Tag: Known Exploited Vulnerabilities

CISA Warns of Critical Fortinet Flaw as Palo Alto and Cisco Issue Urgent Security Patches
News

CISA Warns of Critical Fortinet Flaw as Palo Alto and Cisco Issue Urgent Security Patches

Citing evidence of active exploitation, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a significant security issue affecting Fortinet devices to its Known Exploited Vulnerabilities (KEV) database on Wednesday. The vulnerability affects FortiOS, FortiPAM, FortiProxy, and FortiWeb and is listed as CVE-2024-23113 (CVSS score: 9.8). It is related to incidents of remote code execution. Fortinet stated in an advisory for the vulnerability back in February 2024 that a remote, unauthenticated attacker may be able to execute arbitrary code or commands through the exploitation of an externally-controlled format string vulnerability [CWE-134] in the FortiOS fgfmd daemon. As usual, there are few specifics in the warning about how the vulnerability is being used in th...