CVE-2022-26119

A improper authentication vulnerability in Fortinet FortiSIEM before 6.5.0 allows a local attacker with CLI access to perform operations on the Glassfish server directly via a hardcoded password.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
fortinetCNA
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:U/RC:C
CVEADP
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 19%
VendorProductVersion
fortinetfortisiem
5.1.0 ≤
𝑥
≤ 5.1.3
fortinetfortisiem
5.2.5 ≤
𝑥
≤ 5.2.8
fortinetfortisiem
5.3.0 ≤
𝑥
≤ 5.3.3
fortinetfortisiem
6.1.0 ≤
𝑥
≤ 6.1.2
fortinetfortisiem
6.3.0 ≤
𝑥
≤ 6.3.3
fortinetfortisiem
5.0.0
fortinetfortisiem
5.0.1
fortinetfortisiem
5.2.1
fortinetfortisiem
5.2.2
fortinetfortisiem
5.4.0
fortinetfortisiem
6.2.0
fortinetfortisiem
6.2.1
fortinetfortisiem
6.4.0
fortinetfortisiem
6.4.1
𝑥
= Vulnerable software versions