Vulnerabilities
Vulnerable Software
Fortinet:  >> Fortisiem  >> 5.2.7  Security Vulnerabilities
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiSIEM version 5.4.0 and 5.3.0 through 5.3.3 and 5.2.5 through 5.2.8 and 5.2.1 through 5.2.2 and 5.1.0 through 5.1.3 and 5.0.0 through 5.0.1 and 4.10.0 and 4.9.0 and 4.7.2 allows attacker to execute unauthorized code or commands via crafted API requests.
CVSS Score
9.8
EPSS Score
0.018
Published
2023-11-14
An Improper Restriction of Excessive Authentication Attempts [CWE-307] in FortiSIEM below 7.0.0 may allow a non-privileged user with access to several endpoints to brute force attack these endpoints.
CVSS Score
8.1
EPSS Score
0.002
Published
2023-06-13
A improper authentication vulnerability in Fortinet FortiSIEM before 6.5.0 allows a local attacker with CLI access to perform operations on the Glassfish server directly via a hardcoded password.
CVSS Score
7.8
EPSS Score
0.001
Published
2022-11-02


Contact Us

Shodan ® - All rights reserved