Security

Patches

Double trouble for Fortinet as it issues critical FortiSIEM vulns

Please stand by 73 hours for vendor response...*


Updated Fortinet's FortiSIEM product is vulnerable to two maximum-severity security vulnerabilities that allow for remote code execution, or at least according to two freshly published CVEs.*

Both CVE-2024-23108 and CVE-2024-23109 have been assigned scores of 10 on the CVSS scale, suggesting exploits can be carried out remotely by unauthenticated attackers, are low in complexity, and require no user interaction to pull off.

In registering the CVE identities for the vulnerabilities, Fortinet linked to its own advisory to provide more information, but the link directs users to an older issue that was addressed in early October 2023.

"Multiple improper neutralization of special elements used in an OS Command vulnerability [CWE-78] in FortiSIEM supervisor may allow a remote unauthenticated attacker to execute unauthorized commands via crafted API requests," the advisory's description of the vulnerability reads.

Taking a glance at older, cached versions of the same advisory, we can see that the list of affected products has been recently updated, adding additional FortiSIEM versions. Despite Fortinet's advisory not being officially updated (yet), it suggests the two new vulnerabilities may be similar in nature to the one fixed in October, affecting newer versions of FortiSIEM.

The Register asked Fortinet for clarity on the matter but did not receive a response.

We also spoke to application security expert Sean Wright, who said the most recent two vulnerabilities in FortiSIEM will likely be classified as the same vulnerability from October (CVE-2023-34992), or at least a variation of it that impacts different or additional versions.

Hopefully Fortinet will provide some clarity on the matter in the coming days, although discerning the differences between vulnerabilities, especially in the early days of disclosure, can often be confusing for security pros sifting through conflicting details as we are here with the yet-to-be-updated advisory.

The National Vulnerability Database listings for CVE-2024-23108 and CVE-2024-23109 indicate both are currently under review, so we'll probably learn more about the issues at a later date.

Although there is no known publicly available exploit code available, Fortinet customers will want to get these vulnerabilities sorted out as soon as possible given their severity.

The following versions are confirmed to be vulnerable:

Customers can upgrade to version 7.1.2 today and have these vulnerabilities plugged, or wait for upcoming versions if for whatever reason upgrading to the very latest version is unfeasible.

Fortinet said it will be releasing new versions for 7.0.x, 6.7.x, 6.6.x, 6.5.x, and 6.4.x soon, without specifying an expected date. ®

Updated to add on February 7 2023

* The vendor has since claimed in a quote to another tech outlet that the CVEs were indeed duplicated from last October, and claimed it "issued duplicate CVEs in error."

Updated to add on February 9 2023

* The company later backtracked saying that yes, actually, these are two new vulnerabilities – two bypasses for October's CVE-2023-34992. For more on this tale of absolute vendor bunglement, please read our February 9 piece, "Fortinet's week to forget: Critical vulns, disclosure screw-ups, and that toothbrush DDoS attack claim"....

Send us news
3 Comments

Tired of airport security queues? SQL inject yourself into the cockpit, claim researchers

Infosec hounds say they spotted vulnerability during routine travel in the US

Check your IP cameras: There's a new Mirai botnet on the rise

Also, US offering $2.5M for Belarusian hacker, Backpage kingpins jailed, additional MOVEit victims, and more

White House’s new fix for cyber job gaps: Serve the nation in infosec

Now do your patriotic duty and fill one of those 500k open roles, please?

US sues Georgia Tech over alleged cybersecurity failings as a Pentagon contractor

Rap sheet spells out major no-nos after disgruntled staff blow whistle

Brain Cipher claims attack on Olympic venue, promises 300 GB data leak

French police reckon financial system targeted during Summer Games

SolarWinds left critical hardcoded credentials in its Web Help Desk product

Why go to the effort of backdooring code when devs will basically do it for you accidentally anyway

Multiple flaws in Microsoft macOS apps unpatched despite potential risks

Windows giant tells Cisco Talos it isn't fixing them

Cisco's Smart Licensing Utility flaws suggest it's pretty dumb on security

Two critical holes including hardcoded admin credential

Homeland security hopes to scuttle maritime cyber-threats with port infosec testbed

Supply chains, 13M jobs and $649B a year at risk, so Uncle Sam is fighting back - with a request for info

Deadline looms: Google Workspace mandates OAuth by September 30

27 days to get your users' third-party apps on Google’s sign-in

RansomHub hits 210 victims in just 6 months

The ransomware gang recruits high-profile affiliates from LockBit and ALPHV

AMD reverses course: Ryzen 3000 CPUs will get SinkClose patch after all

Still no love for 1000- or 2000-series