← Back

Fortinet

fortinet

1,119 CVEs • 247 products

Products (247)

Click to collapse
Toggle
Fortios
fortios
Fortiweb
fortiweb
Fortiproxy
fortiproxy
Fortimanager
fortimanager
Fortianalyzer
fortianalyzer
Forticlient
forticlient
Fortisandbox
fortisandbox
Fortimail
fortimail
Fortiportal
fortiportal
Fortiadc
fortiadc
Fortisoar
fortisoar
Fortinac
fortinac
Fortisiem
fortisiem
Fortipam
fortipam
Fortivoice
fortivoice
Fortiwlm
fortiwlm
Fortiwan
fortiwan
Fortitester
fortitester
Fortiswitch
fortiswitch
Fortiwlc
fortiwlc
Fortinac F
fortinac-f
Fortirecorder
fortirecorder
Fortideceptor
fortideceptor
Fortindr
fortindr
Fortiisolator
fortiisolator
Fortisase
fortisase
Fortiap W2
fortiap-w2
Fortiap
fortiap
Fortiap U
fortiap-u
Fortiedr
fortiedr
Fortiddos F
fortiddos-f
Fortiap S
fortiap-s
Fortiddos
fortiddos
Fortiaiops
fortiaiops
Fortisra
fortisra
Fortigate
fortigate
Fortigate 20c
fortigate-20c
Fortigate 40c
fortigate-40c
Fortigate 50b
fortigate-50b
Fortigate 60c
fortigate-60c
Fortigate 80c
fortigate-80c
Fortiadc 200d
fortiadc-200d
Fortiadc 300e
fortiadc-300e
Fortiadc 400e
fortiadc-400e
Fortiadc 600e
fortiadc-600e
Fortipresence
fortipresence

CVEs (1,119)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Fortinet
1Fortisiem
Nov 21, 2024
Nov 2, 2021
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
A unprotected storage of credentials in Fortinet FortiSIEM Windows Agent version 4.1.4 and below allows an authenticated user to disclosure agent password due to plaintext credential storage in log files
1Fortinet
1Fortisiem
Nov 21, 2024
Nov 2, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
A improper privilege management in Fortinet FortiSIEM Windows Agent version 4.1.4 and below allows attacker to execute privileged code or commands via powershell scripts
1Fortinet
1Fortiweb
Nov 21, 2024
Nov 2, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A uncontrolled resource consumption in Fortinet FortiWeb version 6.4.0, version 6.3.15 and below, 6.2.5 and below allows attacker to cause a denial of service for webserver daemon via crafted HTTP requests
1Fortinet
1Fortiweb
Nov 21, 2024
Nov 2, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A stack-based buffer overflow in Fortinet FortiWeb version 6.4.0, version 6.3.15 and below, 6.2.5 and below allows attacker to execute unauthorized code or commands via crafted HTTP requests
1Fortinet
1Fortiwlm
Nov 21, 2024
Nov 2, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A improper neutralization of special elements used in an OS command ('OS Command Injection') in Fortinet FortiWLM version 8.6.1 and below allows attacker to execute unauthorized code or commands via crafted HTTP requests...Show more
A improper neutralization of special elements used in an OS command ('OS Command Injection') in Fortinet FortiWLM version 8.6.1 and below allows attacker to execute unauthorized code or commands via crafted HTTP requests.Show less
1Fortinet
1Fortiwlm
Nov 21, 2024
Nov 2, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
A improper neutralization of Special Elements used in an SQL Command ('SQL Injection') in Fortinet FortiWLM version 8.6.1 and below allows attacker to disclosure device, users and database information via crafted HTTP re...Show more
A improper neutralization of Special Elements used in an SQL Command ('SQL Injection') in Fortinet FortiWLM version 8.6.1 and below allows attacker to disclosure device, users and database information via crafted HTTP requests.Show less
1Fortinet
1Forticlient
Nov 21, 2024
Nov 2, 2021
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
An improper authorization vulnerability [CWE-285] in FortiClient for Windows versions 7.0.1 and below and 6.4.2 and below may allow a local unprivileged attacker to escalate their privileges to SYSTEM via the named pipe...Show more
An improper authorization vulnerability [CWE-285] in FortiClient for Windows versions 7.0.1 and below and 6.4.2 and below may allow a local unprivileged attacker to escalate their privileges to SYSTEM via the named pipe responsible for Forticlient updates.Show less
1Fortinet
1Fortiportal
Nov 21, 2024
Nov 2, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Multiple uncontrolled resource consumption vulnerabilities in the web interface of FortiPortal before 6.0.6 may allow a single low-privileged user to induce a denial of service via multiple HTTP requests.
1Fortinet
1Fortiportal
Nov 21, 2024
Nov 2, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A memory allocation with excessive size value vulnerability in the license verification function of FortiPortal before 6.0.6 may allow an attacker to perform a denial of service attack via specially crafted license blobs...Show more
A memory allocation with excessive size value vulnerability in the license verification function of FortiPortal before 6.0.6 may allow an attacker to perform a denial of service attack via specially crafted license blobs.Show less
1Fortinet
1Fortiadc
Nov 21, 2024
Nov 2, 2021
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
A cleartext storage of sensitive information in GUI in FortiADC versions 5.4.3 and below, 6.0.0 and below may allow a remote authenticated attacker to retrieve some sensitive information such as users LDAP passwords and...Show more
A cleartext storage of sensitive information in GUI in FortiADC versions 5.4.3 and below, 6.0.0 and below may allow a remote authenticated attacker to retrieve some sensitive information such as users LDAP passwords and RADIUS shared secret by deobfuscating the passwords entry fields.Show less
1Fortinet
1Fortios
Nov 21, 2024
Nov 2, 2021
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
An improper validation of certificate with host mismatch [CWE-297] vulnerability in FortiOS versions 6.4.6 and below may allow the connection to a malicious LDAP server via options in GUI, leading to disclosure of sensit...Show more
An improper validation of certificate with host mismatch [CWE-297] vulnerability in FortiOS versions 6.4.6 and below may allow the connection to a malicious LDAP server via options in GUI, leading to disclosure of sensitive information, such as AD credentials.Show less
1Fortinet
1Fortiportal
Nov 21, 2024
Nov 2, 2021
N/A· v4
3.1 LOW· v3
3.5 LOW· v2
A concurrent execution using shared resource with improper Synchronization vulnerability ('Race Condition') in the customer database interface of FortiPortal before 6.0.6 may allow an authenticated, low-privilege user to...Show more
A concurrent execution using shared resource with improper Synchronization vulnerability ('Race Condition') in the customer database interface of FortiPortal before 6.0.6 may allow an authenticated, low-privilege user to bring the underlying database data into an inconsistent state via specific coordination of web requests.Show less
1Fortinet
1Fortiportal
Nov 21, 2024
Nov 2, 2021
N/A· v4
8.1 HIGH· v3
6.4 MEDIUM· v2
An improper restriction of XML external entity reference vulnerability in the parser of XML responses of FortiPortal before 6.0.6 may allow an attacker who controls the producer of XML reports consumed by FortiPortal to...Show more
An improper restriction of XML external entity reference vulnerability in the parser of XML responses of FortiPortal before 6.0.6 may allow an attacker who controls the producer of XML reports consumed by FortiPortal to trigger a denial of service or read arbitrary files from the underlying file system by means of specifically crafted XML documents.Show less
1Fortinet
1Fortiportal
Nov 21, 2024
Nov 2, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Multiple uncontrolled resource consumption vulnerabilities in the web interface of FortiPortal before 6.0.6 may allow a single low-privileged user to induce a denial of service via multiple HTTP requests.
1Fortinet
1Fortimanager
Nov 21, 2024
Nov 2, 2021
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
An improper access control vulnerability [CWE-284] in FortiManager versions 6.4.4 and 6.4.5 may allow an authenticated attacker with a restricted user profile to modify the VPN tunnel status of other VDOMs using VPN Mana...Show more
An improper access control vulnerability [CWE-284] in FortiManager versions 6.4.4 and 6.4.5 may allow an authenticated attacker with a restricted user profile to modify the VPN tunnel status of other VDOMs using VPN Manager.Show less
1Fortinet
1Forticlient Enterprise Management Server
Nov 21, 2024
Nov 2, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
An improper neutralization of input vulnerability [CWE-79] in FortiClientEMS versions 6.4.1 and below and 6.2.9 and below may allow a remote authenticated attacker to inject malicious script/tags via the name parameter o...Show more
An improper neutralization of input vulnerability [CWE-79] in FortiClientEMS versions 6.4.1 and below and 6.2.9 and below may allow a remote authenticated attacker to inject malicious script/tags via the name parameter of various sections of the server.Show less
1Fortinet
1Fortianalyzer
Nov 21, 2024
Nov 2, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiAnalyzer version 6.0.6 and below, version 6.4.4 allows attacker to execute unauthorized code or commands via specifi...Show more
A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiAnalyzer version 6.0.6 and below, version 6.4.4 allows attacker to execute unauthorized code or commands via specifically crafted requests to the web GUI.Show less
1Fortinet
1Fortisdnconnector
Nov 21, 2024
Oct 6, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
A insufficiently protected credentials in Fortinet FortiSDNConnector version 1.1.7 and below allows attacker to disclose third-party devices credential information via configuration page lookup.
1Fortinet
1Fortiweb
Nov 21, 2024
Oct 6, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
An improper neutralization of input vulnerability [CWE-79] in FortiWebManager versions 6.2.3 and below, 6.0.2 and below may allow a remote authenticated attacker to inject malicious script/tags via the name/description/c...Show more
An improper neutralization of input vulnerability [CWE-79] in FortiWebManager versions 6.2.3 and below, 6.0.2 and below may allow a remote authenticated attacker to inject malicious script/tags via the name/description/comments parameter of various sections of the device.Show less
1Fortinet
2Fortianalyzer
Fortimanager
Nov 21, 2024
Oct 6, 2021
N/A· v4
3.2 LOW· v3
2.1 LOW· v2
An information disclosure vulnerability [CWE-200] in FortiAnalyzerVM and FortiManagerVM versions 7.0.0 and 6.4.6 and below may allow an authenticated attacker to read the FortiCloud credentials which were used to activat...Show more
An information disclosure vulnerability [CWE-200] in FortiAnalyzerVM and FortiManagerVM versions 7.0.0 and 6.4.6 and below may allow an authenticated attacker to read the FortiCloud credentials which were used to activate the trial license in cleartext.Show less