CISA Warns of Critical Fortinet Flaw as Palo Alto and Cisco Issue Urgent Security Patches
Citing evidence of active exploitation, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a significant security issue affecting Fortinet devices to its Known Exploited Vulnerabilities (KEV) database on Wednesday.
The vulnerability affects FortiOS, FortiPAM, FortiProxy, and FortiWeb and is listed as CVE-2024-23113 (CVSS score: 9.8). It is related to incidents of remote code execution.
Fortinet stated in an advisory for the vulnerability back in February 2024 that a remote, unauthenticated attacker may be able to execute arbitrary code or commands through the exploitation of an externally-controlled format string vulnerability [CWE-134] in the FortiOS fgfmd daemon.
As usual, there are few specifics in the warning about how the vulnerability is being used in th...

