSA
GHSA-57pf-f69p-p222: A use of externally-controlled format string in Fortinet FortiOS versions 7
ghsa_unreviewed·2024-02-15
CVE-2024-23113 [CRITICAL] CWE-134 GHSA-57pf-f69p-p222: A use of externally-controlled format string in Fortinet FortiOS versions 7
A use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, FortiProxy versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0.14, FortiPAM versions 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiSwitchManager versions 7.2.0 through 7.2.3, 7.0.0 through 7.0.3 allows attacker to execute unauthorized code or commands via specially crafted packets.
VulnCheck
Fortinet Multiple Products Format String Vulnerability
vulncheck·2024·CVSS 9.8
CVE-2024-23113 [CRITICAL] CWE-134 Fortinet Multiple Products Format String Vulnerability
Fortinet Multiple Products Format String Vulnerability
Fortinet FortiOS, FortiPAM, FortiProxy, and FortiWeb contain a format string vulnerability that allows a remote, unauthenticated attacker to execute arbitrary code or commands via specially crafted requests.
Affected: Fortinet Multiple Products
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Exploitation References: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://www.cert.govt.nz/advisories/rce-vulnerability-affecting-fortinet-products/; https://x.com/mattjay/status/1857183112662520252; https://www4.orangecyberdefense.com/security-navigator-2025-en; https://cdn.prod.website-files.com/626ff4d25aca2edf4325ff97/67b
Suricata
ET EXPLOIT Fortinet FortiManager File Transfer Handle Response
suricata·2024-11-18·CVSS 9.8
CVE-2024-47575 [CRITICAL] ET EXPLOIT Fortinet FortiManager File Transfer Handle Response
ET EXPLOIT Fortinet FortiManager File Transfer Handle Response
Rule: alert tcp $HOME_NET 541 -> any any (msg:"ET EXPLOIT Fortinet FortiManager File Transfer Handle Response"; flow:established,to_client; flowbits:isset,ET.FMFG_CVE-2024-47575; content:"|36 e0 11 00|"; startswith; content:"action|3d|ack"; fast_pattern; distance:4; content:"localid|3d|"; content:"remoteid|3d|"; reference:url,labs.watchtowr.com/hop-skip-fortijump-fortijumphigher-cve-2024-23113-cve-2024-47575/; classtype:attempted-admin; sid:2057691; rev:1; metadata:affected_product FortiManager, attack_target Server, tls_state TLSDecrypt, created_at 2024_11_18, cve CVE_2024_47575, deployment Perimeter, deployment Internal, deployment SSLDecrypt, confidence High, signature_severity Major, tag Exploit, tag CISA_KEV, updated_at 2
Suricata
ET EXPLOIT Fortinet FortiManager Unauthenticated Remote Code Execution (CVE-2024-47575) M1
suricata·2024-11-18·CVSS 9.8
CVE-2024-47575 [CRITICAL] ET EXPLOIT Fortinet FortiManager Unauthenticated Remote Code Execution (CVE-2024-47575) M1
ET EXPLOIT Fortinet FortiManager Unauthenticated Remote Code Execution (CVE-2024-47575) M1
Rule: alert tcp any any -> $HOME_NET 541 (msg:"ET EXPLOIT Fortinet FortiManager Unauthenticated Remote Code Execution (CVE-2024-47575) M1"; flow:established,to_server; content:"|36 e0 11 00|"; startswith; content:"channel|0d 0a|"; distance:4; content:"remoteid|3d|"; content:"/som/export"; fast_pattern; content:"|22|file|22 3a|"; pcre:"/^.*?[\x3b\x0a\x26\x60\x7c\x24]/R"; reference:url,labs.watchtowr.com/hop-skip-fortijump-fortijumphigher-cve-2024-23113-cve-2024-47575/; reference:cve,2024-47575; classtype:attempted-admin; sid:2057692; rev:1; metadata:affected_product FortiManager, attack_target Server, tls_state TLSDecrypt, created_at 2024_11_18, cve CVE_2024_47575, deployment Perimeter, deployment In
