imPC@ndo EN

Vulnerabilità Fortinet

1134 CVE

CVE-2024-32118
Media 6.7

Multiple improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] in Fortinet FortiManager version 7.4.0 through 7.4.2 and before 7.2.5, Fortinet FortiAnalyzer version 7.4.0 through 7.4.2 and before 7.…

fortinet fortianalyzer · fortinet fortianalyzer_big_data · fortinet fortimanager
0.01EPSS
CVE-2024-46669
Bassa 3.5

An Integer Overflow or Wraparound vulnerability [CWE-190] in version 7.4.4 and below, version 7.2.10 and below; FortiSASE version 23.4.b FortiOS tenant IPsec IKE service may allow an authenticated attacker to crash the IPsec tunnel via crafted requests, result…

fortinet fortios
0.01EPSS
CVE-2020-9290
Alta 7.8

An Unsafe Search Path vulnerability in FortiClient for Windows online installer 6.2.3 and below may allow a local attacker with control over the directory in which FortiClientOnlineInstaller.exe and FortiClientVPNOnlineInstaller.exe resides to execute arbitrar…

fortinet forticlient · fortinet forticlient_virtual_private_network
0.01EPSS
CVE-2024-52964
Media 5.5

An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in Fortinet FortiManager version 7.6.0 through 7.6.1, 7.4.0 through 7.4.5, 7.2.0 through 7.2.9 and below 7.0.13 & FortiManager Cloud version 7.6.0 through …

fortinet fortimanager · fortinet fortimanager_cloud
0.01EPSS
CVE-2021-36175
Media 4.1

An improper neutralization of input vulnerability [CWE-79] in FortiWebManager versions 6.2.3 and below, 6.0.2 and below may allow a remote authenticated attacker to inject malicious script/tags via the name/description/comments parameter of various sections of…

fortinet fortiweb
0.01EPSS
CVE-2021-32597
Media 4.6

Multiple improper neutralization of input during web page generation (CWE-79) in FortiManager and FortiAnalyzer versions 7.0.0, 6.4.5 and below, 6.2.7 and below user interface, may allow a remote authenticated attacker to perform a Stored Cross Site Scripting …

fortinet fortianalyzer · fortinet fortimanager
0.01EPSS
CVE-2020-9287
Alta 7.8

An Unsafe Search Path vulnerability in FortiClient EMS online installer 6.2.1 and below may allow a local attacker with control over the directory in which FortiClientEMSOnlineInstaller.exe resides to execute arbitrary code on the system via uploading maliciou…

fortinet forticlient_emergency_management_server
0.01EPSS
CVE-2024-40591
Alta 8.8

An incorrect privilege assignment vulnerability [CWE-266] in Fortinet FortiOS version 7.6.0, 7.4.0 through 7.4.4, 7.2.0 through 7.2.9 and before 7.0.15 allows an authenticated admin whose access profile has the Security Fabric permission to escalate their priv…

fortinet fortios
0.01EPSS
CVE-2020-6641
Media 4.3

Two authorization bypass through user-controlled key vulnerabilities in the Fortinet FortiPresence 2.1.0 administration interface may allow an attacker to gain access to some user data via portal manager or portal users parameters.

fortinet fortipresence
0.01EPSS
CVE-2025-53843
Alta 7.5

A stack-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions allows attacker to execute unauthorized code or commands via speciall…

fortinet fortios
0.01EPSS
CVE-2024-46667
Alta 7.5

A allocation of resources without limits or throttling in Fortinet FortiSIEM 5.3 all versions, 5.4 all versions, 6.x all versions, 7.0 all versions, and 7.1.0 through 7.1.5 may allow an attacker to deny valid TLS traffic via consuming all allotted connections.…

fortinet fortisiem
0.01EPSS
CVE-2022-43951
Media 5.3

An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiNAC 9.4.1 and below, 9.2.6 and below, 9.1.8 and below, 8.8.11 and below, 8.7.6 and below may allow an unauthenticated attacker to access sensitive information via cra…

fortinet fortinac · fortinet fortinac-f
0.01EPSS
CVE-2023-33307
Media 6.5

A null pointer dereference in Fortinet FortiOS before 7.2.5 and before 7.0.11, FortiProxy before 7.2.3 and before 7.0.9 allows attacker to denial of sslvpn service via specifically crafted request in network parameter.

