CVE-2024-55592: Incorrect authorization in incident page
An incorrect authorization vulnerability [CWE-863] in FortiSIEM 7.2 all versions, 7.1 all versions, 7.0 all versions, 6.7 all versions, 6.6 all versions, 6.5 all versions, 6.4 all versions, 6.3 all versions, 6.2 all versions, 6.1 all versions, 5.4 all versions, 5.3 all versions, may allow an authenticated attacker to perform unauthorized operations on incidents via crafted HTTP requests.
Other sources
An incorrect authorization vulnerability [CWE-863] in FortiSIEM may allow an authenticated attacker to perform unauthorized operations on incidents via crafted HTTP requests.
— FortiGuard
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-55592?
CVE-2024-55592 is classified as a critical vulnerability due to its potential impact on unauthorized access.
How do I fix CVE-2024-55592?
To fix CVE-2024-55592, update FortiSIEM to the latest version which addresses this authorization issue.
What versions of FortiSIEM are affected by CVE-2024-55592?
CVE-2024-55592 affects FortiSIEM versions 5.3 through 7.2, including all versions in between.
What are the consequences of exploitation of CVE-2024-55592?
Exploitation of CVE-2024-55592 may allow unauthorized users to gain access to sensitive data or system functionalities.
Is Fortinet providing patches for CVE-2024-55592?
Yes, Fortinet is providing patches for CVE-2024-55592 through software updates for affected versions.