CVE-2024-23113

CRITICAL KEV

Fortinet FortiOS/FortiProxy/FortiPAM/FortiSwitchManager Format String Vulnerability via Crafted Packets

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2024-23113 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added October 9, 2024. EIP tracks 8 public exploits from researchers including p33d, adminlove520, MAVRICK-1.

AI-analyzed exploit summary The repository contains a Python script that scans for CVE-2024-23113, a format string vulnerability in FortiGate's FGFM service on TCP port 541. It checks for vulnerability by sending a crafted payload and analyzing the SSL/TLS response, but does not include exploit code for RCE.

Description

A use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, FortiProxy versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0.14, FortiPAM versions 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiSwitchManager versions 7.2.0 through 7.2.3, 7.0.0 through 7.0.3 allows attacker to execute unauthorized code or commands via specially crafted packets.

Exploits (8)

nomisec SCANNER 10 stars
by p33d · infoleak
https://github.com/p33d/CVE-2024-23113

The repository contains a Python script that scans for CVE-2024-23113, a format string vulnerability in FortiGate's FGFM service on TCP port 541. It checks for vulnerability by sending a crafted payload and analyzing the SSL/TLS response, but does not include exploit code for RCE.

Classification
Scanner 90%
Attack Type
Info Leak
Complexity
Moderate
Reliability
Reliable
Target: FortiGate FGFM service
No auth needed
Prerequisites: Network access to target device on port 541 · FGFM service running on target
devstral-2 · analyzed Feb 19, 2026 Full analysis →
github WORKING POC 2 stars
by adminlove520 · pythonpoc
https://github.com/adminlove520/CVE-Poc_All_in_One/tree/main/2024/CVE-2024-23113

The repository contains functional exploit code for CVE-2024-23113, including a server.py script and Docker setup for demonstration. The PoC leverages an authentication bypass vulnerability in TOTOLINK devices by manipulating the authCode parameter.

Classification
Working Poc 90%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: TOTOLINK LR350 (V9.3.5u.6369_B20220309) and T6 (V4.1.5cu.748_B20211015)
No auth needed
Prerequisites: Network access to the target device
devstral-2 · analyzed Feb 27, 2026 Full analysis →
nomisec SCANNER 1 stars
by MAVRICK-1 · poc
https://github.com/MAVRICK-1/cve-2024-23113-test-env

This repository provides a Docker-based test environment for validating CVE-2024-23113 Nuclei templates against simulated vulnerable FortiOS instances. It does not contain exploit code but simulates vulnerable endpoints for detection testing.

Classification
Scanner 95%
Attack Type
Info Leak
Complexity
Moderate
Reliability
Reliable
Target: FortiOS (versions 7.4.0-7.4.2, 7.2.0-7.2.6, 7.0.0-7.0.13)
No auth needed
Prerequisites: Docker · Docker Compose · Nuclei
devstral-2 · analyzed Feb 19, 2026 Full analysis →
nomisec SCANNER 1 stars
by valornode · dos
https://github.com/valornode/CVE-2024-23113

The repository contains a Python script that scans for CVE-2024-23113 by checking if FortiGate devices are vulnerable via a TLS-based format string payload. It does not exploit the vulnerability but detects potential exposure.

Classification
Scanner 90%
Attack Type
Info Leak
Complexity
Moderate
Reliability
Reliable
Target: FortiGate devices
No auth needed
Prerequisites: List of target IP addresses in 'clients.txt'
devstral-2 · analyzed Feb 19, 2026 Full analysis →
nomisec SCANNER 1 stars
by puckiestyle · infoleak
https://github.com/puckiestyle/CVE-2024-23113

The repository contains a Python script that scans for CVE-2024-23113, a format string vulnerability in FortiGate's FGFM service on TCP port 541. It checks for vulnerability by sending a crafted payload and analyzing the server's response, but does not include functional exploit code for RCE.

Classification
Scanner 90%
Attack Type
Info Leak
Complexity
Moderate
Reliability
Reliable
Target: FortiGate FGFM service
No auth needed
Prerequisites: Network access to target device on port 541 · FGFM service running on target
devstral-2 · analyzed Feb 19, 2026 Full analysis →
nomisec STUB 1 stars
by CheckCve2 · poc
https://github.com/CheckCve2/CVE-2024-23113

The repository contains only a trivial 'Hello World' script and minimal README files with no functional exploit code or technical details about CVE-2024-23113.

Classification
Stub 100%
Attack Type
Other
Complexity
Trivial
Reliability
Theoretical
Target: unknown
No auth needed
devstral-2 · analyzed Feb 19, 2026 Full analysis →
nomisec WORKING POC
by MinhPham123456789 · poc
https://github.com/MinhPham123456789/PoC-CVE-2024-23113

The repository contains a functional Python script that exploits CVE-2024-23113, a format string vulnerability in the FortiGate FGFM service. The script sends a crafted request with a format string specifier (%n) to trigger the vulnerability, potentially leading to RCE or DoS.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: FortiGate FGFM service
No auth needed
Prerequisites: Network access to TCP port 541 · SSL certificate and key for the exploit
devstral-2 · analyzed May 25, 2026 Full analysis →
nomisec SCANNER
by ownouwa · poc
https://github.com/ownouwa/cve-2024-23113-poc

The repository contains a Python script that checks for the presence of CVE-2024-23113 by sending a crafted packet to a target host and analyzing the SSL/TLS response. It does not exploit the vulnerability but detects potential susceptibility.

Classification
Scanner 90%
Attack Type
Info Leak
Complexity
Moderate
Reliability
Reliable
Target: Linux Kernel (BPF subsystem)
No auth needed
Prerequisites: Network access to target host on port 541 · TLS 1.2 support on target
devstral-2 · analyzed Feb 19, 2026 Full analysis →

Scores

CVSS v3 9.8
EPSS 0.5438
EPSS Percentile 98.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation active
Automatable yes
Technical Impact total

Details

CISA KEV 2024-10-09
VulnCheck KEV 2024-10-09
InTheWild.io 2024-10-09
ENISA EUVD EUVD-2024-20638
CWE
CWE-134
Status published
Products (5)
fortinet/fortios 7.0.0 - 7.0.13
fortinet/fortipam 1.2.0
fortinet/fortipam 1.0.0 - 1.0.3
fortinet/fortiproxy 7.0.0 - 7.0.14
fortinet/fortiswitchmanager 7.0.0 - 7.0.3
Published Feb 15, 2024
KEV Added Oct 09, 2024
Tracked Since Feb 18, 2026