imPC@ndo EN

Vulnerabilità Fortinet

1134 CVE

CVE-2018-1360
Alta 8.1

A cleartext transmission of sensitive information vulnerability in Fortinet FortiManager 5.2.0 through 5.2.7, 5.4.0 and 5.4.1 may allow an unauthenticated attacker in a man in the middle position to retrieve the admin password via intercepting REST API JSON re…

fortinet fortimanager
0.01EPSS
CVE-2020-12820
Media 5.4

Under non-default configuration, a stack-based buffer overflow in FortiOS version 6.0.10 and below, version 5.6.12 and below may allow a remote attacker authenticated to the SSL VPN to crash the FortiClient NAC daemon (fcnacd) and potentially execute arbitrary…

fortinet fortios
0.01EPSS
CVE-2019-16157
Media 6.5

An information exposure vulnerability in Fortinet FortiWeb 6.2.0 CLI and earlier may allow an authenticated user to view sensitive information being logged via diagnose debug commands.

fortinet fortiweb
0.01EPSS
CVE-2024-31487
Media 5.9

A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.4, FortiSandbox 4.2.1 through 4.2.6, FortiSandbox 4.0 all versions, FortiSandbox 3.2 all versions, FortiSandbox 3.1 all ve…

fortinet fortisandbox
0.01EPSS
CVE-2020-9288
Media 5.4

An improper neutralization of input vulnerability in FortiWLC 8.5.1 allows a remote authenticated attacker to perform a stored cross site scripting attack (XSS) via the ESS profile or the Radius Profile.

fortinet fortiwlc
0.01EPSS
CVE-2020-6640
Media 5.4

An improper neutralization of input vulnerability in the Admin Profile of FortiAnalyzer may allow a remote authenticated attacker to perform a stored cross site scripting attack (XSS) via the Description Area.

fortinet fortianalyzer
0.01EPSS
CVE-2020-12815
Media 5.4

An improper neutralization of input vulnerability in FortiTester before 3.9.0 may allow a remote authenticated attacker to inject script related HTML tags via IPv4/IPv6 address fields.

fortinet fortianalyzer · fortinet fortitester
0.01EPSS
CVE-2023-40720
Alta 7.1

An authorization bypass through user-controlled key vulnerability [CWE-639] in FortiVoiceEntreprise version 7.0.0 through 7.0.1 and before 6.4.8 allows an authenticated attacker to read the SIP configuration of other users via crafted HTTP or HTTPS requests.

fortinet fortivoice
0.01EPSS
CVE-2023-44251
Alta 8.3

** UNSUPPORTED WHEN ASSIGNED **A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability [CWE-22] in Fortinet FortiWAN version 5.2.0 through 5.2.1 and version 5.1.1. through 5.1.2 may allow an authenticated attacker to read…

fortinet fortiwan
0.01EPSS
CVE-2020-6643
Media 5.4

An improper neutralization of input vulnerability in the URL Description in Fortinet FortiIsolator version 1.2.2 allows a remote authenticated attacker to perform a cross site scripting attack (XSS).

fortinet fortiisolator
0.01EPSS
CVE-2023-33306
Media 6.5

A null pointer dereference in Fortinet FortiOS before 7.2.5, before 7.0.11 and before 6.4.13, FortiProxy before 7.2.4 and before 7.0.10 allows attacker to denial of sslvpn service via specifically crafted request in bookmark parameter.

fortinet fortios · fortinet fortiproxy
0.01EPSS
CVE-2024-32117
Media 4.9

An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in Fortinet FortiManager version 7.4.0 through 7.4.2 and below 7.2.5, FortiAnalyzer version 7.4.0 through 7.4.2 and below 7.2.5 & FortiAnalyzer-BigData ver…

fortinet fortianalyzer · fortinet fortianalyzer_big_data · fortinet fortimanager
0.01EPSS
CVE-2023-36556
Alta 8.8

