← Back

Fortinet

fortinet

1,119 CVEs • 247 products

Products (247)

Click to collapse
Toggle
Fortios
fortios
Fortiweb
fortiweb
Fortiproxy
fortiproxy
Fortimanager
fortimanager
Fortianalyzer
fortianalyzer
Forticlient
forticlient
Fortisandbox
fortisandbox
Fortimail
fortimail
Fortiportal
fortiportal
Fortiadc
fortiadc
Fortisoar
fortisoar
Fortinac
fortinac
Fortisiem
fortisiem
Fortipam
fortipam
Fortivoice
fortivoice
Fortiwlm
fortiwlm
Fortiwan
fortiwan
Fortitester
fortitester
Fortiswitch
fortiswitch
Fortiwlc
fortiwlc
Fortinac F
fortinac-f
Fortirecorder
fortirecorder
Fortideceptor
fortideceptor
Fortindr
fortindr
Fortiisolator
fortiisolator
Fortisase
fortisase
Fortiap W2
fortiap-w2
Fortiap
fortiap
Fortiap U
fortiap-u
Fortiedr
fortiedr
Fortiddos F
fortiddos-f
Fortiap S
fortiap-s
Fortiddos
fortiddos
Fortiaiops
fortiaiops
Fortisra
fortisra
Fortigate
fortigate
Fortigate 20c
fortigate-20c
Fortigate 40c
fortigate-40c
Fortigate 50b
fortigate-50b
Fortigate 60c
fortigate-60c
Fortigate 80c
fortigate-80c
Fortiadc 200d
fortiadc-200d
Fortiadc 300e
fortiadc-300e
Fortiadc 400e
fortiadc-400e
Fortiadc 600e
fortiadc-600e
Fortipresence
fortipresence

