<?xml version="1.0" encoding="UTF-8"?>
<cvrf:cvrfdoc xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:cvrf-common="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/common" xmlns:cvrf="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/cvrf">
    <cvrf:DocumentTitle>Multiple remote unauthenticated os command injection</cvrf:DocumentTitle>
    <cvrf:DocumentType>Fortinet PSIRT Advisories</cvrf:DocumentType>
    <cvrf:DocumentPublisher Type="Vendor">
        <cvrf:ContactDetails>
            Fortinet PSIRT Contact:
            Website: https://fortiguard.fortinet.com/faq/psirt-contact
        </cvrf:ContactDetails>
     </cvrf:DocumentPublisher>
    <cvrf:DocumentTracking>
        <cvrf:Identification>
            <cvrf:ID>FG-IR-23-130</cvrf:ID>
        </cvrf:Identification>
        <cvrf:Status>Final</cvrf:Status>
        <cvrf:Version>1</cvrf:Version>
        <cvrf:RevisionHistory>
            <cvrf:Revision>
                <cvrf:Number>1</cvrf:Number>
                <cvrf:Date>2023-10-10T00:00:00</cvrf:Date>
                <cvrf:Description>Current version</cvrf:Description>
        </cvrf:Revision>
       </cvrf:RevisionHistory>
        <cvrf:InitialReleaseDate>2023-10-10T00:00:00</cvrf:InitialReleaseDate>
        <cvrf:CurrentReleaseDate>2024-01-31T00:00:00</cvrf:CurrentReleaseDate>
    </cvrf:DocumentTracking>
    <cvrf:DocumentNotes>
        <cvrf:Note Title="Summary" Type="Summary" Ordinal="1">
            Multiple improper neutralization of special elements used in an OS Command vulnerability [CWE-78] in FortiSIEM supervisor may allow a remote unauthenticated attacker to execute unauthorized commands via crafted API requests.
        </cvrf:Note>
        <cvrf:Note Title="Description" Type="General" Ordinal="2">
            None
        </cvrf:Note>
        <cvrf:Note Title="Impact" Type="General" Ordinal="3">
            Execute unauthorized code or commands
        </cvrf:Note>
        <cvrf:Note Title="Affected Products" Type="General" Ordinal="4">
            FortiSIEM version 7.1.0 through 7.1.1FortiSIEM version 7.0.0 through 7.0.2FortiSIEM version 6.7.0 through 6.7.8FortiSIEM version 6.6.0 through 6.6.3FortiSIEM version 6.5.0 through 6.5.2FortiSIEM version 6.4.0 through 6.4.3FortiSIEM 6.3 all versions are not affectedFortiSIEM 6.2 all versions are not affectedFortiSIEM 6.1 all versions are not affectedFortiSIEM 5.4 all versions are not affectedFortiSIEM 5.3 all versions are not affected
        </cvrf:Note>
        <cvrf:Note Title="Solutions" Type="General" Ordinal="5">
            Please upgrade to FortiSIEM version 7.1.2 or above Please upgrade to FortiSIEM version 7.0.3 or abovePlease upgrade to FortiSIEM version 6.7.9 or abovePlease upgrade to FortiSIEM version 6.6.4 or abovePlease upgrade to FortiSIEM version 6.5.3 or abovePlease upgrade to FortiSIEM version 6.4.4 or abovePlease upgrade to upcoming FortiSIEM version 7.2.0 or above
        </cvrf:Note>
    </cvrf:DocumentNotes>
    <cvrf:Acknowledgments>
        <cvrf:Acknowledgment>
            <cvrf:Description>Fortinet is pleased to thank security researchers Zach Hanley (@hacks_zach) of Horizon3.ai</cvrf:Description>
        </cvrf:Acknowledgment>
        <cvrf:Acknowledgment>
            <cvrf:Description>for discovering and reporting this vulnerability under responsible disclosure.</cvrf:Description>
        </cvrf:Acknowledgment>
    </cvrf:Acknowledgments>
    <ProductTree>
        <Branch Name="Fortinet" Type="Vendor">
            <Branch Name="FortiSIEM" Type="Product Name">
