CVE-2023-40714: Path Traversal
Published Apr 2, 2025
·Updated
A relative path traversal in Fortinet FortiSIEM versions 7.0.0, 6.7.0 through 6.7.2, 6.6.0 through 6.6.3, 6.5.1, 6.5.0 allows attacker to escalate privilege via uploading certain GUI elements
Affected Software
5 affected components
Fortinet FortiSIEM>=6.7.0<6.7.3, >=6.6.0<6.6.4
Fortinet FortiSIEM>=6.4.0<=6.5.1
Fortinet FortiSIEM>=6.6.0<=6.6.3
Fortinet FortiSIEM>=6.7.0<=6.7.3
Fortinet FortiSIEM=7.0.0
Remediation
Information
Please upgrade to FortiSIEM version 7.0.1 or above
Please upgrade to FortiSIEM version 6.7.4 or above
Please upgrade to FortiSIEM version 6.6.4 or above
Please upgrade to FortiSIEM version 6.5.2 or above
Please upgrade to FortiSIEM version 6.4.3 or above
Event History
Apr 2, 2025
CVE Published
via MITRE·08:06 AM
Data Sourced
via MITRE·08:06 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·08:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-40714?
CVE-2023-40714 has been classified as a high severity vulnerability due to its potential for privilege escalation.
2
How do I fix CVE-2023-40714?
To fix CVE-2023-40714, upgrade Fortinet FortiSIEM to version 6.7.3 or later, or to version 6.6.4 or later.
3
What specific versions of Fortinet FortiSIEM are affected by CVE-2023-40714?
CVE-2023-40714 affects Fortinet FortiSIEM versions 7.0.0, 6.7.0 through 6.7.2, 6.6.0 through 6.6.3, 6.5.1, and 6.5.0.
4
What type of vulnerability is CVE-2023-40714?
CVE-2023-40714 is a relative path traversal vulnerability that allows an attacker to escalate privileges.
5
What are the potential impacts of CVE-2023-40714?
The potential impacts of CVE-2023-40714 include unauthorized access and control over the FortiSIEM system.