Fortinet FortiSIEM Incorrect Authorization Vulnerability Allowing Unauthorized Incident Operations

Vulnerability

A vulnerability allowing incorrect authorization has been identified in Fortinet FortiSIEM across multiple versions, including 7.2, 7.1, 7.0, 6.7, 6.6, 6.5, 6.4, 6.3, 6.2, 6.1, 5.4, and 5.3. This vulnerability may enable an authenticated attacker to execute unauthorized actions on incidents by sending specially crafted HTTP requests.

Impact

Exploitation of this vulnerability could lead to unauthorized modifications or operations on incident data within FortiSIEM.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
1.9
impact
1.3
exploitability
5.2
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.