Skip to content

Known CVE

Fortinet FortiSIEM - OS Command Injection

FortiSIEM versions 6.4.0 through 7.1.1 contain an OS command injection vulnerability in the Phoenix Monitor service. The vulnerability exists in the XML parsing of TEST_STORAGE elements where the mount_point field is not properly sanitized before being passed to shell commands, allowing unauthenticated remote code execution.

CVE-2024-23108

Critical2024CVSS 10CWE-78

cve2024 · fortinet · fortisiem · vkev · injection · unauth

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website