CVE-2024-23113 KEV
9.8
CRITICAL · CVSS 3.1 · EPSS 61.7% (pctl 99)
Patch first
On CISA KEV — known exploited in the wild, due 2024-10-30.
Description
A use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, FortiProxy versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0.14, FortiPAM versions 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiSwitchManager versions 7.2.0 through 7.2.3, 7.0.0 through 7.0.3 allows attacker to execute unauthorized code or commands via specially crafted packets.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 61.73% — more likely to be exploited than 99% of all CVEs |
| Weakness | CWE-134 |
| On CISA KEV | yes — remediate by 2024-10-30 |
| Public exploit | none known |
| Published | 2024-02-15 |
| Last modified | 2026-06-17 |
CISA KEV
| Name | Fortinet Multiple Products Format String Vulnerability |
|---|---|
| Added | 2024-10-09 |
| Due | 2024-10-30 |
| Vendor / product | Fortinet / Multiple Products |
| Ransomware use | none reported |
Affected (4)
| Vendor | Product |
|---|---|
| fortinet | fortios |
| fortinet | fortipam |
| fortinet | fortiproxy |
| fortinet | fortiswitchmanager |
References
→ the Explorer · watch your stack · NVD