imPC@ndo EN

Vulnerabilità Fortinet

1134 CVE

CVE-2023-48782
Alta 8.8

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 allows attacker to execute unauthorized code or commands via specifically crafted http get request parameters

fortinet fortiwlm
0.03EPSS
CVE-2019-5589
Alta 7.8

An Unsafe Search Path vulnerability in FortiClient Online Installer (Windows version before 6.0.6) may allow an unauthenticated, remote attacker with control over the directory in which FortiClientOnlineInstaller.exe resides to execute arbitrary code on the sy…

fortinet forticlient
0.03EPSS
CVE-2023-29180
Alta 7.5

A null pointer dereference in Fortinet FortiOS version 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through 6.4.12, 6.2.0 through 6.2.14, 6.0.0 through 6.0.16, FortiProxy 7.2.0 through 7.2.3, 7.0.0 through 7.0.10, 2.0.0 through 2.0.12, 1.2.0 through 1.2.13…

fortinet fortios · fortinet fortiproxy
0.03EPSS
CVE-2022-33873
Media 6.8

An improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerabilities [CWE-78] in Console login components of FortiTester 2.3.0 through 3.9.1, 4.0.0 through 4.2.0, 7.0.0 through 7.1.0 may allow an unauthenticated attacke…

fortinet fortitester
0.03EPSS
CVE-2020-29015
Critica 9.8

A blind SQL injection in the user interface of FortiWeb 6.3.0 through 6.3.7 and version before 6.2.4 may allow an unauthenticated, remote attacker to execute arbitrary SQL queries or commands by sending a request with a crafted Authorization header containing …

fortinet fortiweb
0.03EPSS
CVE-2022-30303
Alta 8.8

An improper neutralization of special elements used in an os command ('OS Command Injection') [CWE-78] in FortiWeb 7.0.0 through 7.0.1, 6.3.0 through 6.3.19, 6.4 all versions may allow an authenticated attacker to execute arbitrary shell code as `root` user vi…

fortinet fortiweb
0.03EPSS
CVE-2024-21755
Alta 8.8

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.3, FortiSandbox 4.2.1 through 4.2.6, FortiSandbox 4.0.0 through 4.0.4 allows attacker to execute unauthorized …

fortinet fortisandbox
0.02EPSS
CVE-2017-7336
Critica 9.8

A hard-coded account named 'upgrade' in Fortinet FortiWLM 8.3.0 and lower versions allows a remote attacker to log-in and execute commands with 'upgrade' account privileges.

fortinet fortiwlm
0.02EPSS
CVE-2023-29179
Media 6.5

A null pointer dereference in Fortinet FortiOS version 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through 6.4.12, Fortiproxy version 7.2.0 through 7.2.4, 7.0.0 through 7.0.10 allows attacker to denial of service via specially crafted HTTP requests.

fortinet fortios · fortinet fortiproxy
0.02EPSS
CVE-2013-7182
Media 4.3

Cross-site scripting (XSS) vulnerability in firewall/schedule/recurrdlg in Fortinet FortiOS 5.0.5 allows remote attackers to inject arbitrary web script or HTML via the mkey parameter.

fortinet fortios
0.02EPSS
CVE-2013-7181
Media 4.3

Cross-site scripting (XSS) vulnerability in user/ldap_user/add in Fortinet FortiOS 5.0.3 allows remote attackers to inject arbitrary web script or HTML via the filter parameter.

fortinet fortiweb
0.02EPSS
CVE-2015-3620
Media 4.3

Cross-site scripting (XSS) vulnerability in the advanced dataset reports page in Fortinet FortiAnalyzer 5.0.0 through 5.0.10 and 5.2.0 through 5.2.1 and FortiManager 5.0.3 through 5.0.10 and 5.2.0 through 5.2.1 allows remote attackers to inject arbitrary web s…

fortinet fortianalyzer_firmware · fortinet fortimanager_firmware
0.02EPSS
CVE-2019-17657
Alta 7.5

