Description

Fortinet has issued a critical alert to its customers concerning a severe OS command injection vulnerability identified in the FortiSIEM report server. Tracked as CVE-2023-36553, this flaw enables remote, unauthenticated attackers to execute commands by manipulating API requests. Rated with a critical severity score of 9.3 by Fortinet's team and 9.8 by NIST, this vulnerability poses a significant threat. FortiSIEM, a robust cybersecurity solution, is widely utilized across diverse sectors such as healthcare, finance, retail, e-commerce, and government, offering heightened visibility and control over security posture. The vulnerability, a variant of the previously addressed CVE-2023-34992 issue, stems from inadequate neutralization of special elements within API requests. Exploiting this oversight can authorize the execution of unauthorized commands, potentially leading to data breaches or manipulation of systems. Fortinet strongly advises administrators to upgrade affected FortiSIEM versions (ranging from 4.7 to 5.4) to versions 6.4.3, 6.5.2, 6.6.4, 6.7.6, 7.0.1, or 7.1.0, emphasizing the urgency for immediate action. Fortinet's products, including firewalls and intrusion detection systems, are attractive targets for sophisticated hacking groups. Recent reports have linked exploits in Fortinet products to instances of cyber-espionage affecting U.S. aeronautical firms and Chinese clusters. Notably, government networks have also faced compromises due to zero-day vulnerabilities found in Fortinet products, underscoring the critical need for robust security measures.