Vulnerabilities > Fortinet > Fortisiem > Medium

DATE CVE VULNERABILITY TITLE RISK
2023-11-14 CVE-2023-41676 Insufficiently Protected Credentials vulnerability in Fortinet Fortisiem
An exposure of sensitive information to an unauthorized actor [CWE-200] in FortiSIEM version 7.0.0 and before 6.7.5 may allow an attacker with access to windows agent logs to obtain the windows agent password via searching through the logs.
network
low complexity
fortinet CWE-522
6.5
2023-09-13 CVE-2023-36551 Unspecified vulnerability in Fortinet Fortisiem
A exposure of sensitive information to an unauthorized actor in Fortinet FortiSIEM version 6.7.0 through 6.7.5 allows attacker to information disclosure via a crafted http request.
network
low complexity
fortinet
5.3
2021-11-02 CVE-2021-41022 Improper Privilege Management vulnerability in Fortinet Fortisiem
A improper privilege management in Fortinet FortiSIEM Windows Agent version 4.1.4 and below allows attacker to execute privileged code or commands via powershell scripts
local
low complexity
fortinet CWE-269
4.6
2020-03-12 CVE-2019-17653 Cross-Site Request Forgery (CSRF) vulnerability in Fortinet Fortisiem 5.2.5
A Cross-Site Request Forgery (CSRF) vulnerability in the user interface of Fortinet FortiSIEM 5.2.5 could allow a remote, unauthenticated attacker to perform arbitrary actions using an authenticated user's session by persuading the victim to follow a malicious link.
network
fortinet CWE-352
6.8
2020-01-07 CVE-2019-6700 Insufficiently Protected Credentials vulnerability in Fortinet Fortisiem
An information exposure vulnerability in the external authentication profile form of FortiSIEM 5.2.2 and earlier may allow an authenticated attacker to retrieve the external authentication password via the HTML source code.
network
low complexity
fortinet CWE-522
4.0
2019-04-17 CVE-2018-13378 Information Exposure vulnerability in Fortinet Fortisiem
An information disclosure vulnerability in Fortinet FortiSIEM 5.2.0 and below versions exposes the LDAP server plaintext password via the HTML source code.
network
low complexity
fortinet CWE-200
4.0