Fortinet Fortisoar vulnerabilities
33 known vulnerabilities affecting fortinet/fortisoar.
Total CVEs
33
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH14MEDIUM18
Vulnerabilities
Page 2 of 2
CVE-2024-45327HIGHCVSS 7.5≥ 7.0.0, < 7.3.3≥ 7.4.0, < 7.4.4+4 more2024-09-11
CVE-2024-45327 [HIGH] CWE-307 CVE-2024-45327: An improper authorization vulnerability [CWE-285] in FortiSOAR version 7.4.0 through 7.4.3, 7.3.0 th
An improper authorization vulnerability [CWE-285] in FortiSOAR version 7.4.0 through 7.4.3, 7.3.0 through 7.3.2, 7.2.0 through 7.2.2, 7.0.0 through 7.0.3 change password endpoint may allow an authenticated attacker to perform a brute force attack on users and administrators password via crafted HTTP requests.
nvdfortinet
CVE-2023-26211CRITICALCVSS 9.0≥ 6.4.0, < 7.3.3v7.4.0+5 more2024-08-13
CVE-2023-26211 [CRITICAL] CWE-79 CVE-2023-26211: An improper neutralization of input during web page generation ('cross-site scripting') in Fortinet
An improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiSOAR 7.3.0 through 7.3.2 allows an authenticated, remote attacker to inject arbitrary web script or HTML via the Communications module.
nvdfortinet
CVE-2023-23775HIGHCVSS 8.8≥ 7.0.0, < 7.2.1v7.2.0+1 more2024-06-11
CVE-2023-23775 [HIGH] CWE-89 CVE-2023-23775: Multiple improper neutralization of special elements used in SQL commands ('SQL Injection') vulnerab
Multiple improper neutralization of special elements used in SQL commands ('SQL Injection') vulnerabilities [CWE-89] in FortiSOAR 7.2.0 and before 7.0.3 may allow an authenticated attacker to execute unauthorized code or commands via specifically crafted strings parameters.
nvdfortinet
CVE-2024-31493MEDIUMCVSS 6.5≥ 7.0.0, < 7.3.1v7.3.0+2 more2024-06-03
CVE-2024-31493 [MEDIUM] CWE-212 CVE-2024-31493: An improper removal of sensitive information before storage or transfer vulnerability [CWE-212] in F
An improper removal of sensitive information before storage or transfer vulnerability [CWE-212] in FortiSOAR version 7.3.0, version 7.2.2 and below, version 7.0.3 and below may allow an authenticated low privileged user to read Connector passwords in plain-text via HTTP responses.
nvdfortinet
CVE-2023-27995HIGHCVSS 8.8≥ 7.3.0, < 7.3.2≥ 7.3.0, ≤ 7.3.12023-04-11
CVE-2023-27995 [HIGH] CWE-1336 CVE-2023-27995: A improper neutralization of special elements used in a template engine vulnerability in Fortinet Fo
A improper neutralization of special elements used in a template engine vulnerability in Fortinet FortiSOAR 7.3.0 through 7.3.1 allows an authenticated, remote attacker to execute arbitrary code via a crafted payload.
nvdfortinet
CVE-2023-25605HIGHCVSS 7.2≥ 7.3.0, < 7.3.2≥ 7.3.0, ≤ 7.3.12023-03-07
CVE-2023-25605 [HIGH] CWE-284 CVE-2023-25605: A improper access control vulnerability in Fortinet FortiSOAR 7.3.0 - 7.3.1 allows an attacker authe
A improper access control vulnerability in Fortinet FortiSOAR 7.3.0 - 7.3.1 allows an attacker authenticated on the administrative interface to perform unauthorized actions via crafted HTTP requests.
nvdfortinet
CVE-2022-38379MEDIUMCVSS 5.4≥ 7.0.0, ≤ 7.0.3v7.2.02022-12-06
CVE-2022-38379 [MEDIUM] CWE-79 CVE-2022-38379: Improper neutralization of input during web page generation [CWE-79] in FortiSOAR 7.0.0 through 7.0.
