cbcvebase.

Fortinet Fortisiem vulnerabilities

31 known vulnerabilities affecting fortinet/fortisiem.

Total CVEs
31
CISA KEV
0
Public exploits
4
Exploited in wild
4
Severity breakdown
CRITICAL8HIGH11MEDIUM10LOW2

Vulnerabilities

Page 2 of 2
CVE-2018-13378P3HIGHCVSS 7.2≤ 5.2.02019-04-17
CVE-2018-13378 [HIGH] CWE-200 CVE-2018-13378: An information disclosure vulnerability in Fortinet FortiSIEM 5.2.0 and below versions exposes the L An information disclosure vulnerability in Fortinet FortiSIEM 5.2.0 and below versions exposes the LDAP server plaintext password via the HTML source code.
nvd
CVE-2023-41676P3MEDIUMCVSS 6.5≥ 6.7.0, ≤ 6.7.5v7.0.02023-11-14
CVE-2023-41676 [MEDIUM] CWE-200 CVE-2023-41676: An exposure of sensitive information to an unauthorized actor [CWE-200] in FortiSIEM version 7.0.0 An exposure of sensitive information to an unauthorized actor [CWE-200] in FortiSIEM version 7.0.0 and before 6.7.5 may allow an attacker with access to windows agent logs to obtain the windows agent password via searching through the logs.
nvd
CVE-2026-25972P4MEDIUMCVSS 6.1≥ 7.3.0, < 7.3.5v7.4.0+1 more2026-03-10
CVE-2026-25972 [MEDIUM] CWE-79 CVE-2026-25972: An improper neutralization of input during web page generation ('cross-site scripting') vulnerabilit An improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiSIEM 7.4.0, FortiSIEM 7.3.0 through 7.3.4 may allow a remote unauthenticated attacker to provide arbitrary data enabling a social engineering attack via spoofed URL parameters.
nvd
CVE-2023-36551P4MEDIUMCVSS 5.3≥ 6.7.0, < 6.7.6≥ 6.7.0, ≤ 6.7.52023-09-13
CVE-2023-36551 [MEDIUM] CWE-200 CVE-2023-36551: A exposure of sensitive information to an unauthorized actor in Fortinet FortiSIEM version 6.7.0 thr A exposure of sensitive information to an unauthorized actor in Fortinet FortiSIEM version 6.7.0 through 6.7.5 allows attacker to information disclosure via a crafted http request.
nvd
CVE-2019-17651P4MEDIUMCVSS 5.4≤ 5.2.52020-01-28
CVE-2019-17651 [MEDIUM] CWE-79 CVE-2019-17651: An Improper Neutralization of Input vulnerability in the description and title parameters of a Devic An Improper Neutralization of Input vulnerability in the description and title parameters of a Device Maintenance Schedule in FortiSIEM version 5.2.5 and below may allow a remote authenticated attacker to perform a Stored Cross Site Scripting attack (XSS) by injecting malicious JavaScript code into the description field of a Device Maintenance schedu
nvd
CVE-2024-27780P4MEDIUMCVSS 5.4≥ 6.7.0, ≤ 6.7.9≥ 7.0.0, ≤ 7.0.3+1 more2025-02-11
CVE-2024-27780 [MEDIUM] CWE-79 CVE-2024-27780: Multiple Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulner Multiple Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerabilities [CWE-79] in FortiSIEM 7.1 all versions, 7.0 all versions, 6.7 all versions incident page may allow an authenticated attacker to perform a cross-site scripting attack via crafted HTTP requests.
nvd
CVE-2021-41023P4MEDIUMCVSS 5.5≥ 3.1.0, ≤ 4.1.42021-11-02
CVE-2021-41023 [MEDIUM] CWE-522 CVE-2021-41023: A unprotected storage of credentials in Fortinet FortiSIEM Windows Agent version 4.1.4 and below all A unprotected storage of credentials in Fortinet FortiSIEM Windows Agent version 4.1.4 and below allows an authenticated user to disclosure agent password due to plaintext credential storage in log files
nvd
CVE-2026-59838P4MEDIUMCVSS 4.8≥ 6.4.0, < 7.2.7≥ 7.3.0, < 7.3.5+11 more2026-07-15
CVE-2026-59838 [MEDIUM] CWE-80 CVE-2026-59838: A improper neutralization of script-related html tags in a web page (basic xss) vulnerability in For A improper neutralization of script-related html tags in a web page (basic xss) vulnerability in Fortinet FortiSIEM 7.4.0, FortiSIEM 7.3.0 through 7.3.4, FortiSIEM 7.2.0 through 7.2.6, FortiSIEM 7.1 all versions, FortiSIEM 7.0 all versions, FortiSIEM 6.7 all versions, FortiSIEM 6.6 all versions, FortiSIEM 6.5 all versions, FortiSIEM 6.4 all versions
nvd
CVE-2025-58324P4MEDIUMCVSS 4.8≥ 6.2.0, < 7.2.3≥ 7.2.0, ≤ 7.2.2+8 more2025-10-14
CVE-2025-58324 [MEDIUM] CWE-79 CVE-2025-58324: An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiSIEM 7 An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiSIEM 7.2.0 through 7.2.2, 7.1 all versions, 7.0 all versions, 6.7 all versions, 6.6 all versions, 6.5 all versions, 6.4 all versions, 6.3 all versions, 6.2 all versions may allow an authenticated attacker to perform a stored cross site scripting (XSS) attack
nvd
CVE-2024-55592P4LOWCVSS 3.8≥ 5.3.0, ≤ 7.2.5≥ 7.2.0, ≤ 7.2.5+10 more2025-03-11
CVE-2024-55592 [LOW] CWE-863 CVE-2024-55592: An incorrect authorization vulnerability [CWE-863] in FortiSIEM 7.2 all versions, 7.1 all versions, An incorrect authorization vulnerability [CWE-863] in FortiSIEM 7.2 all versions, 7.1 all versions, 7.0 all versions, 6.7 all versions, 6.6 all versions, 6.5 all versions, 6.4 all versions, 6.3 all versions, 6.2 all versions, 6.1 all versions, 5.4 all versions, 5.3 all versions, may allow an authenticated attacker to perform unauthorized operations on i
nvd
CVE-2023-45585P4LOWCVSS 3.3≥ 5.3.0, ≤ 5.3.3≥ 6.7.0, ≤ 6.7.6+26 more2023-11-14
CVE-2023-45585 [LOW] CWE-532 CVE-2023-45585: An insertion of sensitive information into log file vulnerability [CWE-532] in FortiSIEM version 7.0 An insertion of sensitive information into log file vulnerability [CWE-532] in FortiSIEM version 7.0.0, version 6.7.6 and below, version 6.6.3 and below, version 6.5.1 and below, version 6.4.2 and below, version 6.3.3 and below, version 6.2.1 and below, version 6.1.2 and below, version 5.4.0, version 5.3.3 and below may allow an authenticated user to v
nvd