CVEs (1,119)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Fortinet
1Fortisandbox
Nov 21, 2024
Aug 4, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
An improper neutralization of special elements used in an OS Command vulnerability in FortiSandbox 3.2.0 through 3.2.2, 3.1.0 through 3.1.4, and 3.0.0 through 3.0.6 may allow an authenticated attacker with access to the...Show more
An improper neutralization of special elements used in an OS Command vulnerability in FortiSandbox 3.2.0 through 3.2.2, 3.1.0 through 3.1.4, and 3.0.0 through 3.0.6 may allow an authenticated attacker with access to the web GUI to execute unauthorized code or commands via specifically crafted HTTP requests.Show less
1Fortinet
1Fortisandbox
Nov 21, 2024
Aug 4, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Instances of SQL Injection vulnerabilities in the checksum search and MTA-quarantine modules of FortiSandbox 3.2.0 through 3.2.2, and 3.1.0 through 3.1.4 may allow an authenticated attacker to execute unauthorized code o...Show more
Instances of SQL Injection vulnerabilities in the checksum search and MTA-quarantine modules of FortiSandbox 3.2.0 through 3.2.2, and 3.1.0 through 3.1.4 may allow an authenticated attacker to execute unauthorized code on the underlying SQL interpreter via specifically crafted HTTP requests.Show less
1Fortinet
1Fortiportal
Nov 21, 2024
Aug 4, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
A Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Fortinet FortiPortal 6.x before 6.0.5, FortiPortal 5.3.x before 5.3.6 and any FortiPortal before 6.2.5 allows authenticated attacker to...Show more
A Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Fortinet FortiPortal 6.x before 6.0.5, FortiPortal 5.3.x before 5.3.6 and any FortiPortal before 6.2.5 allows authenticated attacker to disclosure information via crafted GET request with malicious parameter values.Show less
1Fortinet
1Fortios
Nov 21, 2024
Aug 4, 2021
N/A· v4
8.8 HIGH· v3
5.8 MEDIUM· v2
A buffer underwrite vulnerability in the firmware verification routine of FortiOS before 7.0.1 may allow an attacker located in the adjacent network to potentially execute arbitrary code via a specifically crafted firmwa...Show more
A buffer underwrite vulnerability in the firmware verification routine of FortiOS before 7.0.1 may allow an attacker located in the adjacent network to potentially execute arbitrary code via a specifically crafted firmware image.Show less
1Fortinet
1Fortisandbox
Nov 21, 2024
Aug 4, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Improper limitation of a pathname to a restricted directory vulnerabilities in FortiSandbox 3.2.0 through 3.2.2, and 3.1.0 through 3.1.4 may allow an authenticated user to obtain unauthorized access to files and data via...Show more
Improper limitation of a pathname to a restricted directory vulnerabilities in FortiSandbox 3.2.0 through 3.2.2, and 3.1.0 through 3.1.4 may allow an authenticated user to obtain unauthorized access to files and data via specifially crafted web requests.Show less
1Fortinet
1Fortiportal
Nov 21, 2024
Aug 4, 2021
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
An unrestricted file upload vulnerability in the web interface of FortiPortal 6.0.0 through 6.0.4, 5.3.0 through 5.3.5, 5.2.0 through 5.2.5, and 4.2.2 and earlier may allow a low-privileged user to potentially tamper wit...Show more
An unrestricted file upload vulnerability in the web interface of FortiPortal 6.0.0 through 6.0.4, 5.3.0 through 5.3.5, 5.2.0 through 5.2.5, and 4.2.2 and earlier may allow a low-privileged user to potentially tamper with the underlying system's files via the upload of specifically crafted files.Show less
1Fortinet
1Fortiportal
Nov 21, 2024
Aug 4, 2021
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
Multiple improper neutralization of special elements used in an SQL command vulnerabilities in FortiPortal 6.0.0 through 6.0.4, 5.3.0 through 5.3.5, 5.2.0 through 5.2.5, and 4.2.2 and earlier may allow an attacker with r...Show more
Multiple improper neutralization of special elements used in an SQL command vulnerabilities in FortiPortal 6.0.0 through 6.0.4, 5.3.0 through 5.3.5, 5.2.0 through 5.2.5, and 4.2.2 and earlier may allow an attacker with regular user's privileges to execute arbitrary commands on the underlying SQL database via specifically crafted HTTP requests.Show less
1Fortinet
1Fortisandbox
Nov 21, 2024
Aug 4, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An instance of small space of random values in the RPC API of FortiSandbox before 4.0.0 may allow an attacker in possession of a few information pieces about the state of the device to possibly predict valid session IDs.
1Fortinet
1Fortimail
Nov 21, 2024
Jul 20, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
The combination of various cryptographic issues in the session management of FortiMail 6.4.0 through 6.4.4 and 6.2.0 through 6.2.6, including the encryption construction of the session cookie, may allow a remote attacker...Show more
The combination of various cryptographic issues in the session management of FortiMail 6.4.0 through 6.4.4 and 6.2.0 through 6.2.6, including the encryption construction of the session cookie, may allow a remote attacker already in possession of a cookie to possibly reveal and alter or forge its content, thereby escalating privileges.Show less
1Fortinet
2Fortianalyzer
Fortimanager
Nov 21, 2024
Jul 20, 2021
N/A· v4
4.4 MEDIUM· v3
2.1 LOW· v2
A buffer overflow vulnerability in FortiAnalyzer CLI 6.4.5 and below, 6.2.7 and below, 6.0.x and FortiManager CLI 6.4.5 and below, 6.2.7 and below, 6.0.x may allow an authenticated, local attacker to perform a Denial of...Show more
