imPC@ndo EN

Vulnerabilità Fortinet

1134 CVE

CVE-2019-6693
Ransomware Media 6.5

Use of a hard-coded cryptographic key to cipher sensitive data in FortiOS configuration backup file may allow an attacker with access to the backup file to decipher the sensitive data, via knowledge of the hard-coded key. The aforementioned sensitive data incl…

fortinet fortios
0.06EPSS
CVE-2025-24472
Ransomware Alta 8.1

An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS 7.0.0 through 7.0.16 and FortiProxy 7.2.0 through 7.2.12, 7.0.0 through 7.0.19 may allow a remote unauthenticated attacker with prior knowledge of upstream an…

fortinet fortios · fortinet fortiproxy
0.04EPSS
CVE-2025-68686
Sfruttata Media 5.9

An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1, FortiOS 7.4.0 through 7.4.6, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions may allow a r…

fortinet fortios
0.01EPSS
CVE-2021-44168
Sfruttata Bassa 3.3

A download of code without integrity check vulnerability in the "execute restore src-vis" command of FortiOS before 7.0.3 may allow a local authenticated attacker to download arbitrary files on the device via specially crafted update packages.

fortinet fortios
0.01EPSS
CVE-2012-1456
Media 4.3

The TAR file parser in AVG Anti-Virus 10.0.0.1190, Quick Heal (aka Cat QuickHeal) 11.00, Comodo Antivirus 7424, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, F-Prot Antivirus 4.6.2.117, Fortinet Antivirus 4.2.254.0, Ikarus Virus Utilities T3 Command Line Scan…

aladdin esafe · avg avg_anti-virus · cat quick_heal · comodo comodo_antivirus · e altri 16
1.00EPSS
CVE-2012-1459
Media 4.3

The TAR file parser in AhnLab V3 Internet Security 2011.01.18.00, Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, avast! Antivirus 4.8.1351.0 and 5.0.677.0, AVG Anti-Virus 10.0.0.1190, Bitdefender 7.2, Quick Heal (aka Cat QuickHeal) 11.00, ClamAV 0.96.4,…

ahnlab v3_internet_security · alwil avast_antivirus · anti-virus vba32 · antiy avl_sdk · e altri 30
1.00EPSS
CVE-2022-39952
Critica 9.8

A external control of file name or path in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.7, 8.8.0 through 8.8.11, 8.7.0 through 8.7.6, 8.6.0 through 8.6.5, 8.5.0 through 8.5.4, 8.3.7 may allow an unauthenticated attacker to execute u…

fortinet fortinac
1.00EPSS
CVE-2012-1446
Media 4.3

The ELF file parser in Quick Heal (aka Cat QuickHeal) 11.00, McAfee Anti-Virus Scanning Engine 5.400.0.1158, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Norman Antivirus 6.06.12, eSafe 7.0.17.0, Kaspersky Anti-Virus 7.0.0.125, McAfee Gateway (fo…

aladdin esafe · antiy avl_sdk · ca etrust_vet_antivirus · cat quick_heal · e altri 10
1.00EPSS
CVE-2012-1443
Media 4.3

The RAR file parser in ClamAV 0.96.4, Rising Antivirus 22.83.00.03, Quick Heal (aka Cat QuickHeal) 11.00, G Data AntiVirus 21, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Command Antivirus 5.2.11.5, Ikarus Virus Utilities T3 Command Line Scanner…

ahnlab v3_internet_security · aladdin esafe · alwil avast_antivirus · anti-virus vba32 · e altri 31
1.00EPSS
CVE-2012-1442
Media 4.3

The ELF file parser in Quick Heal (aka Cat QuickHeal) 11.00, McAfee Anti-Virus Scanning Engine 5.400.0.1158, McAfee Gateway (formerly Webwasher) 2010.1C, eSafe 7.0.17.0, Kaspersky Anti-Virus 7.0.0.125, F-Secure Anti-Virus 9.0.16160.0, Sophos Anti-Virus 4.61.0,…

aladdin esafe · antiy avl_sdk · cat quick_heal · f-secure f-secure_anti-virus · e altri 7
0.99EPSS
CVE-2012-1462
Media 4.3

The ZIP file parser in AhnLab V3 Internet Security 2011.01.18.00, AVG Anti-Virus 10.0.0.1190, Quick Heal (aka Cat QuickHeal) 11.00, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, Fortinet Antivirus 4.2.254.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.…

ahnlab v3_internet_security · aladdin esafe · avg avg_anti-virus · cat quick_heal · e altri 6
0.98EPSS
CVE-2012-1453
Media 4.3

The CAB file parser in Dr.Web 5.0.2.03300, Trend Micro HouseCall 9.120.0.1004, Kaspersky Anti-Virus 7.0.0.125, Sophos Anti-Virus 4.61.0, Trend Micro AntiVirus 9.120.0.1004, McAfee Gateway (formerly Webwasher) 2010.1C, Emsisoft Anti-Malware 5.1.0.1, CA eTrust V…

antiy avl_sdk · ca etrust_vet_antivirus · drweb dr.web_antivirus · emsisoft anti-malware · e altri 10
0.98EPSS
CVE-2012-1420
Media 4.3