fortinet fortios · fortinet fortiproxy
0.01EPSS
CVE-2014-0351
Media 5.4

The FortiManager protocol service in Fortinet FortiOS before 4.3.16 and 5.x before 5.0.8 on FortiGate devices does not prevent use of anonymous ciphersuites, which makes it easier for man-in-the-middle attackers to obtain sensitive information or interfere wit…

fortinet fortios
0.01EPSS
CVE-2024-26011
Media 5.3

A missing authentication for critical function in Fortinet FortiManager version 7.4.0 through 7.4.2, 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through 6.4.14, FortiPAM version 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiProxy version 7.4.0 thr…

fortinet fortimanager · fortinet fortios · fortinet fortipam · fortinet fortiportal · e altri 2
0.01EPSS
CVE-2024-26006
Alta 7.5

An improper neutralization of input during web page Generation vulnerability [CWE-79] in FortiOS version 7.4.3 and below, version 7.2.7 and below, version 7.0.13 and below and FortiProxy version 7.4.3 and below, version 7.2.9 and below, version 7.0.16 and belo…

fortinet fortios · fortinet fortiproxy
0.01EPSS
CVE-2024-56497
Media 6.7

An improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiMail versions 7.2.0 through 7.2.4 and 7.0.0 through 7.0.6 and 6.4.0 through 6.4.7, FortiRecorder versions 7.0.0 and 6.4.0 through 6.4.4 allows attack…

fortinet fortimail · fortinet fortirecorder
0.01EPSS
CVE-2023-37930
Alta 7.5

Multiple issues including the use of uninitialized ressources [CWE-908] and excessive iteration [CWE-834] vulnerabilities vulnerability in Fortinet allows a VPN user to corrupt memory potentially leading to code or commands execution via specifically crafted …

fortinet fortios · fortinet fortiproxy
0.01EPSS
CVE-2023-37934
Media 4.3

An allocation of resources without limits or throttling vulnerability [CWE-770] in FortiPAM 1.0 all versions allows an authenticated attacker to perform a denial of service attack via sending crafted HTTP or HTTPS requests in a high frequency.

fortinet fortipam
0.01EPSS
CVE-2023-40714
Critica 9.9

A relative path traversal in Fortinet FortiSIEM versions 7.0.0, 6.7.0 through 6.7.2, 6.6.0 through 6.6.3, 6.5.1, 6.5.0 allows attacker to escalate privilege via uploading certain GUI elements

fortinet fortisiem
0.01EPSS
CVE-2021-41020
Alta 8.8

An improper access control vulnerability [CWE-284] in FortiIsolator versions 2.3.2 and below may allow an authenticated, non privileged attacker to regenerate the CA certificate via the regeneration URL.

fortinet fortiisolator
0.01EPSS
CVE-2024-47572
Critica 9.0

An improper neutralization of formula elements in a csv file in Fortinet FortiSOAR 7.2.1 through 7.4.1 allows attacker to execute unauthorized code or commands via manipulating csv file

fortinet fortisoar
0.01EPSS
CVE-2022-38376
Media 6.1

Multiple improper neutralization of input during web page generation ('Cross-site Scripting') vulnerabilities [CWE-79] in Fortinet FortiNAC portal UI before 9.4.1 allows an attacker to perform an XSS attack via crafted HTTP requests.

fortinet fortinac
0.01EPSS
CVE-2021-41032
Media 6.3

An improper access control vulnerability [CWE-284] in FortiOS versions 6.4.8 and prior and 7.0.3 and prior may allow an authenticated attacker with a restricted user profile to gather sensitive information and modify the SSL-VPN tunnel status of other VDOMs us…

fortinet fortios
0.01EPSS
CVE-2025-49201
Alta 8.1

A weak authentication vulnerability in Fortinet FortiPAM 1.5.0, FortiPAM 1.4.0 through 1.4.2, FortiPAM 1.3 all versions, FortiPAM 1.2 all versions, FortiPAM 1.1 all versions, FortiPAM 1.0 all versions, FortiSwitchManager 7.2.0 through 7.2.4 allows attacker to …

fortinet fortipam · fortinet fortiswitchmanager
0.01EPSS