Vulnerabilities
Vulnerable Software
Fortinet:  >> Fortiaiops  Security Vulnerabilities
Multiple insufficient session expiration vulnerabilities [CWE-613] in FortiAIOps version 2.0.0 may allow an attacker to re-use stolen old session tokens to perform unauthorized operations via crafted requests.
CVSS Score
8.1
EPSS Score
0.002
Published
2024-07-09
Multiple cross-site request forgery (CSRF) vulnerabilities [CWE-352] in FortiAIOps version 2.0.0 may allow an unauthenticated remote attacker to perform arbitrary actions on behalf of an authenticated user via tricking the victim to execute malicious GET requests.
CVSS Score
7.6
EPSS Score
0.001
Published
2024-07-09
Multiple Exposure of sensitive information to an unauthorized actor vulnerabilities [CWE-200] in FortiAIOps version 2.0.0 may allow an authenticated, remote attacker to retrieve sensitive information from the API endpoint or log files.
CVSS Score
8.8
EPSS Score
0.002
Published
2024-07-09
An improper neutralization of formula elements in a CSV File vulnerability [CWE-1236] in FortiAIOps version 2.0.0 may allow a remote authenticated attacker to execute arbitrary commands on a client's workstation via poisoned CSV reports.
CVSS Score
5.4
EPSS Score
0.005
Published
2024-07-09


Contact Us

Shodan ® - All rights reserved