CERT-In Vulnerability Note
CIVN-2024-0037
Multiple Vulnerabilities in Fortinet FortiSIEM
Original Issue Date:February 09, 2024
Severity Rating: CRITICAL
Software Affected
- FortiSIEM version 7.1.0 through 7.1.1
- FortiSIEM version 7.0.0 through 7.0.2
- FortiSIEM version 6.7.0 through 6.7.8
- FortiSIEM version 6.6.0 through 6.6.3
- FortiSIEM version 6.5.0 through 6.5.2
- FortiSIEM version 6.4.0 through 6.4.2
Overview
Multiple vulnerabilities have been reported in FortiSIEM, which could be exploited by a remote attacker to execute arbitrary OS commands and may result in the complete compromise of the vulnerable system.
Description
These vulnerabilities exist due to improper input validation. A remote attacker could exploit these vulnerabilities by sending specially crafted HTTP requests to the API and execute unauthorized commands on the targeted system.
Successful exploitation of these vulnerabilities could allow a remote unauthenticated attacker to execute arbitrary OS commands and may result in the complete compromise of the vulnerable system.
Solution
Apply appropriate updates as mentioned in the Fortinet advisory:
https://www.fortiguard.com/psirt/FG-IR-23-130
Vendor Information
Fortinet PSIRT
https://www.fortiguard.com/psirt/FG-IR-23-130
References
Bleeping Computer
https://www.bleepingcomputer.com/news/security/fortinet-warns-of-new-fortisiem-rce-bugs-in-confusing-disclosure/
Fortinet PSIRT
https://www.fortiguard.com/psirt/FG-IR-23-130
CVE Name
CVE-2023-34992
CVE-2024-23108
CVE-2024-23109
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-22902657
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|