                <Branch Name="7.1.1" Type="Product Version">
                    <FullProductName ProductID="FortiSIEM-7.1.1">FortiSIEM 7.1.1</FullProductName>
                </Branch>
                <Branch Name="7.1.0" Type="Product Version">
                    <FullProductName ProductID="FortiSIEM-7.1.0">FortiSIEM 7.1.0</FullProductName>
                </Branch>
                <Branch Name="7.0.2" Type="Product Version">
                    <FullProductName ProductID="FortiSIEM-7.0.2">FortiSIEM 7.0.2</FullProductName>
                </Branch>
                <Branch Name="7.0.1" Type="Product Version">
                    <FullProductName ProductID="FortiSIEM-7.0.1">FortiSIEM 7.0.1</FullProductName>
                </Branch>
                <Branch Name="7.0.0" Type="Product Version">
                    <FullProductName ProductID="FortiSIEM-7.0.0">FortiSIEM 7.0.0</FullProductName>
                </Branch>
                <Branch Name="6.7.8" Type="Product Version">
                    <FullProductName ProductID="FortiSIEM-6.7.8">FortiSIEM 6.7.8</FullProductName>
                </Branch>
                <Branch Name="6.7.7" Type="Product Version">
                    <FullProductName ProductID="FortiSIEM-6.7.7">FortiSIEM 6.7.7</FullProductName>
                </Branch>
                <Branch Name="6.7.6" Type="Product Version">
                    <FullProductName ProductID="FortiSIEM-6.7.6">FortiSIEM 6.7.6</FullProductName>
                </Branch>
                <Branch Name="6.7.5" Type="Product Version">
                    <FullProductName ProductID="FortiSIEM-6.7.5">FortiSIEM 6.7.5</FullProductName>
                </Branch>
                <Branch Name="6.7.4" Type="Product Version">
                    <FullProductName ProductID="FortiSIEM-6.7.4">FortiSIEM 6.7.4</FullProductName>
                </Branch>
                <Branch Name="6.7.3" Type="Product Version">
                    <FullProductName ProductID="FortiSIEM-6.7.3">FortiSIEM 6.7.3</FullProductName>
                </Branch>
                <Branch Name="6.7.2" Type="Product Version">
                    <FullProductName ProductID="FortiSIEM-6.7.2">FortiSIEM 6.7.2</FullProductName>
                </Branch>
                <Branch Name="6.7.1" Type="Product Version">
                    <FullProductName ProductID="FortiSIEM-6.7.1">FortiSIEM 6.7.1</FullProductName>
                </Branch>
                <Branch Name="6.7.0" Type="Product Version">
                    <FullProductName ProductID="FortiSIEM-6.7.0">FortiSIEM 6.7.0</FullProductName>
                </Branch>
                <Branch Name="6.6.3" Type="Product Version">
                    <FullProductName ProductID="FortiSIEM-6.6.3">FortiSIEM 6.6.3</FullProductName>
                </Branch>
                <Branch Name="6.6.2" Type="Product Version">
                    <FullProductName ProductID="FortiSIEM-6.6.2">FortiSIEM 6.6.2</FullProductName>
                </Branch>
                <Branch Name="6.6.1" Type="Product Version">
                    <FullProductName ProductID="FortiSIEM-6.6.1">FortiSIEM 6.6.1</FullProductName>
                </Branch>
                <Branch Name="6.6.0" Type="Product Version">
                    <FullProductName ProductID="FortiSIEM-6.6.0">FortiSIEM 6.6.0</FullProductName>
                </Branch>
                <Branch Name="6.5.2" Type="Product Version">
                    <FullProductName ProductID="FortiSIEM-6.5.2">FortiSIEM 6.5.2</FullProductName>
