Server-Side Request Forgery (SSRF)

Low RiskCVSS 3.4FG-IR-26-159Aug 12, 2026
Fortinet
IT in OT - Fortinet products are commonly deployed at IT/OT network boundaries
Attack path
Attack VectorNetwork
Auth RequiredHigh
ComplexityLow
User InteractionNone needed
Summary

A Server-Side Request Forgery (SSRF) vulnerability exists in FortiSIEM and FortiSIEM Cloud that allows an authenticated administrator to make unauthorized requests to internal systems and external services accessible from the FortiSIEM server. The vulnerability affects multiple versions: 7.5.0 is fixed in 7.5.1+, but versions 7.4.0-7.4.2, 7.3.0-7.3.5, and earlier versions have no patch available.

What this means
What could happen
An authenticated admin on FortiSIEM could use the vulnerability to make unauthorized requests to internal systems and cloud services that the FortiSIEM server can reach, potentially accessing sensitive data or triggering unintended actions on those systems.
Who's at risk
FortiSIEM administrators and anyone managing security information and event logging in utilities and industrial facilities. This affects organizations using FortiSIEM for centralized log collection and security monitoring, particularly those with sensitive internal systems on the same network.
How it could be exploited
An attacker with admin credentials to FortiSIEM injects a malicious URL or request into a vulnerable function. FortiSIEM processes the request and makes an outbound connection to the attacker-specified target (internal server, cloud API, or network service). The attacker can then read responses or interact with systems that FortiSIEM has access to.
Prerequisites
  • Valid FortiSIEM admin credentials
  • Network access to FortiSIEM management interface
  • Target internal systems or cloud services reachable from FortiSIEM server
requires high privilege credentialslow attack complexitylow CVSS scoremany older versions lack patches
Exploitability
Unlikely to be exploited — EPSS score 0.3%
Affected products (3)
3 with fix
ProductAffected VersionsFix Status
FortiSIEM7.5.07.5.1+
FortiSIEM7.4.0 - 7.4.27.5.1
FortiSIEM7.3.0 - 7.3.5 and 6 more7.5.1
Remediation & Mitigation
0/4
Do now
0/1
FortiSIEM
WORKAROUNDRestrict FortiSIEM admin access to trusted network segments only using firewall rules
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

FortiSIEM
HOTFIXUpdate FortiSIEM 7.5.0 to version 7.5.1 or later
Long-term hardening
0/2
FortiSIEM
HARDENINGImplement network segmentation to limit outbound connections from FortiSIEM server to only necessary external systems
HARDENINGMonitor FortiSIEM logs for unusual outbound requests to internal or external systems
API: /api/v1/advisories/d5dc481a-f1ca-4e69-9b44-2759a335602a

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Server-Side Request Forgery (SSRF) | CVSS 3.4 - OTPulse