EXPOSURES › CVE-2024-23113
CVE-2024-23113
HIGH ⌖ ON CISA KEV · EXPLOITEDFortinet products allow remote, unauthenticated attackers to execute arbitrary code via a format string vulnerability.
This unpatched format string flaw enables remote code execution in FortiOS, FortiPAM, FortiProxy, and FortiWeb, directly threatening DIB systems that rely on these components for security and management. Because the vulnerability is actively exploited and allows unauthenticated remote code execution, it poses an immediate risk to FedRAMP and NIST 800-171 environments unless patched immediately.
Shame score — A high-severity, actively exploited RCE vulnerability in widely deployed security products indicates a critical failure in patch management and security posture.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Fortinet FortiOS, FortiPAM, FortiProxy, and FortiWeb contain a format string vulnerability that allows a remote, unauthenticated attacker to execute arbitrary code or commands via specially crafted requests.