Fortinet / Fortinet Fortios
46 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2022-38380 | An improper access control [CWE-284] vulnerability in FortiOS version 7.2.0 and versions 7.0.0 through 7.0.7 may allow a remote authenticated read-only user to… | MEDIUM | 4.3 | Nov 2, 2022 |
| CVE-2022-35842 | An exposure of sensitive information to an unauthorized actor vulnerabiltiy [CWE-200] in FortiOS SSL-VPN versions 7.2.0, versions 7.0.0 through 7.0.6 and versi… | HIGH | 7.5 | Nov 2, 2022 |
| CVE-2022-30307 | A key management error vulnerability [CWE-320] affecting the RSA SSH host key in FortiOS 7.2.0 and below, 7.0.6 and below, 6.4.9 and below may allow an unauthe… | HIGH | 8.1 | Nov 2, 2022 |
| CVE-2021-44171 | A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiOS version 6.0.0 through 6.0.14, FortiOS version… | CRITICAL | 9.0 | Oct 10, 2022 |
| CVE-2021-43080 | An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiOS version 7.2.0, version 6.4.0 through 6.4.9, version 7.0.0 thro… | MEDIUM | 5.4 | Sep 6, 2022 |
| CVE-2022-29053 | A missing cryptographic steps vulnerability [CWE-325] in the functions that encrypt the keytab files in FortiOS version 7.2.0, 7.0.0 through 7.0.5 and below 7.… | LOW | 3.3 | Sep 6, 2022 |
| CVE-2022-27491 | A improper verification of source of a communication channel in Fortinet FortiOS with IPS engine version 7.201 through 7.214, 7.001 through 7.113, 6.001 throug… | HIGH | 7.5 | Sep 6, 2022 |
| CVE-2022-23442 | An improper access control vulnerability [CWE-284] in FortiOS versions 6.2.0 through 6.2.11, 6.4.0 through 6.4.8 and 7.0.0 through 7.0.5 may allow an authentic… | MEDIUM | 4.3 | Aug 3, 2022 |
| CVE-2022-23438 | An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in FortiOS version 7.0.5 and prior and 6.4.9 and… | MEDIUM | 6.1 | Jul 18, 2022 |
| CVE-2022-22306 | An improper certificate validation vulnerability [CWE-295] in FortiOS 6.0.0 through 6.0.14, 6.2.0 through 6.2.10, 6.4.0 through 6.4.8, 7.0.0 may allow a networ… | MEDIUM | 5.4 | May 24, 2022 |
| CVE-2021-41032 | An improper access control vulnerability [CWE-284] in FortiOS versions 6.4.8 and prior and 7.0.3 and prior may allow an authenticated attacker with a restricte… | MEDIUM | 6.3 | May 4, 2022 |
| CVE-2020-15936 | A improper input validation in Fortinet FortiGate version 6.4.3 and below, version 6.2.5 and below, version 6.0.11 and below, version 5.6.13 and below allows a… | MEDIUM | 4.5 | Mar 1, 2022 |
| CVE-2021-44168 KEV | A download of code without integrity check vulnerability in the "execute restore src-vis" command of FortiOS before 7.0.3 may allow a local authenticated attac… | HIGH | 7.8 | Jan 4, 2022 |
| CVE-2021-36169 | A Hidden Functionality in Fortinet FortiOS 7.x before 7.0.1, FortiOS 6.4.x before 6.4.7 allows attacker to Execute unauthorized code or commands via specific h… | MEDIUM | 6.0 | Dec 13, 2021 |
| CVE-2021-36173 | A heap-based buffer overflow in the firmware signature verification function of FortiOS versions 7.0.1, 7.0.0, 6.4.0 through 6.4.6, 6.2.0 through 6.2.9, and 6.… | HIGH | 8.8 | Dec 8, 2021 |
| CVE-2021-26109 | An integer overflow or wraparound vulnerability in the memory allocator of SSLVPN in FortiOS before 7.0.1 may allow an unauthenticated attacker to corrupt cont… | CRITICAL | 9.8 | Dec 8, 2021 |
| CVE-2021-26108 | A use of hard-coded cryptographic key vulnerability in the SSLVPN of FortiOS before 7.0.1 may allow an attacker to retrieve the key by reverse engineering. | HIGH | 7.5 | Dec 8, 2021 |
| CVE-2021-41024 | A relative path traversal [CWE-23] vulnerabiltiy in FortiOS versions 7.0.0 and 7.0.1 and FortiProxy verison 7.0.0 may allow an unauthenticated, unauthorized at… | HIGH | 7.5 | Dec 8, 2021 |
| CVE-2021-26103 | An insufficient verification of data authenticity vulnerability (CWE-345) in the user interface of FortiProxy verison 2.0.3 and below, 1.2.11 and below and For… | HIGH | 8.8 | Dec 8, 2021 |
| CVE-2021-32600 | An exposure of sensitive information to an unauthorized actor vulnerability in FortiOS CLI 7.0.0, 6.4.0 through 6.4.6, 6.2.0 through 6.2.9, 6.0.x and 5.6.x may… | MEDIUM | 5.0 | Nov 17, 2021 |
| CVE-2021-41019 | An improper validation of certificate with host mismatch [CWE-297] vulnerability in FortiOS versions 6.4.6 and below may allow the connection to a malicious LD… | MEDIUM | 6.5 | Nov 2, 2021 |
| CVE-2021-24018 | A buffer underwrite vulnerability in the firmware verification routine of FortiOS before 7.0.1 may allow an attacker located in the adjacent network to potenti… | HIGH | 8.8 | Aug 4, 2021 |
| CVE-2021-24012 | An improper following of a certificate's chain of trust vulnerability in FortiGate versions 6.4.0 to 6.4.4 may allow an LDAP user to connect to SSLVPN with any… | HIGH | 7.3 | Jun 2, 2021 |
| CVE-2020-15938 | When traffic other than HTTP/S (eg: SSH traffic, etc...) traverses the FortiGate in version below 6.2.5 and below 6.4.2 on port 80/443, it is not redirected to… | HIGH | 7.5 | Mar 4, 2021 |
| CVE-2020-15937 | An improper neutralization of input vulnerability in FortiGate version 6.2.x below 6.2.5 and 6.4.x below 6.4.1 may allow a remote attacker to perform a stored… | MEDIUM | 6.1 | Mar 3, 2021 |
Showing 1 to 25 of 46 CVEs