imPC@ndo EN

Vulnerabilità Fortinet

1134 CVE

CVE-2018-9185
Alta 8.1

An information disclosure vulnerability in Fortinet FortiOS 6.0.0 and below versions reveals user's web portal login credentials in a Javascript file sent to client-side when pages bookmarked in web portal use the Single Sign-On feature.

fortinet fortios
0.02EPSS
CVE-2022-27483
Alta 7.2

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiManager version 7.0.0 through 7.0.3, 6.4.0 through 6.4.7, 6.2.x and 6.0.x and FortiAnalyzer version 7.0.0 through 7.0.3, version 6.4.0 through 6.4.7, …

fortinet fortianalyzer · fortinet fortimanager
0.02EPSS
CVE-2023-33308
Critica 9.8

A stack-based overflow vulnerability [CWE-124] in Fortinet FortiOS version 7.0.0 through 7.0.10 and 7.2.0 through 7.2.3 and FortiProxy version 7.0.0 through 7.0.9 and 7.2.0 through 7.2.2 allows a remote unauthenticated attacker to execute arbitrary code or com…

fortinet fortios · fortinet fortiproxy
0.02EPSS
CVE-2018-13376
Alta 7.5

An uninitialized memory buffer leak exists in Fortinet FortiOS 5.6.1 to 5.6.3, 5.4.6 to 5.4.7, 5.2 all versions under web proxy's disclaimer response web pages, potentially causing sensitive data to be displayed in the HTTP response.

fortinet fortios
0.02EPSS
CVE-2023-36550
Critica 9.8

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specifically crafted http get req…

fortinet fortiwlm
0.02EPSS
CVE-2023-36549
Alta 8.8

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specifically crafted http get req…

fortinet fortiwlm
0.02EPSS
CVE-2023-36548
Critica 9.8

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specifically crafted http get req…

fortinet fortiwlm
0.02EPSS
CVE-2023-36547
Critica 9.8

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specifically crafted http get req…

fortinet fortiwlm
0.02EPSS
CVE-2017-7732
Media 6.1

A reflected Cross-Site Scripting (XSS) vulnerability in Fortinet FortiMail 5.1 and earlier, 5.2.0 through 5.2.9, and 5.3.0 through 5.3.9 customized pre-authentication webmail login page allows attacker to inject arbitrary web script or HTML via crafted HTTP re…

fortinet fortimail
0.02EPSS
CVE-2015-5965
Media 5.0

The SSL-VPN feature in Fortinet FortiOS before 4.3.13 only checks the first byte of the TLS MAC in finished messages, which makes it easier for remote attackers to spoof encrypted content via a crafted MAC field.

fortinet fortios
0.02EPSS
CVE-2023-34989
Alta 8.8

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specifically crafted HTTP get req…

fortinet fortiwlm
0.02EPSS
CVE-2023-34988
Alta 8.8

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specifically crafted HTTP get req…

fortinet fortiwlm
0.02EPSS
CVE-2023-34987
Alta 8.8

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specifically crafted HTTP get req…

fortinet fortiwlm
0.02EPSS
CVE-2023-34986
Alta 8.8

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specifically crafted HTTP get req…

fortinet fortiwlm
0.02EPSS
CVE-2023-34985
Alta 8.8

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specifically crafted HTTP get req…

fortinet fortiwlm
0.02EPSS
CVE-2020-29019
Media 5.3

A stack-based buffer overflow vulnerability in FortiWeb 6.3.0 through 6.3.7 and version before 6.2.4 may allow a remote, unauthenticated attacker to crash the httpd daemon thread by sending a request with a crafted cookie header.

fortinet fortiweb
0.02EPSS
CVE-2017-14184
Alta 8.8

An Information Disclosure vulnerability in Fortinet FortiClient for Windows 5.6.0 and below versions, FortiClient for Mac OSX 5.6.0 and below versions and FortiClient SSLVPN Client for Linux 4.4.2334 and below versions allows regular users to see each other's …

fortinet forticlient · fortinet forticlient_sslvpn_client
0.02EPSS
CVE-2017-17540
Critica 9.8

The presence of a hardcoded account in Fortinet FortiWLC 8.3.3 allows attackers to gain unauthorized read/write access via a remote shell.

fortinet fortiwlc
0.02EPSS
CVE-2017-17539
Critica 9.8

The presence of a hardcoded account in Fortinet FortiWLC 7.0.11 and earlier allows attackers to gain unauthorized read/write access via a remote shell.

fortinet fortiwlc
0.02EPSS
CVE-2015-1459
Media 4.3

Cross-site scripting (XSS) vulnerability in Fortinet FortiAuthenticator 3.0.0 allows remote attackers to inject arbitrary web script or HTML via the operation parameter to cert/scep/.

fortinet fortiauthenticator
0.02EPSS
CVE-2015-5736
Alta 7.2

The Fortishield.sys driver in Fortinet FortiClient before 5.2.4 allows local users to execute arbitrary code with kernel privileges by setting the callback function in a (1) 0x220024 or (2) 0x220028 ioctl call.

fortinet forticlient
0.02EPSS
CVE-2020-29018
Alta 8.8

A format string vulnerability in FortiWeb 6.3.0 through 6.3.5 may allow an authenticated, remote attacker to read the content of memory and retrieve sensitive data via the redir parameter.

fortinet fortiweb
0.02EPSS
CVE-2013-1471
Media 4.3

Multiple cross-site scripting (XSS) vulnerabilities in admin/FEAdmin.html in Fortinet FortiMail before 4.3.4 on FortiMail Identity-Based Encryption (IBE) appliances allow user-assisted remote attackers to inject arbitrary web script or HTML via (1) the Add fie…

fortinet fortimail
0.02EPSS
CVE-2024-40584
Alta 7.2

An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiAnalyzer version 7.4.0 through 7.4.3, 7.2.0 through 7.2.5, 7.0.0 through 7.0.13, 6.4.0 through 6.4.15 and 6.2.2 through 6.2.13…

fortinet fortianalyzer · fortinet fortianalyzer_big_data · fortinet fortianalyzer_cloud · fortinet fortimanager · e altri 1
0.02EPSS
CVE-2015-3614
Alta 7.5

Fortinet FortiManager 5.0.x before 5.0.11, 5.2.x before 5.2.2 allows remote attackers to obtain arbitrary files via vectors involving another unspecified vulnerability.

fortinet fortimanager_firmware
0.02EPSS