Improper neutralization of input during web page generation [CWE-79] in FortiSOAR 7.0.0 through 7.0.3 and 7.2.0 may allow an authenticated attacker to inject HTML tags via input fields of various components within FortiSOAR.
nvdfortinet
CVE-2022-42473MEDIUMCVSS 5.5≥ 6.4.0, ≤ 6.4.4≥ 7.0.0, ≤ 7.0.3+1 more2022-11-02
CVE-2022-42473 [MEDIUM] CWE-306 CVE-2022-42473: A missing authentication for a critical function vulnerability in Fortinet FortiSOAR 6.4.0 - 6.4.4 a
A missing authentication for a critical function vulnerability in Fortinet FortiSOAR 6.4.0 - 6.4.4 and 7.0.0 - 7.0.3 and 7.2.0 allows an attacker to disclose information via logging into the database using a privileged account without a password.
nvdfortinet
CVE-2022-29061HIGHCVSS 7.2≥ 6.4.1, ≤ 6.4.4≥ 7.0.0, < 7.0.3+1 more2022-09-09
CVE-2022-29061 [HIGH] CWE-78 CVE-2022-29061: An improper neutralization of special elements used in an OS command ('OS Command Injection') vulner
An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiSOAR before 7.2.1 allows an authenticated attacker to execute unauthorized code or commands via crafted HTTP GET requests.
nvdfortinet
CVE-2022-30298HIGHCVSS 7.8≥ 6.4.0, ≤ 6.4.4≥ 7.0.0, < 7.0.3+1 more2022-09-06
CVE-2022-30298 [HIGH] CWE-269 CVE-2022-30298: An improper privilege management vulnerability [CWE-269] in Fortinet FortiSOAR before 7.2.1 allows a
An improper privilege management vulnerability [CWE-269] in Fortinet FortiSOAR before 7.2.1 allows a GUI user who has already found a way to modify system files (via another, unrelated and hypothetical exploit) to execute arbitrary Python commands as root.
nvdfortinet
CVE-2022-35847HIGHCVSS 8.8≥ 6.4.0, ≤ 6.4.4≥ 7.0.0, ≤ 7.0.3+1 more2022-09-06
CVE-2022-35847 [HIGH] CWE-94 CVE-2022-35847: An improper neutralization of special elements used in a template engine vulnerability [CWE-1336] in
An improper neutralization of special elements used in a template engine vulnerability [CWE-1336] in FortiSOAR management interface 7.2.0, 7.0.0 through 7.0.3, 6.4.0 through 6.4.4 may allow a remote and authenticated attacker to execute arbitrary code via a crafted payload.
nvdfortinet
CVE-2022-29062MEDIUMCVSS 6.5≥ 7.0.0, < 7.0.3v7.2.02022-09-06
CVE-2022-29062 [MEDIUM] CWE-22 CVE-2022-29062: Multiple relative path traversal vulnerabilities [CWE-23] in Fortinet FortiSOAR before 7.2.1 allows
Multiple relative path traversal vulnerabilities [CWE-23] in Fortinet FortiSOAR before 7.2.1 allows an authenticated attacker to write to the underlying filesystem with nginx permissions via crafted HTTP requests.
nvdfortinet
CVE-2022-23443HIGHCVSS 7.5≥ 6.4.0, ≤ 6.4.4≥ 7.0.0, ≤ 7.0.2+1 more2022-05-04
CVE-2022-23443 [HIGH] CVE-2022-23443: An improper access control in Fortinet FortiSOAR before 7.2.0 allows unauthenticated attackers to ac
An improper access control in Fortinet FortiSOAR before 7.2.0 allows unauthenticated attackers to access gateway API data via crafted HTTP GET requests.
nvdfortinet
← Previous2 / 2