A buffer overflow vulnerability in FortiAnalyzer CLI 6.4.5 and below, 6.2.7 and below, 6.0.x and FortiManager CLI 6.4.5 and below, 6.2.7 and below, 6.0.x may allow an authenticated, local attacker to perform a Denial of Service attack by running the `diagnose system geoip-city` command with a large ip value.Show less
1Fortinet
1Fortisandbox
Nov 21, 2024
Jul 20, 2021
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
An instance of improper neutralization of special elements in the sniffer module of FortiSandbox before 3.2.2 may allow an authenticated administrator to execute commands on the underlying system's shell via altering the...Show more
An instance of improper neutralization of special elements in the sniffer module of FortiSandbox before 3.2.2 may allow an authenticated administrator to execute commands on the underlying system's shell via altering the content of its configuration file.Show less
1Fortinet
1Fortinet Single Sign On
Nov 21, 2024
Jul 12, 2021
N/A· v4
9.6 CRITICAL· v3
5.8 MEDIUM· v2
An improper authentication vulnerability in FSSO Collector version 5.0.295 and below may allow an unauthenticated user to bypass a FSSO firewall policy and access the protected network via sending specifically crafted UD...Show more
An improper authentication vulnerability in FSSO Collector version 5.0.295 and below may allow an unauthenticated user to bypass a FSSO firewall policy and access the protected network via sending specifically crafted UDP login notification packets.Show less
1Fortinet
1Fortimail
Nov 21, 2024
Jul 12, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
An improper neutralization of special elements used in an OS Command vulnerability in the administrative interface of FortiMail before 6.4.4 may allow an authenticated attacker to execute unauthorized commands via specif...Show more
An improper neutralization of special elements used in an OS Command vulnerability in the administrative interface of FortiMail before 6.4.4 may allow an authenticated attacker to execute unauthorized commands via specifically crafted HTTP requests.Show less
1Fortinet
1Fortimail
Nov 21, 2024
Jul 12, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Multiple Path traversal vulnerabilities in the Webmail of FortiMail before 6.4.4 may allow a regular user to obtain unauthorized access to files and data via specifically crafted web requests.
1Fortinet
1Fortimail
Nov 21, 2024
Jul 12, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A missing release of memory after its effective lifetime vulnerability in the Webmail of FortiMail 6.4.0 through 6.4.4 and 6.2.0 through 6.2.6 may allow an unauthenticated remote attacker to exhaust available memory via...Show more
A missing release of memory after its effective lifetime vulnerability in the Webmail of FortiMail 6.4.0 through 6.4.4 and 6.2.0 through 6.2.6 may allow an unauthenticated remote attacker to exhaust available memory via specifically crafted login requests.Show less
1Fortinet
1Forticlient
Nov 21, 2024
Jul 12, 2021
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
An improper symlink following in FortiClient for Mac 6.4.3 and below may allow an non-privileged user to execute arbitrary privileged shell commands during installation phase.
1Fortinet
1Fortimail
Nov 21, 2024
Jul 12, 2021
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
Missing cryptographic steps in the Identity-Based Encryption service of FortiMail before 7.0.0 may allow an attacker who comes in possession of the encrypted master keys to compromise their confidentiality by observing a...Show more
Missing cryptographic steps in the Identity-Based Encryption service of FortiMail before 7.0.0 may allow an attacker who comes in possession of the encrypted master keys to compromise their confidentiality by observing a few invariant properties of the ciphertext.Show less
1Fortinet
3Fortiap
Fortiap SFortiap W2
Nov 21, 2024
Jul 9, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
An improper neutralization of special elements used in an OS Command vulnerability in FortiAP's console 6.4.1 through 6.4.5 and 6.2.4 through 6.2.5 may allow an authenticated attacker to execute unauthorized commands by...Show more
An improper neutralization of special elements used in an OS Command vulnerability in FortiAP's console 6.4.1 through 6.4.5 and 6.2.4 through 6.2.5 may allow an authenticated attacker to execute unauthorized commands by running the kdbg CLI command with specifically crafted arguments.Show less
1Fortinet
1Fortimail
Nov 21, 2024
Jul 9, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A missing cryptographic step in the Identity-Based Encryption service of FortiMail before 7.0.0 may allow an unauthenticated attacker who intercepts the encrypted messages to manipulate them in such a way that makes the...Show more
A missing cryptographic step in the Identity-Based Encryption service of FortiMail before 7.0.0 may allow an unauthenticated attacker who intercepts the encrypted messages to manipulate them in such a way that makes the tampering and the recovery of the plaintexts possible.Show less
1Fortinet
1Fortimail
Nov 21, 2024
Jul 9, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A missing cryptographic step in the implementation of the hash digest algorithm in FortiMail 6.4.0 through 6.4.4, and 6.2.0 through 6.2.7 may allow an unauthenticated attacker to tamper with signed URLs by appending furt...Show more
A missing cryptographic step in the implementation of the hash digest algorithm in FortiMail 6.4.0 through 6.4.4, and 6.2.0 through 6.2.7 may allow an unauthenticated attacker to tamper with signed URLs by appending further data which allows bypass of signature verification.Show less