Fortinet FortiSOAR 7.3.0

CPE Details

Fortinet FortiSOAR 7.3.0
7.3.0
2023-03-10
18h12 +00:00
2023-07-21
19h54 +00:00
Alerte pour un CPE
Restez informé de toutes modifications pour un CPE spécifique.
Gestion des notifications

CPE Name: cpe:2.3:a:fortinet:fortisoar:7.3.0:*:*:*:*:*:*:*

Informations

Vendor

fortinet

Product

fortisoar

Version

7.3.0

Related CVE

Open and find in CVE List

CVE ID Publié Description Score Gravité
CVE-2024-36510 2025-01-14 14h09 +00:00 An observable response discrepancy vulnerability [CWE-204] in FortiClientEMS 7.4.0, 7.2.0 through 7.2.4, 7.0 all versions, and FortiSOAR 7.5.0, 7.4.0 through 7.4.4, 7.3.0 through 7.3.2, 7.2 all versions, 7.0 all versions, 6.4 all versions may allow an unauthenticated attacker to enumerate valid users via observing login request responses.
5.3
Moyen
CVE-2024-48893 2025-01-14 14h08 +00:00 An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiSOAR 7.3.0 through 7.3.3, 7.2.1 through 7.2.2 may allow an authenticated attacker to perform a stored cross site scripting (XSS) attack via the creation of malicious playbook.
6.8
Moyen
CVE-2024-45327 2024-09-11 09h53 +00:00 An improper authorization vulnerability [CWE-285] in FortiSOAR version 7.4.0 through 7.4.3, 7.3.0 through 7.3.2, 7.2.0 through 7.2.2, 7.0.0 through 7.0.3 change password endpoint may allow an authenticated attacker to perform a brute force attack on users and administrators password via crafted HTTP requests.
7.5
Haute
CVE-2023-26211 2024-08-13 15h51 +00:00 An improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiSOAR 7.3.0 through 7.3.2 allows an authenticated, remote attacker to inject arbitrary web script or HTML via the Communications module.
9
Critique
CVE-2024-31493 2024-06-03 07h55 +00:00 An improper removal of sensitive information before storage or transfer vulnerability [CWE-212] in FortiSOAR version 7.3.0, version 7.2.2 and below, version 7.0.3 and below may allow an authenticated low privileged user to read Connector passwords in plain-text via HTTP responses.
6.5
Moyen
CVE-2023-27995 2023-04-11 16h05 +00:00 A improper neutralization of special elements used in a template engine vulnerability in Fortinet FortiSOAR 7.3.0 through 7.3.1 allows an authenticated, remote attacker to execute arbitrary code via a crafted payload.
8.8
Haute
CVE-2023-25605 2023-03-07 16h04 +00:00 A improper access control vulnerability in Fortinet FortiSOAR 7.3.0 - 7.3.1 allows an attacker authenticated on the administrative interface to perform unauthorized actions via crafted HTTP requests.
7.5
Haute