Fortinet

Fortisiem

26 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Medienbericht
  • EPSS 37.55%
  • Veröffentlicht 12.08.2025 18:59:14
  • Zuletzt bearbeitet 15.08.2025 18:15:27

An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiSIEM version 7.3.0 through 7.3.1, 7.2.0 through 7.2.5, 7.1.0 through 7.1.7, 7.0.0 through 7.0.3 and before 6.7.9 all...

  • EPSS 0.31%
  • Veröffentlicht 02.04.2025 08:15:13
  • Zuletzt bearbeitet 15.07.2025 19:41:08

A relative path traversal in Fortinet FortiSIEM versions 7.0.0, 6.7.0 through 6.7.2, 6.6.0 through 6.6.3, 6.5.1, 6.5.0 allows attacker to escalate privilege via uploading certain GUI elements

  • EPSS 0.11%
  • Veröffentlicht 17.03.2025 13:06:07
  • Zuletzt bearbeitet 15.07.2025 16:48:48

A use of hard-coded cryptographic key vulnerability in FortiSIEM version 5.2.6 may allow a remote unauthenticated attacker to obtain SSH access to the supervisor as the restricted user "tunneluser" by leveraging knowledge of the private key from anot...

  • EPSS 0.02%
  • Veröffentlicht 11.03.2025 14:54:29
  • Zuletzt bearbeitet 25.07.2025 14:25:49

An incorrect authorization vulnerability [CWE-863] in FortiSIEM 7.2 all versions, 7.1 all versions, 7.0 all versions, 6.7 all versions, 6.6 all versions, 6.5 all versions, 6.4 all versions, 6.3 all versions, 6.2 all versions, 6.1 all versions, 5.4 al...

  • EPSS 0.08%
  • Veröffentlicht 11.03.2025 14:54:28
  • Zuletzt bearbeitet 22.07.2025 21:21:00

An exposure of sensitive information to an unauthorized actor in Fortinet FortiSIEM version 6.7.0 through 6.7.4 and 6.6.0 through 6.6.3 and 6.5.0 through 6.5.1 and 6.4.0 through 6.4.2 and 6.3.0 through 6.3.3 and 6.2.0 through 6.2.1 and 6.1.0 through ...

  • EPSS 0.02%
  • Veröffentlicht 11.02.2025 17:15:21
  • Zuletzt bearbeitet 16.07.2025 14:54:28

Multiple Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerabilities [CWE-79] in FortiSIEM 7.1 all versions, 7.0 all versions, 6.7 all versions incident page may allow an authenticated attacker to perform a c...

  • EPSS 0.09%
  • Veröffentlicht 14.01.2025 14:15:34
  • Zuletzt bearbeitet 03.02.2025 22:01:44

An Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability [CWE-89] in FortiSIEM ersion 7.1.7 and below, version 7.1.0, version 7.0.3 and below, version 6.7.9 and below, 6.7.8, version 6.6.5 and below, versi...

  • EPSS 0.17%
  • Veröffentlicht 14.01.2025 14:15:31
  • Zuletzt bearbeitet 16.07.2025 13:16:19

A allocation of resources without limits or throttling in Fortinet FortiSIEM 5.3 all versions, 5.4 all versions, 6.x all versions, 7.0 all versions, and 7.1.0 through 7.1.5 may allow an attacker to deny valid TLS traffic via consuming all allotted co...

  • EPSS 5.01%
  • Veröffentlicht 05.02.2024 14:15:59
  • Zuletzt bearbeitet 21.11.2024 08:56:56

An improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiSIEM version 7.1.0 through 7.1.1 and 7.0.0 through 7.0.2 and 6.7.0 through 6.7.8 and 6.6.0 through 6.6.3 and 6.5.0 through 6.5.2 and 6.4.0 ...

  • EPSS 88.68%
  • Veröffentlicht 05.02.2024 14:15:57
  • Zuletzt bearbeitet 21.11.2024 08:56:56

An improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiSIEM version 7.1.0 through 7.1.1 and 7.0.0 through 7.0.2 and 6.7.0 through 6.7.8 and 6.6.0 through 6.6.3 and 6.5.0 through 6.5.2 and 6.4.0 ...