# CVE-2024-23113

## Summary

- **CVE ID:** CVE-2024-23113
- **Severity:** CRITICAL
- **CVSS Score:** 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:H/RL:U/RC:C)
- **CWE:** CWE-134
- **Published:** Feb 15, 2024
- **Last Modified:** Oct 21, 2025

## Description

A use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, FortiProxy versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0.14, FortiPAM versions 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiSwitchManager versions 7.2.0 through 7.2.3, 7.0.0 through 7.0.3 allows attacker to execute unauthorized code or commands via specially crafted packets.

## Affected Products

- Fortinet — FortiSwitchManager (7.2.0)
- Fortinet — FortiSwitchManager (7.0.0)
- Fortinet — FortiOS (7.4.0)
- Fortinet — FortiOS (7.2.0)
- Fortinet — FortiOS (7.0.0)
- Fortinet — FortiPAM (1.2.0)
- Fortinet — FortiPAM (1.1.0)
- Fortinet — FortiPAM (1.0.0)
- Fortinet — FortiProxy (7.4.0)
- Fortinet — FortiProxy (7.2.0)
- Fortinet — FortiProxy (7.0.0)

## References

- [CNA](https://fortiguard.com/psirt/FG-IR-24-029)
- [CISA-ADP](https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-23113)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 61.72%
- **EPSS Percentile:** 99.1

## Known Exploited Vulnerabilities (KEV)

- **Date Added:** Oct 9, 2024
- **Due Date:** Oct 30, 2024

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._