Fortinet FortiWeb Stack based buffer overflow in SAML management (FG-IR-22-151)

high Nessus Plugin ID 171902

Version 1.5

Oct 28, 2024, 10:30 PM

  • CVSS metrics ("Cvssv4 score" set to 0.0)
  • CVSSv2 severity (based on None, severity decreased from "High" to "Low")
  • Detection (updated detection logic)
  • Plugin metadata

Plugin Feed: 202410282230

Version 1.4

Oct 27, 2024, 2:25 AM

  • CVSS metrics ("Cvssv4 score" set to 0.0)
  • CVSSv2 severity (based on None, severity decreased from "High" to "Low")
  • Detection (updated detection logic)
  • Plugin metadata

Plugin Feed: 202410270225

Version 1.3

May 22, 2024, 3:18 PM

  • Detection (updated detection logic)
  • Plugin metadata

Plugin Feed: 202405221518

Version 1.2

Mar 1, 2023, 2:07 PM

  • CVSS metrics ("CVSSv2 score" changed from "7.7" to "9.0". "CVSSv2 score" changed from "7.7" to "9.0". "CVSSv2 vector" changed from "CVSS2#AV:A/AC:L/Au:S/C:C/I:C/A:C" to "CVSS2#AV:N/AC:L/Au:S/C:C/I:C/A:C". "CVSSv3 score" changed from "8.0" to "8.8". "CVSSv3 vector" changed from "CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" to "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H". "CVSSv2 vector" changed from "CVSS2#AV:A/AC:L/Au:S/C:C/I:C/A:C" to "CVSS2#AV:N/AC:L/Au:S/C:C/I:C/A:C". "CVSSv3 score" changed from "8.0" to "8.8". "CVSSv3 vector" changed from "CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" to "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H". "CVSSv2 vector" changed from "CVSS2#AV:A/AC:L/Au:S/C:C/I:C/A:C" to "CVSS2#AV:N/AC:L/Au:S/C:C/I:C/A:C")
  • CVSSv3 score source (set to "CVE-2023-23781")

Plugin Feed: 202303011407

Version 1.1

Feb 27, 2023, 2:07 PM

  • CVSS metrics ("CVSSv2 score" changed from "6.2" to "7.7". "CVSSv2 score" changed from "6.2" to "7.7". "CVSSv2 score" changed from "6.2" to "7.7". "CVSSv2 score" changed from "6.2" to "7.7". "CVSSv2 vector" changed from "CVSS2#AV:A/AC:H/Au:M/C:C/I:C/A:C" to "CVSS2#AV:A/AC:L/Au:S/C:C/I:C/A:C". "CVSSv3 vector" changed from "CVSS:3.0/AV:A/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H" to "CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H". "CVSSv3 score" changed from "6.4" to "8.0". "CVSSv2 vector" changed from "CVSS2#AV:A/AC:H/Au:M/C:C/I:C/A:C" to "CVSS2#AV:A/AC:L/Au:S/C:C/I:C/A:C". "CVSSv3 vector" changed from "CVSS:3.0/AV:A/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H" to "CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H". "CVSSv3 score" changed from "6.4" to "8.0". "CVSSv2 vector" changed from "CVSS2#AV:A/AC:H/Au:M/C:C/I:C/A:C" to "CVSS2#AV:A/AC:L/Au:S/C:C/I:C/A:C". "CVSSv3 vector" changed from "CVSS:3.0/AV:A/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H" to "CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H". "CVSSv3 score" changed from "6.4" to "8.0")
  • CVSSv2 severity (based on CVE-2023-23781, severity increased from "Medium" to "High")
  • CVSSv3 score source (set to "CVE-2023-23781")
  • CVSSv3 severity (based on CVE-2023-23781, severity increased from "Medium" to "High")

Plugin Feed: 202302271407

Version 1.0

Feb 24, 2023, 6:03 PM

  • New

Plugin Feed: 202302241803

* Changelogs are generally available for changes made after Nov 1, 2022