Suricata
ET EXPLOIT Fortinet FortiManager Unauthenticated Get File Transfer Handle
suricata·2024-11-18·CVSS 9.8
CVE-2024-47575 [CRITICAL] ET EXPLOIT Fortinet FortiManager Unauthenticated Get File Transfer Handle
ET EXPLOIT Fortinet FortiManager Unauthenticated Get File Transfer Handle
Rule: alert tcp any any -> $HOME_NET 541 (msg:"ET EXPLOIT Fortinet FortiManager Unauthenticated Get File Transfer Handle"; flow:established,to_server; flowbits:set,ET.FMFG_CVE-2024-47575; content:"|36 e0 11 00|"; startswith; content:"get file_exchange|0d 0a|"; fast_pattern; distance:4; reference:url,labs.watchtowr.com/hop-skip-fortijump-fortijumphigher-cve-2024-23113-cve-2024-47575/; classtype:attempted-admin; sid:2057690; rev:1; metadata:affected_product FortiManager, attack_target Server, tls_state TLSDecrypt, created_at 2024_11_18, cve CVE_2024_47575, deployment Perimeter, deployment Internal, deployment SSLDecrypt, confidence High, signature_severity Major, tag Exploit, tag CISA_KEV, updated_at 2024_11_18, mitre
Suricata
ET EXPLOIT Fortinet FGFM Arbitrary Code Execution via Externally-Controlled Format String (CVE-2024-23113)
suricata·2024-10-18·CVSS 9.8
CVE-2024-23113 [CRITICAL] ET EXPLOIT Fortinet FGFM Arbitrary Code Execution via Externally-Controlled Format String (CVE-2024-23113)
ET EXPLOIT Fortinet FGFM Arbitrary Code Execution via Externally-Controlled Format String (CVE-2024-23113)
Rule: alert tcp any any -> $HOME_NET 541 (msg:"ET EXPLOIT Fortinet FGFM Arbitrary Code Execution via Externally-Controlled Format String (CVE-2024-23113)"; flow:established,to_server; content:"|36 e0 11 00|"; startswith; content:"reply|20|200|0d 0a|"; fast_pattern; distance:4; content:"request|3d|auth|0d 0a|"; pcre:"/\x0d\x0a(authip|fmg_fqdn|mgmtip)\x3d[^\x0d\x0a]*?(?:\x25(?:(?:d|ul?|x|s|c|h?(?:n|p))|\d|\x2a|\x2e|\x5c?\x24)+)+/"; reference:url,labs.watchtowr.com/fortinet-fortigate-cve-2024-23113-a-super-complex-vulnerability-in-a-super-secure-appliance-in-2024/; reference:cve,2024-23113; classtype:attempted-admin; sid:2056730; rev:1; metadata:attack_target Server, tls_state TLSDecryp
No public exploits indexed.
Tenable
Reducing Remediation Time Remains a Challenge: How Tenable Vulnerability Watch Can Help
blogs_tenable·2025-04-25
Reducing Remediation Time Remains a Challenge: How Tenable Vulnerability Watch Can Help
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Verizon 2025 DBIR: Tenable Research Collaboration Shines a Spotlight on CVE Remediation Trends
blogs_tenable·2025-04-23
Verizon 2025 DBIR: Tenable Research Collaboration Shines a Spotlight on CVE Remediation Trends
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Greynoiseio
GreyNoise Detects Active Exploitation of CVEs Mentioned in Black Basta’s Leaked Chat Logs
blogs_greynoiseio·2025-02-26·CVSS 9.8
[CRITICAL] GreyNoise Detects Active Exploitation of CVEs Mentioned in Black Basta’s Leaked Chat Logs
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
Qualys
Defense Lessons From the Black Basta Ransomware Playbook
blogs_qualys·2025-02-25
Defense Lessons From the Black Basta Ransomware Playbook
## Table of Contents
Know Your Enemys Playbook
Attackers Move Fast
How Qualys Can Help
The cybersecurity world was rocked last week by a massive leak of Black Basta’s internal communications that emerged from the group’s chat logs. Triggered by internal conflicts and a retaliatory data dump following attacks on Russian banks, the exposed records offer a rare glimpse into Black Basta’s tactics, operations, and leadership.
