Vulnerabilities
Vulnerable Software
Fortinet:  >> Fortisiem  >> 6.7.3  Security Vulnerabilities
An exposure of sensitive information to an unauthorized actor [CWE-200] in FortiSIEM version 7.0.0 and before 6.7.5 may allow an attacker with access to windows agent logs to obtain the windows agent password via searching through the logs.
CVSS Score
4.3
EPSS Score
0.003
Published
2023-11-14
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiSIEM version 7.0.0 and 6.7.0 through 6.7.5 and 6.6.0 through 6.6.3 and 6.5.0 through 6.5.1 and 6.4.0 through 6.4.2 allows attacker to execute unauthorized code or commands via crafted API requests.
CVSS Score
9.8
EPSS Score
0.793
Published
2023-10-10
A exposure of sensitive information to an unauthorized actor in Fortinet FortiSIEM version 6.7.0 through 6.7.5 allows attacker to information disclosure via a crafted http request.
CVSS Score
4.3
EPSS Score
0.005
Published
2023-09-13
A plaintext storage of a password vulnerability [CWE-256] in FortiSIEM 6.7 all versions, 6.6 all versions, 6.5 all versions, 6.4 all versions, 6.3 all versions, 6.2 all versions, 6.1 all versions, 5.4 all versions, 5.3 all versions may allow an attacker able to access user DB content to impersonate any admin user on the device GUI.
CVSS Score
3.7
EPSS Score
0.002
Published
2023-06-13


Contact Us

Shodan ® - All rights reserved