Fortinet Fortisoar vulnerabilities

24 known vulnerabilities affecting fortinet/fortisoar.

Total CVEs
24
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH12MEDIUM11

Vulnerabilities

Page 2 of 2
CVE-2022-30298HIGHCVSS 7.8≥ 6.4.0, ≤ 6.4.4≥ 7.0.0, < 7.0.3+1 more2022-09-06
CVE-2022-30298 [HIGH] CWE-269 CVE-2022-30298: An improper privilege management vulnerability [CWE-269] in Fortinet FortiSOAR before 7.2.1 allows a An improper privilege management vulnerability [CWE-269] in Fortinet FortiSOAR before 7.2.1 allows a GUI user who has already found a way to modify system files (via another, unrelated and hypothetical exploit) to execute arbitrary Python commands as root.
nvd
CVE-2022-35847HIGHCVSS 8.8≥ 6.4.0, ≤ 6.4.4≥ 7.0.0, ≤ 7.0.3+1 more2022-09-06
CVE-2022-35847 [MEDIUM] CWE-94 CVE-2022-35847: An improper neutralization of special elements used in a template engine vulnerability [CWE-1336] in An improper neutralization of special elements used in a template engine vulnerability [CWE-1336] in FortiSOAR management interface 7.2.0, 7.0.0 through 7.0.3, 6.4.0 through 6.4.4 may allow a remote and authenticated attacker to execute arbitrary code via a crafted payload.
nvd
CVE-2022-29062MEDIUMCVSS 6.5≥ 7.0.0, < 7.0.3v7.2.02022-09-06
CVE-2022-29062 [MEDIUM] CWE-22 CVE-2022-29062: Multiple relative path traversal vulnerabilities [CWE-23] in Fortinet FortiSOAR before 7.2.1 allows Multiple relative path traversal vulnerabilities [CWE-23] in Fortinet FortiSOAR before 7.2.1 allows an authenticated attacker to write to the underlying filesystem with nginx permissions via crafted HTTP requests.
nvd
CVE-2022-23443HIGHCVSS 7.5≥ 6.4.0, ≤ 6.4.4≥ 7.0.0, ≤ 7.0.2+1 more2022-05-04
CVE-2022-23443 [HIGH] CVE-2022-23443: An improper access control in Fortinet FortiSOAR before 7.2.0 allows unauthenticated attackers to ac An improper access control in Fortinet FortiSOAR before 7.2.0 allows unauthenticated attackers to access gateway API data via crafted HTTP GET requests.
nvd