Fortinet FortiSOAR 7.3.0

CPE Details

Fortinet FortiSOAR 7.3.0
7.3.0
2023-03-10
18h12 +00:00
2023-07-21
19h54 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:fortinet:fortisoar:7.3.0:*:*:*:*:*:*:*

Informations

Vendor

fortinet

Product

fortisoar

Version

7.3.0

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2024-36510 2025-01-14 14h09 +00:00 An observable response discrepancy vulnerability [CWE-204] in FortiClientEMS 7.4.0, 7.2.0 through 7.2.4, 7.0 all versions, and FortiSOAR 7.5.0, 7.4.0 through 7.4.4, 7.3.0 through 7.3.2, 7.2 all versions, 7.0 all versions, 6.4 all versions may allow an unauthenticated attacker to enumerate valid users via observing login request responses.
5.3
Medium
CVE-2024-48893 2025-01-14 14h08 +00:00 An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiSOAR 7.3.0 through 7.3.3, 7.2.1 through 7.2.2 may allow an authenticated attacker to perform a stored cross site scripting (XSS) attack via the creation of malicious playbook.
6.8
Medium
CVE-2024-45327 2024-09-11 09h53 +00:00 An improper authorization vulnerability [CWE-285] in FortiSOAR version 7.4.0 through 7.4.3, 7.3.0 through 7.3.2, 7.2.0 through 7.2.2, 7.0.0 through 7.0.3 change password endpoint may allow an authenticated attacker to perform a brute force attack on users and administrators password via crafted HTTP requests.
7.5
High
CVE-2023-26211 2024-08-13 15h51 +00:00 An improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiSOAR 7.3.0 through 7.3.2 allows an authenticated, remote attacker to inject arbitrary web script or HTML via the Communications module.
9
Critical
CVE-2024-31493 2024-06-03 07h55 +00:00 An improper removal of sensitive information before storage or transfer vulnerability [CWE-212] in FortiSOAR version 7.3.0, version 7.2.2 and below, version 7.0.3 and below may allow an authenticated low privileged user to read Connector passwords in plain-text via HTTP responses.
6.5
Medium
CVE-2023-27995 2023-04-11 16h05 +00:00 A improper neutralization of special elements used in a template engine vulnerability in Fortinet FortiSOAR 7.3.0 through 7.3.1 allows an authenticated, remote attacker to execute arbitrary code via a crafted payload.
8.8
High
CVE-2023-25605 2023-03-07 16h04 +00:00 A improper access control vulnerability in Fortinet FortiSOAR 7.3.0 - 7.3.1 allows an attacker authenticated on the administrative interface to perform unauthorized actions via crafted HTTP requests.
7.5
High