Fortinet Fortisiem vulnerabilities

4 known vulnerabilities affecting fortinet/fortinet_fortisiem.

Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH2MEDIUM1

Vulnerabilities

Page 1 of 1
CVE-2022-26119HIGHCVSS 7.8vFortiSIEM 6.4.0, 6.3.3, 6.3.2, 6.3.1, 6.3.0, 6.2.1, 6.2.0, 6.1.2, 6.1.1, 6.1.0, 5.4.0, 5.3.3, 5.3.2, 5.3.1, 5.3.0, 5.2.8, 5.2.7, 5.2.6, 5.2.5, 5.2.2, 5.2.1, 5.1.3, 5.1.2, 5.1.1, 5.1.0, 5.0.1, 5.0.02022-11-02
CVE-2022-26119 [HIGH] CWE-798 CVE-2022-26119: A improper authentication vulnerability in Fortinet FortiSIEM before 6.5.0 allows a local attacker w A improper authentication vulnerability in Fortinet FortiSIEM before 6.5.0 allows a local attacker with CLI access to perform operations on the Glassfish server directly via a hardcoded password.
cvelistv5nvd
CVE-2019-17653HIGHCVSS 8.8v5.2.52020-03-12
CVE-2019-17653 [HIGH] CWE-352 CVE-2019-17653: A Cross-Site Request Forgery (CSRF) vulnerability in the user interface of Fortinet FortiSIEM 5.2.5 A Cross-Site Request Forgery (CSRF) vulnerability in the user interface of Fortinet FortiSIEM 5.2.5 could allow a remote, unauthenticated attacker to perform arbitrary actions using an authenticated user's session by persuading the victim to follow a malicious link.
cvelistv5nvd
CVE-2019-17651MEDIUMCVSS 5.4vFortiSIEM version 5.2.5 and below2020-01-28
CVE-2019-17651 [MEDIUM] CWE-79 CVE-2019-17651: An Improper Neutralization of Input vulnerability in the description and title parameters of a Devic An Improper Neutralization of Input vulnerability in the description and title parameters of a Device Maintenance Schedule in FortiSIEM version 5.2.5 and below may allow a remote authenticated attacker to perform a Stored Cross Site Scripting attack (XSS) by injecting malicious JavaScript code into the description field of a Device Maintenance schedu
cvelistv5nvd
CVE-2019-16153CRITICALCVSS 9.8vFortiSIEM 5.2.5 and below2020-01-23
CVE-2019-16153 [CRITICAL] CWE-798 CVE-2019-16153: A hard-coded password vulnerability in the Fortinet FortiSIEM database component version 5.2.5 and b A hard-coded password vulnerability in the Fortinet FortiSIEM database component version 5.2.5 and below may allow attackers to access the device database via the use of static credentials.
cvelistv5nvd