CRITICAL🚩 CISA KEV⚡ EXPLOIT🇵🇱 Wersja polska

CVE-2024-23113

CVSS 9.8v3.1pub. 2024-02-15upd. 2025-10-24

A use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, FortiProxy versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0.14, FortiPAM versions 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiSwitchManager versions 7.2.0 through 7.2.3, 7.0.0 through 7.0.3 allows attacker to execute unauthorized code or commands via specially crafted packets.

🤖 AI Analysis
How it works

The attacker sends specially crafted network packets to the vulnerable Fortinet device, in which malicious data reaches the string formatting function (format string) without proper validation. Since the attacker controls the format string, they can force the application to read or write arbitrary memory areas. This results in the ability to execute arbitrary code or system commands with the privileges of the target process.

Impact

An unauthenticated attacker can remotely take full control of the device — obtain sensitive data, modify configuration, and cause service unavailability (full CIA triad: confidentiality, integrity, availability at HIGH level).

Mitigation & patch

Patches available from the vendor must be applied immediately according to references — detailed information about patched versions is available at https://fortiguard.com/psirt/FG-IR-24-029. Due to active exploitation of the vulnerability, the update should be performed urgently.

Who is affected

FortiOS 7.4.0–7.4.2, 7.2.0–7.2.6, 7.0.0–7.0.13; FortiProxy 7.4.0–7.4.2, 7.2.0–7.2.8, 7.0.0–7.0.14; FortiPAM 1.2.0, 1.1.0–1.1.2, 1.0.0–1.0.3; FortiSwitchManager 7.2.0–7.2.3, 7.0.0–7.0.3

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Fortinet FortiOS

    OS
    Fortinet
    7.0.0 – 7.0.137.4.0 – 7.4.27.2.0 – 7.2.6
  • Fortinet Fortipam

    OS
    Fortinet
    1.2.01.1.0 – 1.1.21.0.0 – 1.0.3
  • Fortinet Fortiproxy

    APP
    Fortinet
    7.2.0 – 7.2.87.4.0 – 7.4.27.0.0 – 7.0.14
  • Fortinet Fortiswitchmanager

    APP
    Fortinet
    7.0.0 – 7.0.37.2.0 – 7.2.3

CISA KEV — detailsi

Vendori
Fortinet
Producti
Multiple Products
Added to KEVi
October 9, 2024
Remediation deadline (US Federal)i
October 30, 2024(overdue)
Required action (CISA)i

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CISA descriptioni

Fortinet FortiOS, FortiPAM, FortiProxy, and FortiWeb contain a format string vulnerability that allows a remote, unauthenticated attacker to execute arbitrary code or commands via specially crafted requests.

🔴
IMMEDIATE ACTION
Actively exploited in the wild (CISA KEV). Patch immediately.
CISA DEADLINE: 30 października 2024
Tags
Firewall
CWE
References

Related vulnerabilities

CVE-2026-24858CRITICAL9.8⚠ KEVPL ✓same product

Fortinet – Auth Bypass przez FortiCloud SSO w wielu produktach

CVE-2025-59718CRITICAL9.8⚠ KEVPL ✓same product

Fortinet FortiOS/FortiProxy/FortiSwitchManager — Auth Bypass przez SAML

CVE-2024-55591CRITICAL9.8⚠ KEVPL ✓same product

Authentication Bypass w FortiOS i FortiProxy — przejęcie uprawnień super-admin

CVE-2024-21762CRITICAL9.8⚠ KEVPL ✓same product

Out-of-bounds write w Fortinet FortiOS i FortiProxy — RCE bez uwierzytelnienia

CVE-2023-27997CRITICAL9.8⚠ KEVPL ✓same product

Krytyczny heap buffer overflow w FortiOS/FortiProxy SSL-VPN umożliwiający RCE