An incorrect authorization vulnerability [CWE-863] in FortiMail webmail version 7.2.0 through 7.2.2, version 7.0.0 through 7.0.5 and below 6.4.7 allows an authenticated attacker to login on other users accounts from the same web domain via crafted HTTP or HTTP…

fortinet fortimail
0.01EPSS
CVE-2024-31491
Alta 8.8

A client-side enforcement of server-side security vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.4, FortiSandbox 4.2.1 through 4.2.6 allows attacker to execute unauthorized code or commands via HTTP requests.

fortinet fortisandbox
0.01EPSS
CVE-2023-23775
Media 6.5

Multiple improper neutralization of special elements used in SQL commands ('SQL Injection') vulnerabilities [CWE-89] in FortiSOAR 7.2.0 and before 7.0.3 may allow an authenticated attacker to execute unauthorized code or commands via specifically crafted strin…

fortinet fortisoar
0.01EPSS
CVE-2019-5588
Media 6.1

A reflected Cross-Site-Scripting (XSS) vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4 under SSL VPN web portal may allow an attacker to execute unauthorized malicious script code via the "err" parameter of the error process HTTP requests.

fortinet fortios
0.01EPSS
CVE-2019-5586
Media 6.1

A reflected Cross-Site-Scripting (XSS) vulnerability in Fortinet FortiOS 5.2.0 to 5.6.10, 6.0.0 to 6.0.4 under SSL VPN web portal may allow an attacker to execute unauthorized malicious script code via the "param" parameter of the error process HTTP requests.

fortinet fortios
0.01EPSS
CVE-2023-41841
Alta 8.1

An improper authorization vulnerability in Fortinet FortiOS 7.0.0 - 7.0.11 and 7.2.0 - 7.2.4 allows an attacker belonging to the prof-admin profile to perform elevated actions.

fortinet fortios
0.01EPSS
CVE-2023-33305
Media 4.9

A loop with unreachable exit condition ('infinite loop') in Fortinet FortiOS version 7.2.0 through 7.2.4, FortiOS version 7.0.0 through 7.0.10, FortiOS 6.4 all versions, FortiOS 6.2 all versions, FortiOS 6.0 all versions, FortiProxy version 7.2.0 through 7.2.…

fortinet fortios · fortinet fortiproxy · fortinet fortiweb
0.01EPSS
CVE-2023-45581
Alta 8.8

An improper privilege management vulnerability [CWE-269] in Fortinet FortiClientEMS version 7.2.0 through 7.2.2 and before 7.0.10 allows an Site administrator with Super Admin privileges to perform global administrative operations affecting other sites via cra…

fortinet forticlient_enterprise_management_server
0.01EPSS
CVE-2021-41015
Media 6.1

A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below allows attacker to execute unauthorized code or commands via crafted HTTP requests to SAML login handler

fortinet fortiweb
0.01EPSS
CVE-2024-35275
Media 6.6

A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiAnalyzer version 7.4.0 through 7.4.2, FortiManager version 7.4.0 through 7.4.2 allows attacker to escalation of privilege via specially crafted http request…

fortinet fortianalyzer · fortinet fortianalyzer_cloud · fortinet fortimanager · fortinet fortimanager_cloud
0.01EPSS
CVE-2022-45861
Media 6.5

An access of uninitialized pointer vulnerability [CWE-824] in the SSL VPN portal of Fortinet FortiOS version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.9 and before 6.4.11 and FortiProxy version 7.2.0 through 7.2.1, version 7.0.0 through 7.0.7 and before 2…

fortinet fortios · fortinet fortiproxy
0.01EPSS
CVE-2021-36193
Media 6.7

Multiple stack-based buffer overflows in the command line interpreter of FortiWeb before 6.4.2 may allow an authenticated attacker to achieve arbitrary code execution via specially crafted commands.

fortinet fortiweb
0.01EPSS
CVE-2021-26098
Media 5.3

An instance of small space of random values in the RPC API of FortiSandbox before 4.0.0 may allow an attacker in possession of a few information pieces about the state of the device to possibly predict valid session IDs.

fortinet fortisandbox
0.01EPSS