LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2024-23113: Fortinet Multiple Products Format String Vulnerability

RBRecent Breaches Vulnerability Intelligence·Oct 9, 2024
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Oct 30, 2024
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2024-23113 to its Known Exploited Vulnerabilities catalog on Oct 9, 2024, with a federal patch deadline of Oct 30, 2024 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Fortinet FortiOS, FortiPAM, FortiProxy, and FortiWeb contain a format string vulnerability that allows a remote, unauthenticated attacker to execute arbitrary code or commands via specially crafted…

CVE-2024-23113 is a format string vulnerability affecting multiple Fortinet products, including FortiOS, FortiPAM, FortiProxy, and FortiWeb. It allows a remote, unauthenticated attacker to execute arbitrary code or commands by sending specially crafted requests. This matters because these products commonly sit at network perimeters or handle privileged access, so successful exploitation can give an attacker a foothold without credentials.

Defenders should treat it as a high-priority issue for any exposed Fortinet management or proxy interfaces and confirm exact product coverage and fixed releases against the vendor advisory.

How it works

The underlying weakness is CWE-134: use of externally controlled format strings. In this class of flaw, an application passes attacker-controlled input into a formatting function without proper sanitization. An attacker can supply format specifiers that cause the program to read or write memory in unintended ways.

According to the CISA summary, a remote unauthenticated attacker can abuse this in the affected Fortinet products by sending specially crafted requests. That can lead to arbitrary code or command execution. Exact request paths, parameters, or memory-corruption mechanics are not detailed in the public summary; treat any such claims as unconfirmed until verified against the vendor advisory. The practical outcome is that an unauthenticated network request may be enough to take control of the device process.

Am I affected? How to find it in your systems

These products typically run as firewalls, secure web gateways, privileged access managers, or reverse proxies. Inventory every Fortinet appliance and virtual instance in your environment, including those used for management, VPN, or web application protection.

For signs of exploitation, look for anomalous unauthenticated requests in device logs, sudden process crashes or restarts, unexpected outbound connections from the appliance, or configuration changes that were not authorized. Correlate with network telemetry for unusual traffic to Fortinet management ports. Absence of known public exploit details means you should not expect a single signature; focus on behavioral anomalies and confirm detection guidance with the vendor.

How to remediate

Patch first. Apply the vendor-supplied updates for FortiOS, FortiPAM, FortiProxy, and FortiWeb as directed in the official advisory. CISA’s required action is to apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Document the change and retain evidence of the update for audit and incident-response purposes.

If you can't patch immediately

Reduce the attack surface until the vendor update can be applied.

These controls lower risk but do not eliminate it; plan to patch as soon as operationally feasible.

If your data may have been exposed

Actively exploited remote-code-execution vulnerabilities can lead to full device compromise and subsequent data theft or lateral movement. Known ransomware use of this CVE is not documented in the provided facts, but any successful exploitation should still be treated as a potential breach. Investigate device logs, network flows, and endpoint telemetry for indicators of compromise. If you suspect exposure of credentials or personal data, follow your incident-response plan, rotate secrets, and notify affected parties as required. You can also run a free exposure scan of your email address against known breach data sets to check whether your addresses appear in prior incidents.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedFortinet · Multiple Products
WeaknessCWE-134
Added to CISA KEVOct 9, 2024
Federal patch deadlineOct 30, 2024
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities