VYPR

FortiSIEM

by Fortinet

CVEs (27)

  • CVE-2024-23108CriFeb 5, 2024
    risk 0.71cvss 10.0epss 0.78

    An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet allows attacker to execute unauthorized code or commands via via crafted API requests.

  • CVE-2023-34992CriOct 10, 2023
    risk 0.70cvss 10.0epss 0.66

    A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet allows attacker to execute unauthorized code or commands via crafted API requests.

  • CVE-2024-23109CriFeb 5, 2024
    risk 0.65cvss 10.0epss 0.03

    An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet allows attacker to execute unauthorized code or commands via via crafted API requests.

  • CVE-2023-40714CriApr 2, 2025
    risk 0.64cvss 9.9epss 0.01

    A relative path traversal in Fortinet FortiSIEM versions 7.0.0, 6.7.0 through 6.7.2, 6.6.0 through 6.6.3, 6.5.1, 6.5.0 allows attacker to escalate privilege via uploading certain GUI elements

  • CVE-2023-36553CriNov 14, 2023
    risk 0.64cvss 9.8epss 0.02

    A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiSIEM version 5.4.0 and 5.3.0 through 5.3.3 and 5.2.5 through 5.2.8 and 5.2.1 through 5.2.2 and 5.1.0 through 5.1.3 and 5.0.0 through 5.0.1 and 4.10.0 and 4.9.0 and 4.7.2…

  • CVE-2019-16153CriJan 23, 2020
    risk 0.64cvss 9.8epss 0.01

    A hard-coded password vulnerability in the Fortinet FortiSIEM database component version 5.2.5 and below may allow attackers to access the device database via the use of static credentials.

  • CVE-2019-17653HigMar 12, 2020
    risk 0.57cvss 8.8epss 0.01

    A Cross-Site Request Forgery (CSRF) vulnerability in the user interface of Fortinet FortiSIEM 5.2.5 could allow a remote, unauthenticated attacker to perform arbitrary actions using an authenticated user's session by persuading the victim to follow a malicious link.

  • CVE-2023-40723HigMar 11, 2025
    risk 0.53cvss 8.1epss 0.00

    An exposure of sensitive information to an unauthorized actor in Fortinet FortiSIEM version 6.7.0 through 6.7.4 and 6.6.0 through 6.6.3 and 6.5.0 through 6.5.1 and 6.4.0 through 6.4.2 and 6.3.0 through 6.3.3 and 6.2.0 through 6.2.1 and 6.1.0 through 6.1.2 and 5.4.0 and 5.3.0…

  • CVE-2022-42478HigJun 13, 2023
    risk 0.53cvss 8.1epss 0.01

    An Improper Restriction of Excessive Authentication Attempts [CWE-307] in FortiSIEM below 7.0.0 may allow a non-privileged user with access to several endpoints to brute force attack these endpoints.

  • CVE-2022-26119HigNov 2, 2022
    risk 0.51cvss 7.8epss 0.00

    A improper authentication vulnerability in Fortinet FortiSIEM before 6.5.0 allows a local attacker with CLI access to perform operations on the Glassfish server directly via a hardcoded password.

  • CVE-2024-46667HigJan 14, 2025
    risk 0.49cvss 7.5epss 0.01

    A allocation of resources without limits or throttling in Fortinet FortiSIEM 5.3 all versions, 5.4 all versions, 6.x all versions, 7.0 all versions, and 7.1.0 through 7.1.5 may allow an attacker to deny valid TLS traffic via consuming all allotted connections.

  • CVE-2018-13378HigApr 17, 2019
    risk 0.47cvss 7.2epss 0.01

    An information disclosure vulnerability in Fortinet FortiSIEM 5.2.0 and below versions exposes the LDAP server plaintext password via the HTML source code.

  • CVE-2019-6700MedJan 7, 2020
    risk 0.42cvss 6.5epss 0.01

    An information exposure vulnerability in the external authentication profile form of FortiSIEM 5.2.2 and earlier may allow an authenticated attacker to retrieve the external authentication password via the HTML source code.

  • CVE-2022-43949MedJun 13, 2023
    risk 0.40cvss 6.2epss 0.00

    A use of a broken or risky cryptographic algorithm [CWE-327] in Fortinet FortiSIEM before 6.7.1 allows a remote unauthenticated attacker to perform brute force attacks on GUI endpoints via taking advantage of outdated hashing methods.

  • CVE-2019-17651MedJan 28, 2020
    risk 0.35cvss 5.4epss 0.01

    An Improper Neutralization of Input vulnerability in the description and title parameters of a Device Maintenance Schedule in FortiSIEM version 5.2.5 and below may allow a remote authenticated attacker to perform a Stored Cross Site Scripting attack (XSS) by injecting malicious…

  • CVE-2023-41676MedNov 14, 2023
    risk 0.28cvss 4.3epss 0.00

    An exposure of sensitive information to an unauthorized actor [CWE-200] in FortiSIEM version 7.0.0 and before 6.7.5 may allow an attacker with access to windows agent logs to obtain the windows agent password via searching through the logs.

  • CVE-2023-36551MedSep 13, 2023
    risk 0.28cvss 4.3epss 0.01

    A exposure of sensitive information to an unauthorized actor in Fortinet FortiSIEM version 6.7.0 through 6.7.5 allows attacker to information disclosure via a crafted http request.

  • CVE-2024-52969MedJan 14, 2025
    risk 0.27cvss 4.1epss 0.00

    An Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability [CWE-89] in FortiSIEM ersion 7.1.7 and below, version 7.1.0, version 7.0.3 and below, version 6.7.9 and below, 6.7.8, version 6.6.5 and below, version 6.5.3 and below, version…

  • CVE-2024-55592LowMar 11, 2025
    risk 0.25cvss 3.8epss 0.00

    An incorrect authorization vulnerability [CWE-863] in FortiSIEM 7.2 all versions, 7.1 all versions, 7.0 all versions, 6.7 all versions, 6.6 all versions, 6.5 all versions, 6.4 all versions, 6.3 all versions, 6.2 all versions, 6.1 all versions, 5.4 all versions, 5.3 all versions,…

  • CVE-2019-17659LowMar 17, 2025
    risk 0.24cvss 3.7epss 0.01

    A use of hard-coded cryptographic key vulnerability in FortiSIEM version 5.2.6 may allow a remote unauthenticated attacker to obtain SSH access to the supervisor as the restricted user "tunneluser" by leveraging knowledge of the private key from another installation or a…

Page 1 of 2