VYPR

Fortisiem Windows Agent

by Fortinet

CVEs (3)

  • CVE-2020-9292CriJun 4, 2020
    risk 0.64cvss 9.8epss 0.02

    An unquoted service path vulnerability in the FortiSIEM Windows Agent component may allow an attacker to gain elevated privileges via the AoWinAgt executable service path.

  • CVE-2021-41022HigNov 2, 2021
    risk 0.51cvss 7.8epss 0.00

    A improper privilege management in Fortinet FortiSIEM Windows Agent version 4.1.4 and below allows attacker to execute privileged code or commands via powershell scripts

  • CVE-2021-41023MedNov 2, 2021
    risk 0.36cvss 5.5epss 0.00

    A unprotected storage of credentials in Fortinet FortiSIEM Windows Agent version 4.1.4 and below allows an authenticated user to disclosure agent password due to plaintext credential storage in log files