We’ve analyzed these newly unveiled tactics, and in this blog, we equip security teams with clear, actionable insights. We aim to highlight the key lessons learned—like immediate patching, tighter access controls, and rapid incident response—and provide an urgent call to action. This practical guide aims to help organizations strengthen their defenses against evolving
Qualys
Defense Lessons From the Black Basta Ransomware Playbook | Qualys
blogs_qualys·2025-02-25
Defense Lessons From the Black Basta Ransomware Playbook | Qualys
#### Table of Contents
- Know Your Enemys Playbook
- Attackers Move Fast
- How Qualys Can Help
The cybersecurity world was rocked last week by a massive leak of Black Basta’s internal communications that emerged from the group’s chat logs. Triggered by internal conflicts and a retaliatory data dump following attacks on Russian banks, the exposed records offer a rare glimpse into Black Basta’s tactics, operations, and leadership.
We’ve analyzed these newly unveiled tactics, and in this blog, we equip security teams with clear, actionable insights. We aim to highlight the key lessons learned—like immediate patching, tighter access controls, and rapid incident response—and provide an urgent call to action. This practical guide aims to help organizations strengthen their defenses against ev
Bleepingcomputer
CISA says critical Fortinet RCE flaw now exploited in attacks
blogs_bleepingcomputer·2024-10-09·CVSS 9.8
CVE-2024-23113 [CRITICAL] CISA says critical Fortinet RCE flaw now exploited in attacks
## CISA says critical Fortinet RCE flaw now exploited in attacks
## Sergiu Gatlan
Today, CISA revealed that attackers actively exploit a critical FortiOS remote code execution (RCE) vulnerability in the wild.
The flaw (CVE-2024-23113) is caused by the fgfmd daemon accepting an externally controlled format string as an argument, which can let unauthenticated threat actors execute commands or arbitrary code on unpatched devices in low-complexity attacks that don't require user interaction.
As Fortinet explains, the vulnerable fgfmd daemon runs on FortiGate and FortiManager, handling all authentication requests and managing keep-alive messages between them (as well as all resulting actions like instructing other processes to update files or databases).
CVE-2024-23113 impacts FortiOS 7.0
Wiz
Crying Out Cloud - March 2024 Newsletter | Wiz
blogs_wiz·2024-03-01·CVSS 8.6
CVE-2024-21626 [HIGH] Crying Out Cloud - March 2024 Newsletter | Wiz
Welcome back! In this edition, we bring you the latest in cloud security – crucial vulnerabilities, exclusive data, and noteworthy incidents. Stay informed and stay secure. Let's delve in.
Here are our cloud security highlights!
## 🐞 High Profile Vulnerabilities
Leaky Vessels: Docker and runc Container Escape Vulnerabilities
Several vulnerabilities have been revealed in the runC command line tool (CVE-2024-21626, CVE-2024-23651, CVE-2024-23652, and CVE-2024-23653). These flaws pose a risk of container escape, exploiting these vulnerabilities could grant unauthorized access to the host operating system, potentially compromising sensitive data and facilitating further attacks, particularly with superuser privileges.
According to Wiz data, 18% percent of cloud environments have resources
Wiz
New FortiOS Critical Vulnerabilities Exploited In-The-Wild | Wiz Blog
blogs_wiz·2024-02-12·CVSS 9.8
CVE-2024-21762 [CRITICAL] New FortiOS Critical Vulnerabilities Exploited In-The-Wild | Wiz Blog
CVE-2024-21762 and CVE-2024-23113 are critical vulnerabilities in Fortinet's FortiOS and FortiProxy; they received a CVSS score of 9.6 and 9.8, respectively. Both vulnerabilities could allow a remote unauthenticated attacker to execute arbitrary code or commands, and CVE-2024-21762 is reportedly being exploited in the wild. Fortinet guidance recommends to upgrade FortiOS instances to patched versions as soon as possible. Wiz customers can use the pre-built query and advisory in the Wiz Threat Center to search for vulnerable instances in their environment.
