{"id":7616,"date":"2024-10-10T17:58:12","date_gmt":"2024-10-10T23:58:12","guid":{"rendered":"https:\/\/beaconlab.mx\/?post_type=publicacion&#038;p=6283"},"modified":"2024-10-21T16:38:40","modified_gmt":"2024-10-21T21:38:40","slug":"2024-49-vulnerabilidad-critica-de-ejecucion-remota-en-productos-fortinet","status":"publish","type":"publicacion","link":"https:\/\/beaconlab.us\/es\/publicacion\/2024-49-vulnerabilidad-critica-de-ejecucion-remota-en-productos-fortinet\/","title":{"rendered":"Alerta 2024-49 Vulnerabilidad Cr\u00edtica de Ejecuci\u00f3n Remota en Productos Fortinet"},"content":{"rendered":"<p><span data-contrast=\"none\">CISA ha alertado sobre la explotaci\u00f3n activa de una vulnerabilidad cr\u00edtica de <\/span><b><span data-contrast=\"none\">ejecuci\u00f3n remota de c\u00f3digo (RCE)<\/span><\/b><span data-contrast=\"none\"> en productos de <\/span><b><span data-contrast=\"none\">Fortinet<\/span><\/b><span data-contrast=\"none\">, identificada como <\/span><b><span data-contrast=\"none\">CVE-2024-23113<\/span><\/b><span data-contrast=\"none\">. Esta vulnerabilidad afecta a varias soluciones de Fortinet, incluidas <\/span><b><span data-contrast=\"none\">FortiOS<\/span><\/b><span data-contrast=\"none\">, <\/span><b><span data-contrast=\"none\">FortiPAM<\/span><\/b><span data-contrast=\"none\">, <\/span><b><span data-contrast=\"none\">FortiProxy<\/span><\/b><span data-contrast=\"none\">, y <\/span><b><span data-contrast=\"none\">FortiWeb<\/span><\/b><span data-contrast=\"none\">.<\/span><span data-ccp-props=\"{&quot;335551550&quot;:6,&quot;335551620&quot;:6}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"none\">La falla se debe a un problema de <\/span><b><span data-contrast=\"none\">cadena de formato<\/span><\/b><span data-contrast=\"none\"> en el daemon <\/span><b><span data-contrast=\"none\">fgfmd<\/span><\/b><span data-contrast=\"none\"> de FortiOS, que podr\u00eda permitir a un atacante remoto y no autenticado ejecutar comandos o c\u00f3digo arbitrario en el sistema afectado mediante solicitudes manipuladas. La gravedad de la vulnerabilidad se refleja en su puntuaci\u00f3n CVSS de <\/span><b><span data-contrast=\"none\">9.8<\/span><\/b><span data-contrast=\"none\">, calific\u00e1ndola como cr\u00edtica.<\/span><span data-ccp-props=\"{&quot;335551550&quot;:6,&quot;335551620&quot;:6}\">\u00a0<\/span><\/p>\n<p><span class=\"TextRun SCXW42533611 BCX0\" lang=\"ES-MX\" xml:lang=\"ES-MX\" data-contrast=\"none\"><span class=\"NormalTextRun SCXW42533611 BCX0\">Seg\u00fan datos de <\/span><span class=\"NormalTextRun SpellingErrorV2Themed SCXW42533611 BCX0\">Shodan<\/span><span class=\"NormalTextRun SCXW42533611 BCX0\">, en M\u00e9xico se cuentan con m\u00e1s de<\/span> <\/span><span class=\"TextRun SCXW42533611 BCX0\" lang=\"ES-MX\" xml:lang=\"ES-MX\" data-contrast=\"none\"><span class=\"NormalTextRun SCXW42533611 BCX0\">15 mil <\/span><span class=\"NormalTextRun SCXW42533611 BCX0\">dispositivos<\/span> <\/span><span class=\"TextRun SCXW42533611 BCX0\" lang=\"ES-MX\" xml:lang=\"ES-MX\" data-contrast=\"none\"><span class=\"NormalTextRun SCXW42533611 BCX0\">Fortinet activos proporcionando<\/span><span class=\"NormalTextRun SCXW42533611 BCX0\"> diversas capas de seguridad en redes y aplicaciones.