FortiSIEM versions 6.4.0 through 7.1.1 contain an OS command injection vulnerability in the Phoenix Monitor service. The vulnerability exists in the XML parsing of TEST_STORAGE elements where the mount_point field is not properly sanitized before being passed to shell commands, allowing unauthenticated remote code execution.
id: CVE-2024-23108
info:
name: Fortinet FortiSIEM - OS Command Injection
author: 0x_Akoko
sev
...