Advisory
Hospitals That Are Oracle Customers Urged to Take Immediate Action to Address Security Vulnerability
The flaw exists due to improper neutralization of special elements used in an OS command in FortiSIEM devices. In the event of successful exploitation, the flaw could allow threat actors to execute unauthorized code via crafted CLI requests. The flaw has a CVSS score of 9.8, highlighting its criticality.
Affected FortiSIEM versions are as follows:
Patches are available for vulnerable versions, and immediate patching is strongly recommended since the existence of exploit code increases the likelihood of attacks.
For organizations that are currently unable to apply patches, a temporary workaround is to limit access to the phMonitor port (7900).
For help with Cybersecurity and Risk Advisory Services exclusively for AHA members, contact: