← Back

Fortinet

fortinet

1,119 CVEs • 247 products

Products (247)

Click to collapse
Toggle
Fortios
fortios
Fortiweb
fortiweb
Fortiproxy
fortiproxy
Fortimanager
fortimanager
Fortianalyzer
fortianalyzer
Forticlient
forticlient
Fortisandbox
fortisandbox
Fortimail
fortimail
Fortiportal
fortiportal
Fortiadc
fortiadc
Fortisoar
fortisoar
Fortinac
fortinac
Fortisiem
fortisiem
Fortipam
fortipam
Fortivoice
fortivoice
Fortiwlm
fortiwlm
Fortiwan
fortiwan
Fortitester
fortitester
Fortiswitch
fortiswitch
Fortiwlc
fortiwlc
Fortinac F
fortinac-f
Fortirecorder
fortirecorder
Fortideceptor
fortideceptor
Fortindr
fortindr
Fortiisolator
fortiisolator
Fortisase
fortisase
Fortiap W2
fortiap-w2
Fortiap
fortiap
Fortiap U
fortiap-u
Fortiedr
fortiedr
Fortiddos F
fortiddos-f
Fortiap S
fortiap-s
Fortiddos
fortiddos
Fortiaiops
fortiaiops
Fortisra
fortisra
Fortigate
fortigate
Fortigate 20c
fortigate-20c
Fortigate 40c
fortigate-40c
Fortigate 50b
fortigate-50b
Fortigate 60c
fortigate-60c
Fortigate 80c
fortigate-80c
Fortiadc 200d
fortiadc-200d
Fortiadc 300e
fortiadc-300e
Fortiadc 400e
fortiadc-400e
Fortiadc 600e
fortiadc-600e
Fortipresence
fortipresence