                </Branch>
                <Branch Name="6.5.1" Type="Product Version">
                    <FullProductName ProductID="FortiSIEM-6.5.1">FortiSIEM 6.5.1</FullProductName>
                </Branch>
                <Branch Name="6.5.0" Type="Product Version">
                    <FullProductName ProductID="FortiSIEM-6.5.0">FortiSIEM 6.5.0</FullProductName>
                </Branch>
                <Branch Name="6.4.3" Type="Product Version">
                    <FullProductName ProductID="FortiSIEM-6.4.3">FortiSIEM 6.4.3</FullProductName>
                </Branch>
                <Branch Name="6.4.2" Type="Product Version">
                    <FullProductName ProductID="FortiSIEM-6.4.2">FortiSIEM 6.4.2</FullProductName>
                </Branch>
                <Branch Name="6.4.1" Type="Product Version">
                    <FullProductName ProductID="FortiSIEM-6.4.1">FortiSIEM 6.4.1</FullProductName>
                </Branch>
                <Branch Name="6.4.0" Type="Product Version">
                    <FullProductName ProductID="FortiSIEM-6.4.0">FortiSIEM 6.4.0</FullProductName>
                </Branch>
            </Branch>
        </Branch>
    </ProductTree>
    <Vulnerability Ordinal="1">
        <Title>Multiple remote unauthenticated os command injection</Title>
        <cvrf:CVE>CVE-2023-34992</cvrf:CVE>
        <cvrf:CVE>CVE-2024-23108</cvrf:CVE>
        <cvrf:CVE>CVE-2024-23109</cvrf:CVE>
        <ProductStatuses>
            <Status Type="Known Affected">
                <ProductID>FortiSIEM-7.1.1</ProductID>
                <ProductID>FortiSIEM-7.1.0</ProductID>
                <ProductID>FortiSIEM-7.0.2</ProductID>
                <ProductID>FortiSIEM-7.0.1</ProductID>
                <ProductID>FortiSIEM-7.0.0</ProductID>
                <ProductID>FortiSIEM-6.7.8</ProductID>
                <ProductID>FortiSIEM-6.7.7</ProductID>
                <ProductID>FortiSIEM-6.7.6</ProductID>
                <ProductID>FortiSIEM-6.7.5</ProductID>
                <ProductID>FortiSIEM-6.7.4</ProductID>
                <ProductID>FortiSIEM-6.7.3</ProductID>
                <ProductID>FortiSIEM-6.7.2</ProductID>
                <ProductID>FortiSIEM-6.7.1</ProductID>
                <ProductID>FortiSIEM-6.7.0</ProductID>
                <ProductID>FortiSIEM-6.6.3</ProductID>
                <ProductID>FortiSIEM-6.6.2</ProductID>
                <ProductID>FortiSIEM-6.6.1</ProductID>
                <ProductID>FortiSIEM-6.6.0</ProductID>
                <ProductID>FortiSIEM-6.5.2</ProductID>
                <ProductID>FortiSIEM-6.5.1</ProductID>
                <ProductID>FortiSIEM-6.5.0</ProductID>
                <ProductID>FortiSIEM-6.4.3</ProductID>
                <ProductID>FortiSIEM-6.4.2</ProductID>
                <ProductID>FortiSIEM-6.4.1</ProductID>
                <ProductID>FortiSIEM-6.4.0</ProductID>
            </Status>
        </ProductStatuses>
        <CVSSScoreSets>
            <ScoreSetV3>
                <BaseScoreV3>9.7</BaseScoreV3>
                <VectorV3>CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:F/RL:X/RC:X</VectorV3>
            </ScoreSetV3>
        </CVSSScoreSets>
        <References Type="Self">
            <Reference>
                <URL>https://fortiguard.fortinet.com/psirt/FG-IR-23-130</URL>
                <Description>Multiple remote unauthenticated os command injection</Description>
            </Reference>Reference>
        </References>
    </Vulnerability>
</cvrf:cvrfdoc>