An Uncontrolled Resource Consumption vulnerability in Fortinet FortiSwitch below 3.6.11, 6.0.6 and 6.2.2, FortiAnalyzer below 6.2.3, FortiManager below 6.2.3 and FortiAP-S/W2 below 6.2.2 may allow an attacker to cause admin webUI denial of service (DoS) via ha…

fortinet fortianalyzer · fortinet fortiap-s · fortinet fortiap-w2 · fortinet fortimanager · e altri 1
0.02EPSS
CVE-2015-3616
Critica 9.8

SQL injection vulnerability in Fortinet FortiManager 5.0.x before 5.0.11, 5.2.x before 5.2.2 allows remote attackers to execute arbitrary commands via unspecified parameters.

fortinet fortimanager_firmware
0.02EPSS
CVE-2014-2721
Alta 8.8

In FortiBalancer 400, 1000, 2000 and 3000, a platform-specific remote access vulnerability has been discovered that may allow a remote user to gain privileged access to affected systems using SSH. The vulnerability is caused by a configuration error, and is no…

fortinet fortibalancer_1000_firmware · fortinet fortibalancer_2000_firmware · fortinet fortibalancer_3000_firmware · fortinet fortibalancer_400_firmware
0.02EPSS
CVE-2013-1414
Media 5.1

Multiple cross-site request forgery (CSRF) vulnerabilities in Fortinet FortiOS on FortiGate firewall devices before 4.3.13 and 5.x before 5.0.2 allow remote attackers to hijack the authentication of administrators for requests that modify (1) settings or (2) p…

fortinet fortigate-1000c · fortinet fortigate-100d · fortinet fortigate-110c · fortinet fortigate-1240b · e altri 26
0.02EPSS
CVE-2020-12817
Alta 8.8

An improper neutralization of input vulnerability in FortiAnalyzer before 6.4.1 and 6.2.5 may allow a remote authenticated attacker to inject script related HTML tags via Name parameter of Storage Connectors.

fortinet fortianalyzer · fortinet fortitester
0.02EPSS
CVE-2016-4969
Media 6.1

Cross-site scripting (XSS) vulnerability in Fortinet FortiWan (formerly AscernLink) before 4.2.5 allows remote attackers to inject arbitrary web script or HTML via the IP parameter to script/statistics/getconn.php.

fortinet fortiwan
0.02EPSS
CVE-2024-46662
Alta 8.8

A improper neutralization of special elements used in a command ('command injection') in Fortinet FortiManager versions 7.4.1 through 7.4.3, FortiManager Cloud versions 7.4.1 through 7.4.3 allows attacker to escalation of privilege via specifically crafted pac…

fortinet fortimanager · fortinet fortimanager_cloud
0.02EPSS
CVE-2015-3613
Critica 9.8

A vulnerability exists in in FortiManager 5.2.1 and earlier and 5.0.10 and earlier in the WebUI FTP backup page

fortinet fortimanager
0.02EPSS
CVE-2016-4966
Media 6.5

The diagnosis_control.php page in Fortinet FortiWan (formerly AscernLink) before 4.2.5 allows remote authenticated users to download PCAP files via vectors related to the UserName GET parameter.

fortinet fortiwan
0.02EPSS
CVE-2024-21756
Alta 8.8

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.3, FortiSandbox 4.2.1 through 4.2.6, FortiSandbox 4.0.0 through 4.0.4 allows attacker to execute unauthorized …

fortinet fortisandbox
0.02EPSS
CVE-2019-17658
Critica 9.8

An unquoted service path vulnerability in the FortiClient FortiTray component of FortiClientWindows v6.2.2 and prior allow an attacker to gain elevated privileges via the FortiClientConsole executable service path.

fortinet forticlient
0.02EPSS
CVE-2024-50567
Alta 7.2

An improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWeb 7.4.0 through 7.6.0 allows attacker to execute unauthorized code or commands via crafted input.

fortinet fortiweb
0.02EPSS
CVE-2020-9289
Alta 7.5

Use of a hard-coded cryptographic key to encrypt password data in CLI configuration in FortiManager 6.2.3 and below, FortiAnalyzer 6.2.3 and below may allow an attacker with access to the CLI configuration or the CLI backup file to decrypt the sensitive data, …

fortinet fortianalyzer · fortinet fortimanager
0.02EPSS