📦 Fortisiem

by Fortinet

🔍 What is Fortisiem?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-64155

CRITICAL CVSS 9.8 Jan 13, 2026

This CVE describes an OS command injection vulnerability in Fortinet FortiSIEM that allows attackers to execute arbitrary commands via crafted TCP requests. The vulnerability affects multiple FortiSIE...

CVE-2025-25256

CRITICAL CVSS 9.8 Aug 12, 2025

This critical vulnerability allows unauthenticated attackers to execute arbitrary operating system commands on FortiSIEM systems via crafted CLI requests. It affects FortiSIEM versions 6.7.8 and earli...

CVE-2023-40714

CRITICAL CVSS 9.9 Apr 2, 2025

This vulnerability allows attackers to perform relative path traversal in Fortinet FortiSIEM, enabling privilege escalation by uploading malicious GUI elements. It affects FortiSIEM versions 7.0.0, 6....

CVE-2024-23108

CRITICAL CVSS 10.0 Feb 5, 2024

This CVE describes an OS command injection vulnerability in Fortinet products that allows attackers to execute arbitrary commands via crafted API requests. Attackers can achieve remote code execution ...

CVE-2023-36553

CRITICAL CVSS 9.8 Nov 14, 2023

This CVE describes an OS command injection vulnerability in Fortinet FortiSIEM that allows attackers to execute arbitrary commands on affected systems via crafted API requests. The vulnerability affec...

CVE-2023-34992

CRITICAL CVSS 10.0 Oct 10, 2023

This critical OS command injection vulnerability in Fortinet products allows attackers to execute arbitrary commands on affected systems by sending specially crafted API requests. Attackers can gain c...

CVE-2023-40723

HIGH CVSS 8.1 Mar 11, 2025

This vulnerability in Fortinet FortiSIEM allows attackers to execute unauthorized code or commands via API requests, potentially leading to full system compromise. It affects multiple versions across ...

CVE-2024-46667

HIGH CVSS 7.5 Jan 14, 2025

This vulnerability in Fortinet FortiSIEM allows attackers to cause denial of service by consuming all available TLS connections through resource allocation without limits. It affects all versions of F...

CVE-2022-42478

HIGH CVSS 8.1 Jun 13, 2023

CVE-2022-42478 is an authentication brute force vulnerability in FortiSIEM that allows non-privileged users to perform unlimited authentication attempts against multiple endpoints. This affects FortiS...

CVE-2021-41022

HIGH CVSS 7.8 Nov 2, 2021

This vulnerability allows attackers to execute privileged code or commands on Windows systems running vulnerable FortiSIEM agents via PowerShell scripts. It affects Fortinet FortiSIEM Windows Agent ve...

CVE-2025-58324

MEDIUM CVSS 6.4 Oct 14, 2025

This vulnerability allows authenticated attackers to inject malicious scripts into FortiSIEM web pages, which execute when other users view those pages. It affects all versions of FortiSIEM from 6.2 t...

CVE-2024-52969

MEDIUM CVSS 4.1 Jan 14, 2025

This SQL injection vulnerability in FortiSIEM's Update/Create Case feature allows authenticated attackers to extract database information via crafted requests. It affects multiple FortiSIEM versions, ...