VYPR

FortiSIEM

by Fortinet

CVEs (32)

  • CVE-2024-23108CriFeb 5, 2024
    risk 0.71cvss 10.0epss 0.78

    An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet allows attacker to execute unauthorized code or commands via via crafted API requests.

  • CVE-2023-34992CriOct 10, 2023
    risk 0.70cvss 10.0epss 0.80

    A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet allows attacker to execute unauthorized code or commands via crafted API requests.

  • CVE-2025-25256CriAug 12, 2025
    risk 0.69cvss 9.8epss 0.60

    An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] vulnerability in Fortinet FortiSIEM 7.3.0 through 7.3.1, FortiSIEM 7.2.0 through 7.2.5, FortiSIEM 7.1.0 through 7.1.7, FortiSIEM 7.0.0 through 7.0.3, FortiSIEM…

  • CVE-2025-64155CriJan 13, 2026
    risk 0.67cvss 9.8epss 0.43

    An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSIEM 7.4.0, FortiSIEM 7.3.0 through 7.3.4, FortiSIEM 7.1.0 through 7.1.8, FortiSIEM 7.0.0 through 7.0.4, FortiSIEM 6.7.0 through 6.7.10 may allow an…

  • CVE-2024-23109CriFeb 5, 2024
    risk 0.65cvss 10.0epss 0.03

    An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet allows attacker to execute unauthorized code or commands via via crafted API requests.

  • CVE-2023-40714CriApr 2, 2025
    risk 0.64cvss 9.9epss 0.01

    A relative path traversal in Fortinet FortiSIEM versions 7.0.0, 6.7.0 through 6.7.2, 6.6.0 through 6.6.3, 6.5.1, 6.5.0 allows attacker to escalate privilege via uploading certain GUI elements

  • CVE-2023-36553CriNov 14, 2023
    risk 0.64cvss 9.8epss 0.02

    A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiSIEM version 5.4.0 and 5.3.0 through 5.3.3 and 5.2.5 through 5.2.8 and 5.2.1 through 5.2.2 and 5.1.0 through 5.1.3 and 5.0.0 through 5.0.1 and 4.10.0 and 4.9.0 and 4.7.2…

  • CVE-2019-16153CriJan 23, 2020
    risk 0.64cvss 9.8epss 0.01

    A hard-coded password vulnerability in the Fortinet FortiSIEM database component version 5.2.5 and below may allow attackers to access the device database via the use of static credentials.

  • CVE-2019-17653HigMar 12, 2020
    risk 0.57cvss 8.8epss 0.01

    A Cross-Site Request Forgery (CSRF) vulnerability in the user interface of Fortinet FortiSIEM 5.2.5 could allow a remote, unauthenticated attacker to perform arbitrary actions using an authenticated user's session by persuading the victim to follow a malicious link.

  • CVE-2023-40723HigMar 11, 2025
    risk 0.53cvss 8.1epss 0.00

    An exposure of sensitive information to an unauthorized actor in Fortinet FortiSIEM version 6.7.0 through 6.7.4 and 6.6.0 through 6.6.3 and 6.5.0 through 6.5.1 and 6.4.0 through 6.4.2 and 6.3.0 through 6.3.3 and 6.2.0 through 6.2.1 and 6.1.0 through 6.1.2 and 5.4.0 and 5.3.0…

  • CVE-2022-42478HigJun 13, 2023
    risk 0.53cvss 8.1epss 0.01

    An Improper Restriction of Excessive Authentication Attempts [CWE-307] in FortiSIEM below 7.0.0 may allow a non-privileged user with access to several endpoints to brute force attack these endpoints.

  • CVE-2022-26119HigNov 2, 2022
    risk 0.51cvss 7.8epss 0.00

    A improper authentication vulnerability in Fortinet FortiSIEM before 6.5.0 allows a local attacker with CLI access to perform operations on the Glassfish server directly via a hardcoded password.

  • CVE-2021-41022HigNov 2, 2021
    risk 0.51cvss 7.8epss 0.00

    A improper privilege management in Fortinet FortiSIEM Windows Agent version 4.1.4 and below allows attacker to execute privileged code or commands via powershell scripts

  • CVE-2024-46667HigJan 14, 2025
    risk 0.49cvss 7.5epss 0.01

    A allocation of resources without limits or throttling in Fortinet FortiSIEM 5.3 all versions, 5.4 all versions, 6.x all versions, 7.0 all versions, and 7.1.0 through 7.1.5 may allow an attacker to deny valid TLS traffic via consuming all allotted connections.

  • CVE-2018-13378HigApr 17, 2019
    risk 0.47cvss 7.2epss 0.01

    An information disclosure vulnerability in Fortinet FortiSIEM 5.2.0 and below versions exposes the LDAP server plaintext password via the HTML source code.

  • CVE-2025-58324MedOct 14, 2025
    risk 0.42cvss 6.4epss 0.00

    An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiSIEM 7.2.0 through 7.2.2, 7.1 all versions, 7.0 all versions, 6.7 all versions, 6.6 all versions, 6.5 all versions, 6.4 all versions, 6.3 all versions, 6.2 all versions may allow an…

  • CVE-2019-6700MedJan 7, 2020
    risk 0.42cvss 6.5epss 0.01

    An information exposure vulnerability in the external authentication profile form of FortiSIEM 5.2.2 and earlier may allow an authenticated attacker to retrieve the external authentication password via the HTML source code.

  • CVE-2022-43949MedJun 13, 2023
    risk 0.40cvss 6.2epss 0.00

    A use of a broken or risky cryptographic algorithm [CWE-327] in Fortinet FortiSIEM before 6.7.1 allows a remote unauthenticated attacker to perform brute force attacks on GUI endpoints via taking advantage of outdated hashing methods.

  • CVE-2021-41023MedNov 2, 2021
    risk 0.36cvss 5.5epss 0.00

    A unprotected storage of credentials in Fortinet FortiSIEM Windows Agent version 4.1.4 and below allows an authenticated user to disclosure agent password due to plaintext credential storage in log files

  • CVE-2019-17651MedJan 28, 2020
    risk 0.35cvss 5.4epss 0.01

    An Improper Neutralization of Input vulnerability in the description and title parameters of a Device Maintenance Schedule in FortiSIEM version 5.2.5 and below may allow a remote authenticated attacker to perform a Stored Cross Site Scripting attack (XSS) by injecting malicious…

Page 1 of 2