The TAR file parser in Quick Heal (aka Cat QuickHeal) 11.00, Command Antivirus 5.2.11.5, F-Prot Antivirus 4.6.2.117, Fortinet Antivirus 4.2.254.0, K7 AntiVirus 9.77.3565, Kaspersky Anti-Virus 7.0.0.125, Antimalware Engine 1.1.6402.0 in Microsoft Security Essen…

authentium command_antivirus · cat quick_heal · eset nod32_antivirus · f-prot f-prot_antivirus · e altri 7
0.97EPSS
CVE-2012-1425
Media 4.3

The TAR file parser in Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, Quick Heal (aka Cat QuickHeal) 11.00, Emsisoft Anti-Malware 5.1.0.1, Fortinet Antivirus 4.2.254.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Jiangmin Antivirus 13.0.900…

antiy avl_sdk · avira antivir · cat quick_heal · emsisoft anti-malware · e altri 12
0.93EPSS
CVE-2012-1461
Media 4.3

The Gzip file parser in AVG Anti-Virus 10.0.0.1190, Bitdefender 7.2, Command Antivirus 5.2.11.5, Emsisoft Anti-Malware 5.1.0.1, F-Secure Anti-Virus 9.0.16160.0, Fortinet Antivirus 4.2.254.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Jiangmin Ant…

anti-virus vba32 · authentium command_antivirus · avg avg_anti-virus · bitdefender bitdefender · e altri 16
0.92EPSS
CVE-2012-1445
Media 4.3

The ELF file parser in eSafe 7.0.17.0, Rising Antivirus 22.83.00.03, Fortinet Antivirus 4.2.254.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an ELF file with a modified abi field. NOTE: this may later be SPLIT into m…

aladdin esafe · fortinet fortinet_antivirus · pandasecurity panda_antivirus · rising-global rising_antivirus
0.90EPSS
CVE-2012-1439
Media 4.3

The ELF file parser in eSafe 7.0.17.0, Rising Antivirus 22.83.00.03, Fortinet Antivirus 4.2.254.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an ELF file with a modified padding field. NOTE: this may later be SPLIT in…

aladdin esafe · fortinet fortinet_antivirus · pandasecurity panda_antivirus · rising-global rising_antivirus
0.90EPSS
CVE-2012-1423
Media 4.3

The TAR file parser in Command Antivirus 5.2.11.5, Emsisoft Anti-Malware 5.1.0.1, F-Prot Antivirus 4.6.2.117, Fortinet Antivirus 4.2.254.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, K7 AntiVirus 9.77.3565, NOD32 Antivirus 5795, Norman Antivirus …

authentium command_antivirus · emsisoft anti-malware · eset nod32_antivirus · f-prot f-prot_antivirus · e altri 7
0.90EPSS
CVE-2012-1454
Media 4.3

The ELF file parser in Dr.Web 5.0.2.03300, eSafe 7.0.17.0, McAfee Gateway (formerly Webwasher) 2010.1C, Rising Antivirus 22.83.00.03, Fortinet Antivirus 4.2.254.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an ELF file…

aladdin esafe · drweb dr.web_antivirus · fortinet fortinet_antivirus · mcafee gateway · e altri 2
0.88EPSS
CVE-2023-34992
Critica 10.0

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet allows attacker to execute unauthorized code or commands via crafted API requests.

fortinet fortisiem
0.80EPSS
CVE-2024-23108
Critica 10.0

An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet allows attacker to execute unauthorized code or commands via via crafted API requests.

fortinet fortisiem
0.78EPSS
CVE-2020-9294
Critica 9.8

An improper authentication vulnerability in FortiMail 5.4.10, 6.0.7, 6.2.2 and earlier and FortiVoiceEntreprise 6.0.0 and 6.0.1 may allow a remote unauthenticated attacker to access the system as a legitimate user by requesting a password change via the user i…

fortinet fortimail · fortinet fortivoice
0.78EPSS
CVE-2012-1440
Media 4.3

The ELF file parser in Norman Antivirus 6.06.12, eSafe 7.0.17.0, CA eTrust Vet Antivirus 36.1.8511, Fortinet Antivirus 4.2.254.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an ELF file with a modified identsize field. …

aladdin esafe · ca etrust_vet_antivirus · fortinet fortinet_antivirus · norman norman_antivirus_\&_antispyware · e altri 1
0.78EPSS
CVE-2021-22123
Alta 7.6

An OS command injection vulnerability in FortiWeb's management interface 6.3.7 and below, 6.2.3 and below, 6.1.x, 6.0.x, 5.9.x may allow a remote authenticated attacker to execute arbitrary commands on the system via the SAML server configuration page.

fortinet fortiweb
0.77EPSS
CVE-2016-1909
Critica 9.8

Fortinet FortiAnalyzer before 5.0.12 and 5.2.x before 5.2.5; FortiSwitch 3.3.x before 3.3.3; FortiCache 3.0.x before 3.0.8; and FortiOS 4.1.x before 4.1.11, 4.2.x before 4.2.16, 4.3.x before 4.3.17 and 5.0.x before 5.0.8 have a hardcoded passphrase for the For…

fortinet fortios
0.71EPSS