CVE-2024-55592

Published Mar 11, 2025

Last updated 7 months ago

Overview

Description
An incorrect authorization vulnerability [CWE-863] in FortiSIEM 7.2 all versions, 7.1 all versions, 7.0 all versions, 6.7 all versions, 6.6 all versions, 6.5 all versions, 6.4 all versions, 6.3 all versions, 6.2 all versions, 6.1 all versions, 5.4 all versions, 5.3 all versions, may allow an authenticated attacker to perform unauthorized operations on incidents via crafted HTTP requests.
Source
psirt@fortinet.com
NVD status
Analyzed
Products
fortisiem

Risk scores

CVSS 3.1

Type
Secondary
Base score
3.8
Impact score
2.5
Exploitability score
1.2
Vector string
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N
Severity
LOW

Weaknesses

psirt@fortinet.com
CWE-863

Social media

Hype score
Not currently trending

Configurations

References

Sources include official advisories and independent security research.