CVE-2024-23108
An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet allows attacker to execute unauthorized code or commands via via crafted API requests.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.7
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:F/RL:X/RC:X
- EPSS probability
- 78.23%
- CWE
- CWE-78
- Published
- 2024-02-05
- Last modified
- 2026-05-19
Affected products
- Fortinet FortiSIEM
- Fortinet FortiSIEM
- Fortinet FortiSIEM
- Fortinet FortiSIEM
- Fortinet FortiSIEM
- Fortinet FortiSIEM
Weakness type
Related vulnerabilities
- CVE-2026-17176 — OS command injection Vulnerability in Deco BE11000
- CVE-2026-78569 — Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards
- CVE-2026-78575 — Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards
- CVE-2026-79724 — Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards
- CVE-2026-81550 — DataStage on Cloud Pak for Data has several vulnerabilities due to open source software
- CVE-2026-82095 — DataStage on Cloud Pak for Data has several vulnerabilities due to open source software
- CVE-2026-82098 — DataStage on Cloud Pak for Data has several vulnerabilities due to open source software
- CVE-2026-82099 — DataStage on Cloud Pak for Data has several vulnerabilities due to open source software