CyberzSOC

Publication detail
← Back to advisories & guidance

2025-008: High Vulnerabilities in Fortinet Products ↗ source

March 14, 2025 CERT-EU Advisory

Summary

It is recommended updating as soon as possible. forgery vulnerability in FortiNDR that may allow a remote unauthenticated attacker to execute unauthorised actions via crafted HTTP GET requests [2]. that may allow a privileged attacker to execute unauthorised code or commands via specially crafted HTTP or HTTPS commands [3]. information to an unauthorised actor in FortiSIEM that may allow a remote unauthenticated attacker who acquired knowledge of the agent’s authorisation header by other means to read the database password via crafted api requests [4]. Fortinet also fixes low and medium severity vulnerabilities in their products [1]. The vulnerability CVE-2023-48790 affects the following products and versions [2]: The vulnerability CVE-2024-45324 affects the following products and versions [3]: The vulnerability CVE-2023-40723 affects the following products and versions [4]: CERT-EU recommends updating the affected products as soon as possible to the latest version.

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2023-40723 7.7 High Fortinet FortiSIEM An exposure of sensitive information to an unauthorized actor in Fortinet FortiSIEM version 6.7.0 through 6.7.4 and 6.6.0 through 6.6.3 and 6.5.0 thr…
CVE-2023-48790 7.1 High Fortinet FortiNDR A cross site request forgery vulnerability [CWE-352] in Fortinet FortiNDR version 7.4.0, 7.2.0 through 7.2.1 and 7.1.0 through 7.1.1 and before 7.0.5…
CVE-2024-45324 7.0 High Fortinet FortiPAM A use of externally-controlled format string vulnerability [CWE-134] in FortiOS version 7.4.0 through 7.4.4, version 7.2.0 through 7.2.9, version 7.0…

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.