# What are CVE-2024-21762 and CVE-2024-23113?
The vulnerability identified as CVE-2024-21762, rated with a CVSS score of 9.6, stems from improper parameter validation within FortiOS SSL-VPN. It can be exploited by a remote, unauthentica
Wiz
New FortiOS Critical Vulnerabilities Exploited In-The-Wild | Wiz Blog
blogs_wiz·2024-02-12·CVSS 9.8
CVE-2024-21762 [CRITICAL] New FortiOS Critical Vulnerabilities Exploited In-The-Wild | Wiz Blog
CVE-2024-21762 and CVE-2024-23113 are critical vulnerabilities in Fortinet's FortiOS and FortiProxy; they received a CVSS score of 9.6 and 9.8, respectively. Both vulnerabilities could allow a remote unauthenticated attacker to execute arbitrary code or commands, and CVE-2024-21762 is reportedly being exploited in the wild. Fortinet guidance recommends to upgrade FortiOS instances to patched versions as soon as possible. Wiz customers can use the pre-built query and advisory in the Wiz Threat Center to search for vulnerable instances in their environment.
## What are CVE-2024-21762 and CVE-2024-23113?
The vulnerability identified as CVE-2024-21762, rated with a CVSS score of 9.6, stems from improper parameter validation within FortiOS SSL-VPN. It can be exploited by a remote, unauthentic
Tenable
CVE-2024-21762: Critical Fortinet FortiOS Out-of-Bound Write SSL VPN Vulnerability
blogs_tenable·2024-02-09·CVSS 9.8
[CRITICAL] CVE-2024-21762: Critical Fortinet FortiOS Out-of-Bound Write SSL VPN Vulnerability
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Bleepingcomputer
New Fortinet RCE flaw in SSL VPN likely exploited in attacks
blogs_bleepingcomputer·2024-02-08·CVSS 7.5
CVE-2024-21762 [HIGH] New Fortinet RCE flaw in SSL VPN likely exploited in attacks
## New Fortinet RCE flaw in SSL VPN likely exploited in attacks
## Lawrence Abrams
Fortinet is warning that a new critical remote code execution vulnerability in FortiOS SSL VPN is potentially being exploited in attacks.
The flaw (tracked as CVE-2024-21762 / FG-IR-24-015 ) received a 9.6 severity rating and is an out-of-bounds write vulnerability in FortiOS that allows unauthenticated attackers to gain remote code execution (RCE) via maliciously crafted requests.
To patch the bug, Fortinet recommends upgrading to one of the latest version based on this table:
FortiOS 7.6
Not affected
Not Applicable
FortiOS 7.4
7.4.0 through 7.4.2
Upgrade to 7.4.3 or above
FortiOS 7.2
7.2.0 through 7.2.6
Upgrade to 7.2.7 or above
FortiOS 7.0
7.0.0 through 7.0.13
Upgrade to 7.0.14 or above
F
Huntress
CVE-2024-23113 Vulnerability: Analysis, Detection, Removal | Huntress
blogs_huntress·CVSS 9.8
CVE-2024-23113 [CRITICAL] CVE-2024-23113 Vulnerability: Analysis, Detection, Removal | Huntress
## CVE-2024-23113 Vulnerability
Published: 12/05/2025
Written by: Lizzie Danielson
## What is CVE-2024-23113 Vulnerability?
CVE-2024-23113 is a remote code execution (RCE) vulnerability in Fortinet’s FortiOS, impacting the HTTP/HTTPS interface of certain FortiGate products. A result of a logic flaw in the authentication process, it permits unauthenticated adversaries to execute arbitrary commands without proper credentials. This vulnerability poses significant risks, including data theft, surveillance, and the complete compromise of affected systems.
## When was it discovered?
CVE-2024-23113 was publicly disclosed on October 3, 2024. Researchers from WatchTowr Labs identified and responsibly disclosed the vulnerability to Fortinet, which issued advisory patches shortly after its publ
2024-02-15
Published
2024-10-09
Added to CISA KEV
Exploited in the wild