Impact
The vulnerability is a server‑side request forgery (SSRF) that allows an attacker to direct the FortiSIEM server to send arbitrary requests. Accordingly, this could lead to the execution of unauthorized code or commands if the attacker can reach internal or external services. The flaw is identified as CWE‑918, indicating that the server does not properly validate user‑controlled URLs or payloads. Impact is restricted to the FortiSIEM appliance – the attacker must be able to submit a malicious request to a vulnerable component, typically through the web interface or API. Inferred from the description, the threat requires network access to the FortiSIEM appliance and exploitation of an SSRF‑capable endpoint.
Affected Systems
Affected systems include Fortinet FortiSIEM releases: 7.5.0, 7.4.0 through 7.4.2, 7.3.0 through 7.3.5, all 7.2.x, all 7.1.x, all 7.0.x, all 6.7.x, all 6.6.x, and all 6.5.x server‑side request forgery vulnerable API components. FortiSIEM versions 7.5.1 and later, 7.4.3 and later, and 7.3.6 and later include the fix, so these are not affected.
Risk and Exploitability
The risk rating is low, with a CVSS score of 3.4 and no EPSS data available. The flaw is not listed in the CISA KEV catalog, indicating no documented large‑scale exploitation. Nonetheless, the attack vector is inferred to be via the web interface or API, and would require an attacker with network access to the FortiSIEM appliance. Proper access controls and network segmentation reduce the likelihood of a successful attack, but no known public exploit exists as of the latest data.
OpenCVE Enrichment