CVE-2023-40714

CRITICAL

Fortinet FortiSIEM <6.7.2-6.6.3 - Path Traversal

Title source: llm

Description

A relative path traversal in Fortinet FortiSIEM versions 7.0.0, 6.7.0 through 6.7.2, 6.6.0 through 6.6.3, 6.5.1, 6.5.0 allows attacker to escalate privilege via uploading certain GUI elements

Scores

CVSS v3 9.9
EPSS 0.0051
EPSS Percentile 66.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Classification

CWE
CWE-23
Status published

Affected Products (2)

fortinet/fortisiem < 6.5.1
fortinet/fortisiem

Timeline

Published Apr 02, 2025
Tracked Since Feb 18, 2026