ZeroHour

CVE-2024-23113

KEVlarge1

Format String Vulnerability Enables Unauthenticated RCE in Fortinet FortiOS and FortiProxy

CISA: Fortinet Multiple Products Format String Vulnerability

CVSS 3.1
9.8 critical
EPSS
62%p99
Published
()
KEV added
AI analysis

CVE-2024-23113 is a use of externally-controlled format string (CWE-134) in multiple Fortinet products, allowing an unauthenticated remote attacker to execute unauthorized code or commands by sending specially crafted packets to an affected device. The flaw carries a critical CVSS 3.1 score of 9.8 (network vector, no privileges or user interaction required, high impact on confidentiality, integrity, and availability). It affects FortiOS 7.0.0 through 7.0.13, 7.2.0 through 7.2.6, and 7.4.0 through 7.4.2; FortiProxy 7.0.0 through 7.0.14, 7.2.0 through 7.2.8, and 7.4.0 through 7.4.2; FortiPAM 1.0.0 through 1.0.3, 1.1.0 through 1.1.2, and 1.2.0; and FortiSwitchManager 7.0.0 through 7.0.3 and 7.2.0 through 7.2.3. CISA added the vulnerability to the Known Exploited Vulnerabilities catalog on 2024-10-09 and warns it is likely being exploited in the wild, though no public proof-of-concept is known. Scanning coverage reported in the trade press indicates roughly 87,000 or more internet-exposed Fortinet devices remained vulnerable and open to attack after disclosure.

What to do: Upgrade affected FortiOS, FortiProxy, FortiPAM, and FortiSwitchManager deployments to a patched release per Fortinet's advisory, since the data does not specify fixed build numbers. Until patching is complete, restrict management interface access to trusted sources, minimize internet exposure of affected devices, and verify your version falls within the affected ranges above. Treat this as an actively exploited vulnerability per CISA's KEV listing (added 2024-10-09) and prioritize it accordingly.

Affected
Fortinet FortiOS7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13
Fortinet FortiProxy7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0.14
Fortinet FortiPAM1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3
Fortinet FortiSwitchManager7.2.0 through 7.2.3, 7.0.0 through 7.0.3
Estimated exposure
large≈87,000+ internet-exposed Fortinet devices per public scans (FortiOS/FortiProxy deployments; total installed base larger, affected-version share unknown) — Publicly reported internet-facing scans cited in trade coverage identified over 87,000 unpatched Fortinet devices, and the affected version ranges span the widely deployed FortiOS 7.0/7.2/7.4 and FortiProxy branches, placing the exposed…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, FortiProxy versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0.14, FortiPAM versions 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiSwitchManager versions 7.2.0 through 7.2.3, 7.0.0 through 7.0.3 allows attacker to execute unauthorized code or commands via specially crafted packets.

CISA Known Exploited Vulnerability
Affected
Fortinet Multiple Products
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
fortinet
Products
fortiproxy, fortiswitchmanager, fortios, fortipam
Weakness
CWE-134
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news