Fortinet Fortisoar On-Premise vulnerabilities
4 known vulnerabilities affecting fortinet/fortisoar_on-premise.
Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM3
Vulnerabilities
Page 1 of 1
CVE-2025-59808MEDIUMCVSS 6.8≥ 7.6.0, ≤ 7.6.2≥ 7.5.0, ≤ 7.5.1+2 more2025-12-09
CVE-2025-59808 [MEDIUM] CWE-620 CVE-2025-59808: An unverified password change vulnerability [CWE-620] vulnerability in Fortinet FortiSOAR PaaS 7.6.0
An unverified password change vulnerability [CWE-620] vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.2, FortiSOAR PaaS 7.5.0 through 7.5.1, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.0 through 7.6.2, FortiSOAR on-premise 7.5.0 through 7.5.1, FortiSOAR on-premise 7.4 all versions, FortiSOAR
cvelistv5nvd
CVE-2025-59810MEDIUMCVSS 6.5≥ 7.6.0, ≤ 7.6.2≥ 7.5.0, ≤ 7.5.1+2 more2025-12-09
CVE-2025-59810 [MEDIUM] CWE-284 CVE-2025-59810: An improper access control vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.2, FortiSOAR P
An improper access control vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.2, FortiSOAR PaaS 7.5.0 through 7.5.1, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.0 through 7.6.2, FortiSOAR on-premise 7.5.0 through 7.5.1, FortiSOAR on-premise 7.4 all versions, FortiSOAR on-premise 7.3 all versions
cvelistv5nvd
CVE-2024-48891HIGHCVSS 7.0v7.6.0≥ 7.5.0, ≤ 7.5.1+2 more2025-10-14
CVE-2024-48891 [HIGH] CWE-78 CVE-2024-48891: An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulner
An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] in FortiSOAR 7.6.0 through 7.6.1, 7.5.0 through 7.5.1, 7.4 all versions, 7.3 all versions may allow an attacker who has already obtained a non-login low privileged shell access (via another hypothetical vulnerability) to perform a local
cvelistv5nvd
CVE-2022-23439MEDIUMCVSS 6.1≥ 7.2.0, ≤ 7.2.2≥ 7.0.0, ≤ 7.0.3+2 more2025-01-22
CVE-2022-23439 [MEDIUM] CWE-610 CVE-2022-23439: A externally controlled reference to a resource in another sphere vulnerability in Fortinet allows
A externally controlled reference to a resource in another sphere vulnerability in Fortinet allows attacker to poison web caches via crafted HTTP requests, where the `Host` header points to an arbitrary webserver
cvelistv5nvd