Cross-Site Request Forgery Vulnerability in Fortinet FortiSIEM
CVE-2019-17653

8.8HIGH

Key Information:

Vendor
Fortinet
Vendor
CVE Published:
12 March 2020

Summary

A Cross-Site Request Forgery (CSRF) vulnerability exists in the user interface of Fortinet's FortiSIEM 5.2.5. This security flaw enables a remote, unauthenticated attacker to execute arbitrary actions on behalf of authenticated users. By enticing a victim to click on a malicious link, attackers can exploit active user sessions, creating potential risks for data manipulation and unauthorized access.

Affected Version(s)

Fortinet FortiSIEM 5.2.5

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.