# CVE-2024-23108

## Summary

- **CVE ID:** CVE-2024-23108
- **Severity:** CRITICAL
- **CVSS Score:** 9.7 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:F/RL:X/RC:X)
- **CWE:** CWE-78
- **Published:** Feb 5, 2024
- **Last Modified:** May 19, 2026

## Description

An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet  allows attacker to execute unauthorized code or commands via via crafted API requests.

## Affected Products

- Fortinet — FortiSIEM (7.1.0)
- Fortinet — FortiSIEM (7.0.0)
- Fortinet — FortiSIEM (6.7.0)
- Fortinet — FortiSIEM (6.6.0)
- Fortinet — FortiSIEM (6.5.0)
- Fortinet — FortiSIEM (6.4.0)

## References

- [CNA](https://fortiguard.com/psirt/FG-IR-23-130)
- [CISA-ADP](https://github.com/horizon3ai/CVE-2024-23108)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 78.23%
- **EPSS Percentile:** 99.5

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._