Vulnerabilities > Fortinet > Fortisoar > High

DATE CVE VULNERABILITY TITLE RISK
2024-09-11 CVE-2024-45327 Improper Restriction of Excessive Authentication Attempts vulnerability in Fortinet Fortisoar
An improper authorization vulnerability [CWE-285] in FortiSOAR version 7.4.0 through 7.4.3, 7.3.0 through 7.3.2, 7.2.0 through 7.2.2, 7.0.0 through 7.0.3 change password endpoint may allow an authenticated attacker to perform a brute force attack on users and administrators password via crafted HTTP requests.
network
high complexity
fortinet CWE-307
7.5
2024-06-11 CVE-2023-23775 Unspecified vulnerability in Fortinet Fortisoar
Multiple improper neutralization of special elements used in SQL commands ('SQL Injection') vulnerabilities [CWE-89] in FortiSOAR 7.2.0 and before 7.0.3 may allow an authenticated attacker to execute unauthorized code or commands via specifically crafted strings parameters.
network
low complexity
fortinet
8.8
2023-04-11 CVE-2023-27995 Unspecified vulnerability in Fortinet Fortisoar 7.3.0/7.3.1
A improper neutralization of special elements used in a template engine vulnerability in Fortinet FortiSOAR 7.3.0 through 7.3.1 allows an authenticated, remote attacker to execute arbitrary code via a crafted payload.
network
low complexity
fortinet
8.8
2023-03-07 CVE-2023-25605 Unspecified vulnerability in Fortinet Fortisoar 7.3.0/7.3.1
A improper access control vulnerability in Fortinet FortiSOAR 7.3.0 - 7.3.1 allows an attacker authenticated on the administrative interface to perform unauthorized actions via crafted HTTP requests.
network
low complexity
fortinet
7.2
2022-09-09 CVE-2022-29061 OS Command Injection vulnerability in Fortinet Fortisoar
An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiSOAR before 7.2.1 allows an authenticated attacker to execute unauthorized code or commands via crafted HTTP GET requests.
network
low complexity
fortinet CWE-78
7.2
2022-09-06 CVE-2022-30298 Improper Privilege Management vulnerability in Fortinet Fortisoar
An improper privilege management vulnerability [CWE-269] in Fortinet FortiSOAR before 7.2.1 allows a GUI user who has already found a way to modify system files (via another, unrelated and hypothetical exploit) to execute arbitrary Python commands as root.
local
low complexity
fortinet CWE-269
7.8
2022-09-06 CVE-2022-35847 Code Injection vulnerability in Fortinet Fortisoar
An improper neutralization of special elements used in a template engine vulnerability [CWE-1336] in FortiSOAR management interface 7.2.0, 7.0.0 through 7.0.3, 6.4.0 through 6.4.4 may allow a remote and authenticated attacker to execute arbitrary code via a crafted payload.
network
low complexity
fortinet CWE-94
8.8
2022-05-04 CVE-2022-23443 Unspecified vulnerability in Fortinet Fortisoar
An improper access control in Fortinet FortiSOAR before 7.2.0 allows unauthenticated attackers to access gateway API data via crafted HTTP GET requests.
network
low complexity
fortinet
7.5