<\/span><\/span><\/p>\n<p><span class=\"TextRun SCXW17682327 BCX0\" lang=\"ES-MX\" xml:lang=\"ES-MX\" data-contrast=\"none\"><span class=\"NormalTextRun SCXW17682327 BCX0\">Para mitigar la vulnerabilidad <\/span><\/span><span class=\"TextRun SCXW17682327 BCX0\" lang=\"ES-MX\" xml:lang=\"ES-MX\" data-contrast=\"none\"><span class=\"NormalTextRun SCXW17682327 BCX0\">CVE-2024-23113<\/span><\/span><span class=\"TextRun SCXW17682327 BCX0\" lang=\"ES-MX\" xml:lang=\"ES-MX\" data-contrast=\"none\"><span class=\"NormalTextRun SCXW17682327 BCX0\"> en los productos de Fortinet, la soluci\u00f3n es <\/span><\/span><span class=\"TextRun SCXW17682327 BCX0\" lang=\"ES-MX\" xml:lang=\"ES-MX\" data-contrast=\"none\"><span class=\"NormalTextRun SCXW17682327 BCX0\">actualizar a las versiones parcheadas<\/span><\/span><span class=\"TextRun SCXW17682327 BCX0\" lang=\"ES-MX\" xml:lang=\"ES-MX\" data-contrast=\"none\"><span class=\"NormalTextRun SCXW17682327 BCX0\">. Fortinet ha lanzado actualizaciones que corrigen <\/span><span class=\"NormalTextRun SCXW17682327 BCX0\">esta vulnerabilidad. Para <\/span><span class=\"NormalTextRun ContextualSpellingAndGrammarErrorV2Themed SCXW17682327 BCX0\">mas<\/span><span class=\"NormalTextRun SCXW17682327 BCX0\"> informaci\u00f3n visita el siguiente <\/span><span class=\"NormalTextRun AdvancedProofingIssueV2Themed SCXW17682327 BCX0\">link<\/span><span class=\"NormalTextRun SCXW17682327 BCX0\">: <\/span><\/span><a class=\"Hyperlink SCXW17682327 BCX0\" href=\"https:\/\/support.fortinet.com\/\" target=\"_blank\" rel=\"noreferrer noopener\"><span class=\"TextRun Underlined SCXW17682327 BCX0\" lang=\"ES-MX\" xml:lang=\"ES-MX\" data-contrast=\"none\"><span class=\"NormalTextRun SCXW17682327 BCX0\" data-ccp-charstyle=\"Hyperlink\">https:\/\/support.fortinet.com\/<\/span><\/span><\/a><span class=\"EOP SCXW17682327 BCX0\" data-ccp-props=\"{&quot;335551550&quot;:6,&quot;335551620&quot;:6}\">\u00a0<\/span><\/p>\n","protected":false},"featured_media":7637,"template":"","class_list":["post-7616","publicacion","type-publicacion","status-publish","has-post-thumbnail","hentry"],"acf":{"activar_pdf_link":true,"pdf":7988,"numero_de_boletin":"","traffic_light_protocol":"Amber"},"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/beaconlab.us\/es\/wp-json\/wp\/v2\/publicacion\/7616","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/beaconlab.us\/es\/wp-json\/wp\/v2\/publicacion"}],"about":[{"href":"https:\/\/beaconlab.us\/es\/wp-json\/wp\/v2\/types\/publicacion"}],"version-history":[{"count":1,"href":"https:\/\/beaconlab.us\/es\/wp-json\/wp\/v2\/publicacion\/7616\/revisions"}],"predecessor-version":[{"id":7805,"href":"https:\/\/beaconlab.us\/es\/wp-json\/wp\/v2\/publicacion\/7616\/revisions\/7805"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/beaconlab.us\/es\/wp-json\/wp\/v2\/media\/7637"}],"wp:attachment":[{"href":"https:\/\/beaconlab.us\/es\/wp-json\/wp\/v2\/media?parent=7616"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}