CVEs (1,119)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Fortinet
1Fortirecorder
Jan 31, 2025
Jan 14, 2025
N/A· v4
6.0 MEDIUM· v3
N/A· v2
A improper limitation of a pathname to a restricted directory ('path traversal') [CWE-23] in Fortinet FortiRecorder version 7.2.0 through 7.2.1 and before 7.0.4 allows a privileged attacker to delete files from the under...Show more
A improper limitation of a pathname to a restricted directory ('path traversal') [CWE-23] in Fortinet FortiRecorder version 7.2.0 through 7.2.1 and before 7.0.4 allows a privileged attacker to delete files from the underlying filesystem via crafted CLI requests.Show less
1Fortinet
1Fortios
Jan 31, 2025
Jan 14, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
An Out-of-bounds Read vulnerability [CWE-125] in FortiOS version 7.6.0, version 7.4.4 and below, version 7.2.9 and below and FortiSASE FortiOS tenant version 24.3.b IPsec IKE service may allow an unauthenticated remote a...Show more
An Out-of-bounds Read vulnerability [CWE-125] in FortiOS version 7.6.0, version 7.4.4 and below, version 7.2.9 and below and FortiSASE FortiOS tenant version 24.3.b IPsec IKE service may allow an unauthenticated remote attacker to trigger memory consumption leading to Denial of Service via crafted requests.Show less
1Fortinet
1Fortios
Jan 31, 2025
Jan 14, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
An Integer Overflow or Wraparound vulnerability [CWE-190] in version 7.4.4 and below, version 7.2.10 and below; FortiSASE version 23.4.b FortiOS tenant IPsec IKE service may allow an authenticated attacker to crash the I...Show more
An Integer Overflow or Wraparound vulnerability [CWE-190] in version 7.4.4 and below, version 7.2.10 and below; FortiSASE version 23.4.b FortiOS tenant IPsec IKE service may allow an authenticated attacker to crash the IPsec tunnel via crafted requests, resulting in potential denial of service.Show less
1Fortinet
1Fortios
Jan 31, 2025
Jan 14, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
An allocation of resources without limits or throttling vulnerability [CWE-770] in FortiOS versions 7.4.0 through 7.4.4, versions 7.2.0 through 7.2.8, versions 7.0.0 through 7.0.15, and versions 6.4.0 through 6.4.15 may...Show more
An allocation of resources without limits or throttling vulnerability [CWE-770] in FortiOS versions 7.4.0 through 7.4.4, versions 7.2.0 through 7.2.8, versions 7.0.0 through 7.0.15, and versions 6.4.0 through 6.4.15 may allow an unauthenticated remote user to consume all system memory via multiple large file uploads.Show less
1Fortinet
1Fortisiem
Jul 16, 2025
Jan 14, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
A allocation of resources without limits or throttling in Fortinet FortiSIEM 5.3 all versions, 5.4 all versions, 6.x all versions, 7.0 all versions, and 7.1.0 through 7.1.5 may allow an attacker to deny valid TLS traffic...Show more
A allocation of resources without limits or throttling in Fortinet FortiSIEM 5.3 all versions, 5.4 all versions, 6.x all versions, 7.0 all versions, and 7.1.0 through 7.1.5 may allow an attacker to deny valid TLS traffic via consuming all allotted connections.Show less
1Fortinet
1Fortios
Jul 22, 2025
Jan 14, 2025
N/A· v4
5.3 MEDIUM· v3
N/A· v2
An allocation of resources without limits or throttling [CWE-770] vulnerability in FortiOS versions 7.6.0, versions 7.4.4 through 7.4.0, 7.2 all versions, 7.0 all versions, 6.4 all versions may allow a remote unauthentic...Show more
An allocation of resources without limits or throttling [CWE-770] vulnerability in FortiOS versions 7.6.0, versions 7.4.4 through 7.4.0, 7.2 all versions, 7.0 all versions, 6.4 all versions may allow a remote unauthenticated attacker to prevent access to the GUI via specially crafted requests directed at specific endpoints.Show less
1Fortinet
1Fortios
Jan 31, 2025
Jan 14, 2025
N/A· v4
3.7 LOW· v3
N/A· v2
An insertion of sensitive information into sent data vulnerability [CWE-201] in FortiOS 7.6.0, 7.4.0 through 7.4.4 may allow an attacker in a man-in-the-middle position to retrieve the RADIUS accounting server shared sec...Show more
An insertion of sensitive information into sent data vulnerability [CWE-201] in FortiOS 7.6.0, 7.4.0 through 7.4.4 may allow an attacker in a man-in-the-middle position to retrieve the RADIUS accounting server shared secret via intercepting accounting-requests.Show less
1Fortinet
1Fortirecorder
Jan 31, 2025
Jan 14, 2025
N/A· v4
4.9 MEDIUM· v3
N/A· v2
A relative path traversal in Fortinet FortiRecorder [CWE-23] version 7.2.0 through 7.2.1 and before 7.0.4 allows a privileged attacker to read files from the underlying filesystem via crafted HTTP or HTTPs requests.
1Fortinet
1Fortideceptor
Feb 4, 2026
Jan 14, 2025
N/A· v4
4.3 MEDIUM· v3
N/A· v2
An Improper Access Control vulnerability [CWE-284] vulnerability in Fortinet FortiDeceptor 6.0.0, FortiDeceptor 5.3 all versions, FortiDeceptor 5.2 all versions, FortiDeceptor 5.1 all versions, FortiDeceptor 5.0 all vers...Show more
An Improper Access Control vulnerability [CWE-284] vulnerability in Fortinet FortiDeceptor 6.0.0, FortiDeceptor 5.3 all versions, FortiDeceptor 5.2 all versions, FortiDeceptor 5.1 all versions, FortiDeceptor 5.0 all versions may allow an authenticated attacker with none privileges to perform operations on the central management appliance via crafted requests.Show less
1Fortinet
1Fortivoice
Jan 31, 2025
Jan 14, 2025
N/A· v4
6.7 MEDIUM· v3
N/A· v2
An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiVoice version 7.0.0 through 7.0.4 and before 6.4.9 allows an authenticated privileged...Show more
An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiVoice version 7.0.0 through 7.0.4 and before 6.4.9 allows an authenticated privileged attacker to execute unauthorized code or commands via crafted CLI requests.Show less
1Fortinet
2Fortianalyzer
Fortimanager
Jan 31, 2025
Jan 14, 2025
N/A· v4
7.2 HIGH· v3
N/A· v2
An improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiManager, FortiAnalyzer 7.4.0 through 7.4.3 and 7.2.0 through 7.2.5 and 7.0.2 through 7.0.12 and 6.2.10 through 6.2.13 all...Show more
An improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiManager, FortiAnalyzer 7.4.0 through 7.4.3 and 7.2.0 through 7.2.5 and 7.0.2 through 7.0.12 and 6.2.10 through 6.2.13 allows attacker to execute unauthorized code or commands via crafted HTTP or HTTPS requests.Show less
1Fortinet
2Forticlientems
Fortisoar
Jan 31, 2025
Jan 14, 2025
N/A· v4
5.3 MEDIUM· v3
N/A· v2
An observable response discrepancy vulnerability [CWE-204] in FortiClientEMS 7.4.0, 7.2.0 through 7.2.4, 7.0 all versions, and FortiSOAR 7.5.0, 7.4.0 through 7.4.4, 7.3.0 through 7.3.2, 7.2 all versions, 7.0 all versions...Show more
An observable response discrepancy vulnerability [CWE-204] in FortiClientEMS 7.4.0, 7.2.0 through 7.2.4, 7.0 all versions, and FortiSOAR 7.5.0, 7.4.0 through 7.4.4, 7.3.0 through 7.3.2, 7.2 all versions, 7.0 all versions, 6.4 all versions may allow an unauthenticated attacker to enumerate valid users via observing login request responses.Show less
1Fortinet
2Forticlientems
Forticlientems Cloud
Jan 31, 2025
Jan 14, 2025
N/A· v4
5.3 MEDIUM· v3
N/A· v2
An improper verification of source of a communication channel vulnerability [CWE-940] in FortiClientEMS 7.4.0, 7.2.0 through 7.2.4, 7.0 all versions, 6.4 all versions may allow a remote attacker to bypass the trusted hos...Show more
An improper verification of source of a communication channel vulnerability [CWE-940] in FortiClientEMS 7.4.0, 7.2.0 through 7.2.4, 7.0 all versions, 6.4 all versions may allow a remote attacker to bypass the trusted host feature via session connection.Show less
1Fortinet
1Fortios
Jul 22, 2025
Jan 14, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
An out-of-bounds read vulnerability [CWE-125] in FortiOS SSLVPN web portal versions 7.4.0 through 7.4.4, versions 7.2.0 through 7.2.8, 7.0 all verisons, and 6.4 all versions may allow an authenticated attacker to perform...Show more
An out-of-bounds read vulnerability [CWE-125] in FortiOS SSLVPN web portal versions 7.4.0 through 7.4.4, versions 7.2.0 through 7.2.8, 7.0 all verisons, and 6.4 all versions may allow an authenticated attacker to perform a denial of service on the SSLVPN web portal via a specially crafted URL.Show less
1Fortinet
1Fortiportal
Jan 31, 2025
Jan 14, 2025
N/A· v4
4.3 MEDIUM· v3
N/A· v2
A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiPortal versions 7.2.4 through 7.2.0 and 7.0.0 through 7.2.8 may allow an authenticated attacker to view the SQL quer...Show more
A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiPortal versions 7.2.4 through 7.2.0 and 7.0.0 through 7.2.8 may allow an authenticated attacker to view the SQL query being run server-side when submitting an HTTP request, via including special elements in said request.Show less
1Fortinet
2Fortimanager
Fortimanager Cloud
Jan 31, 2025
Jan 14, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
A missing authentication for critical function in Fortinet FortiPortal version 6.0.0 through 6.0.15, FortiManager version 7.4.0 through 7.4.2, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14 allows attack...Show more
A missing authentication for critical function in Fortinet FortiPortal version 6.0.0 through 6.0.15, FortiManager version 7.4.0 through 7.4.2, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14 allows attacker to access to the configuration of the managed devices by sending specifically crafted packetsShow less
1Fortinet
4Fortianalyzer
Fortianalyzer CloudFortimanager+1 more
Jan 31, 2025
Jan 14, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A stack-based buffer overflow in Fortinet FortiAnalyzer versions 7.4.0 through 7.4.3, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14, FortiManager versions 7.4.0 through 7.4.3, 7.2.0 through 7.2.5, 7.0.0...Show more
A stack-based buffer overflow in Fortinet FortiAnalyzer versions 7.4.0 through 7.4.3, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14, FortiManager versions 7.4.0 through 7.4.3, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14, FortiManager Cloud versions 7.4.1 through 7.4.3, 7.2.1 through 7.2.5, 7.0.1 through 7.0.11, 6.4.1 through 6.4.7, FortiAnalyzer Cloud versions 7.4.1 through 7.4.3, 7.2.1 through 7.2.5, 7.0.1 through 7.0.11, 6.4.1 through 6.4.7 allows attacker to execute unauthorized code or commands via specially crafted packets.Show less
1Fortinet
4Fortianalyzer
Fortianalyzer CloudFortimanager+1 more
Jan 31, 2025
Jan 14, 2025
N/A· v4
8.8 HIGH· v3
N/A· v2
A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiAnalyzer version 7.4.0 through 7.4.2, FortiManager version 7.4.0 through 7.4.2 allows attacker to escalation of priv...Show more
A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiAnalyzer version 7.4.0 through 7.4.2, FortiManager version 7.4.0 through 7.4.2 allows attacker to escalation of privilege via specially crafted http requests.Show less
1Fortinet
4Fortianalyzer
Fortianalyzer CloudFortimanager+1 more
Jan 31, 2025
Jan 14, 2025
N/A· v4
8.8 HIGH· v3
N/A· v2
A out-of-bounds write in Fortinet FortiManager version 7.4.0 through 7.4.2, FortiAnalyzer version 7.4.0 through 7.4.2 allows attacker to escalation of privilege via specially crafted http requests.
1Fortinet
4Fortianalyzer
Fortianalyzer CloudFortimanager+1 more
Jan 31, 2025
Jan 14, 2025
N/A· v4
7.8 HIGH· v3
N/A· v2
A improper privilege management in Fortinet FortiManager version 7.4.0 through 7.4.3, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14, FortiAnalyzer version 7.4.0 through 7.4.2, 7.2.0 through 7.2.5, 7.0.0...Show more
A improper privilege management in Fortinet FortiManager version 7.4.0 through 7.4.3, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14, FortiAnalyzer version 7.4.0 through 7.4.2, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14 allows attacker to escalation of privilege via specific shell commandsShow less