Skip to main content

Vendor/product archive

fortinet / fortisiem CVEs

Beta · best-effort

31 CVEs tagged to fortinet / fortisiem8 Critical, 8 High, 10 Medium, 5 Low, 0 Unrated.

CVE-2026-59838

Published Jul 15, 2026

A improper neutralization of script-related html tags in a web page (basic xss) vulnerability in Fortinet FortiSIEM 7.4.0, FortiSIEM 7.3.0 through 7.3.4, FortiSIEM 7.2.0 through 7…

CVSS 5.9 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-59841

Published Jul 14, 2026

A improper restriction of communication channel to intended endpoints vulnerability in Fortinet FortiSIEMWindowsAgent 7.4.0 through 7.4.1 may allow attacker to escalation of privi…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-25972

Published Mar 10, 2026

An improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiSIEM 7.4.0, FortiSIEM 7.3.0 through 7.3.4 may allow a remote…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-64155

Published Jan 13, 2026

An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSIEM 7.4.0, FortiSIEM 7.3.0 through 7.3.4, FortiSIEM 7…

CVSS 9.8 · Critical
evidence mentions
8
Buzz score
36.5
Vendor/product tagsBeta · best-effort

CVE-2025-58324

Published Oct 14, 2025

An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiSIEM 7.2.0 through 7.2.2, 7.1 all versions, 7.0 all versions, 6.7 all versions, 6.6 a…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-25256

Published Aug 12, 2025

An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiSIEM version 7.3.0 through 7.3.1, 7.2.0 throu…

CVSS 9.8 · Critical
evidence mentions
15
Buzz score
47.7
Vendor/product tagsBeta · best-effort

CVE-2023-40714

Published Apr 2, 2025

A relative path traversal in Fortinet FortiSIEM versions 7.0.0, 6.7.0 through 6.7.2, 6.6.0 through 6.6.3, 6.5.1, 6.5.0 allows attacker to escalate privilege via uploading certain…

CVSS 9.9 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-17659

Published Mar 17, 2025

A use of hard-coded cryptographic key vulnerability in FortiSIEM version 5.2.6 may allow a remote unauthenticated attacker to obtain SSH access to the supervisor as the restricted…

CVSS 3.7 · Low
evidence mentions
3
Buzz score
20.4
Vendor/product tagsBeta · best-effort

CVE-2024-55592

Published Mar 11, 2025

An incorrect authorization vulnerability [CWE-863] in FortiSIEM 7.2 all versions, 7.1 all versions, 7.0 all versions, 6.7 all versions, 6.6 all versions, 6.5 all versions, 6.4 all…

CVSS 3.8 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-40723

Published Mar 11, 2025

An exposure of sensitive information to an unauthorized actor in Fortinet FortiSIEM version 6.7.0 through 6.7.4 and 6.6.0 through 6.6.3 and 6.5.0 through 6.5.1 and 6.4.0 through 6…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-27780

Published Feb 11, 2025

Multiple Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerabilities [CWE-79] in FortiSIEM 7.1 all versions, 7.0 all versions, 6.7 all ve…

CVSS 2.2 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-52969

Published Jan 14, 2025

An Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability [CWE-89] in FortiSIEM ersion 7.1.7 and below, version 7.1.0, version 7.0.3 an…

CVSS 4.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-46667

Published Jan 14, 2025

A allocation of resources without limits or throttling in Fortinet FortiSIEM 5.3 all versions, 5.4 all versions, 6.x all versions, 7.0 all versions, and 7.1.0 through 7.1.5 may al…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-23109

Published Feb 5, 2024

An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet allows attacker to execute unauthorized code or commands v…

CVSS 10.0 · Critical
evidence mentions
5
Buzz score
30.9
Vendor/product tagsBeta · best-effort

CVE-2024-23108

Published Feb 5, 2024

An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet allows attacker to execute unauthorized code or commands v…

CVSS 10.0 · Critical
evidence mentions
9
Buzz score
36.0
Vendor/product tagsBeta · best-effort

CVE-2023-45585

Published Nov 14, 2023

An insertion of sensitive information into log file vulnerability [CWE-532] in FortiSIEM version 7.0.0, version 6.7.6 and below, version 6.6.3 and below, version 6.5.1 and below,…

CVSS 2.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-41676

Published Nov 14, 2023

An exposure of sensitive information to an unauthorized actor [CWE-200] in FortiSIEM version 7.0.0 and before 6.7.5 may allow an attacker with access to windows agent logs to obt…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-36553

Published Nov 14, 2023

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiSIEM version 5.4.0 and 5.3.0 through 5.3.3 and 5.2.5 through 5.2.8 an…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2023-34992

Published Oct 10, 2023

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet allows attacker to execute unauthorized code or commands vi…

CVSS 10.0 · Critical
evidence mentions
9
Buzz score
36.0
Vendor/product tagsBeta · best-effort

CVE-2023-36551

Published Sep 13, 2023

A exposure of sensitive information to an unauthorized actor in Fortinet FortiSIEM version 6.7.0 through 6.7.5 allows attacker to information disclosure via a crafted http request.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-26204

Published Jun 13, 2023

A plaintext storage of a password vulnerability [CWE-256] in FortiSIEM 6.7 all versions, 6.6 all versions, 6.5 all versions, 6.4 all versions, 6.3 all versions, 6.2 all versions,…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-43949

Published Jun 13, 2023

A use of a broken or risky cryptographic algorithm [CWE-327] in Fortinet FortiSIEM before 6.7.1 allows a remote unauthenticated attacker to perform brute force attacks on GUI end…

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-42478

Published Jun 13, 2023

An Improper Restriction of Excessive Authentication Attempts [CWE-307] in FortiSIEM below 7.0.0 may allow a non-privileged user with access to several endpoints to brute force att…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2022-26119

Published Nov 2, 2022

A improper authentication vulnerability in Fortinet FortiSIEM before 6.5.0 allows a local attacker with CLI access to perform operations on the Glassfish server directly via a har…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2021-41023

Published Nov 2, 2021

A unprotected storage of credentials in Fortinet FortiSIEM Windows Agent version 4.1.4 and below allows an authenticated user to disclosure agent password due to plaintext credent…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 31 CVEsPage 1 of 2