Vulnerabilities > Fortinet > Fortisiem > Low

DATE CVE VULNERABILITY TITLE RISK
2023-11-14 CVE-2023-45585 Information Exposure Through Log Files vulnerability in Fortinet Fortisiem
An insertion of sensitive information into log file vulnerability [CWE-532] in FortiSIEM version 7.0.0, version 6.7.6 and below, version 6.6.3 and below, version 6.5.1 and below, version 6.4.2 and below, version 6.3.3 and below, version 6.2.1 and below, version 6.1.2 and below, version 5.4.0, version 5.3.3 and below may allow an authenticated user to view an encrypted ElasticSearch password via debug log files generated when FortiSIEM is configured with ElasticSearch Event Storage.
local
low complexity
fortinet CWE-532
3.3
2021-11-02 CVE-2021-41023 Insufficiently Protected Credentials vulnerability in Fortinet Fortisiem
A unprotected storage of credentials in Fortinet FortiSIEM Windows Agent version 4.1.4 and below allows an authenticated user to disclosure agent password due to plaintext credential storage in log files
local
low complexity
fortinet CWE-522
2.1
2020-01-28 CVE-2019-17651 Cross-site Scripting vulnerability in Fortinet Fortisiem
An Improper Neutralization of Input vulnerability in the description and title parameters of a Device Maintenance Schedule in FortiSIEM version 5.2.5 and below may allow a remote authenticated attacker to perform a Stored Cross Site Scripting attack (XSS) by injecting malicious JavaScript code into the description field of a Device Maintenance schedule.
network
fortinet CWE-79
3.5