imPC@ndo EN

Vulnerabilità Fortinet

1134 CVE

CVE-2021-42758
Alta 8.8

An improper access control vulnerability [CWE-284] in FortiWLC 8.6.1 and below may allow an authenticated and remote attacker with low privileges to execute any command as an admin user with full access rights via bypassing the GUI restrictions.

fortinet fortiwlc
0.02EPSS
CVE-2013-6826
Media 6.8

cgi-bin/module//sysmanager/admin/SYSAdminUserDialog in Fortinet FortiAnalyzer before 5.0.5 does not properly validate the csrf_token parameter, which allows remote attackers to perform cross-site request forgery (CSRF) attacks.

fortinet fortianalyzer-1000d · fortinet fortianalyzer-2000b · fortinet fortianalyzer-200d · fortinet fortianalyzer-3000d · e altri 3
0.02EPSS
CVE-2021-36182
Alta 8.8

A Improper neutralization of special elements used in a command ('Command Injection') in Fortinet FortiWeb version 6.3.13 and below allows attacker to execute unauthorized code or commands via crafted HTTP requests

fortinet fortiweb
0.02EPSS
CVE-2021-36185
Alta 8.8

A improper neutralization of special elements used in an OS command ('OS Command Injection') in Fortinet FortiWLM version 8.6.1 and below allows attacker to execute unauthorized code or commands via crafted HTTP requests.

fortinet fortiwlm
0.02EPSS
CVE-2021-41017
Alta 8.8

Multiple heap-based buffer overflow vulnerabilities in some web API controllers of FortiWeb 6.4.1, 6.4.0, and 6.3.0 through 6.3.15 may allow a remote authenticated attacker to execute arbitrary code or commands via specifically crafted HTTP requests.

fortinet fortiweb
0.02EPSS
CVE-2014-0331
Media 4.3

Cross-site scripting (XSS) vulnerability in the web administration interface in FortiADC with firmware before 3.2.1 allows remote attackers to inject arbitrary web script or HTML via the locale parameter to gui_partA/.

fortinet fortiadc-1000e · fortinet fortiadc-1500d · fortinet fortiadc-2000d · fortinet fortiadc-200d · e altri 5
0.02EPSS
CVE-2023-36553
Critica 9.8

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiSIEM version 5.4.0 and 5.3.0 through 5.3.3 and 5.2.5 through 5.2.8 and 5.2.1 through 5.2.2 and 5.1.0 through 5.1.3 and 5.0.0 through 5.0.1 and 4.10.0 …

fortinet fortisiem
0.02EPSS
CVE-2017-7344
Alta 8.1

A privilege escalation in Fortinet FortiClient Windows 5.4.3 and earlier as well as 5.6.0 allows attacker to gain privilege via exploiting the Windows "security alert" dialog thereby popping up when the "VPN before logon" feature is enabled and an untrusted ce…

fortinet forticlient
0.02EPSS
CVE-2021-26109
Alta 8.1

An integer overflow or wraparound vulnerability in the memory allocator of SSLVPN in FortiOS before 7.0.1 may allow an unauthenticated attacker to corrupt control data on the heap via specifically crafted requests to SSLVPN, resulting in potentially arbitrary …

fortinet fortios
0.02EPSS
CVE-2016-8493
Alta 8.8

In FortiClientWindows 5.4.1 and 5.4.2, an attacker may escalate privilege via a FortiClientNamedPipe vulnerability.

fortinet forticlient
0.02EPSS
CVE-2014-8616
Media 4.3

Multiple cross-site scripting (XSS) vulnerabilities in Fortinet FortiOS 5.2.x before 5.2.3 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors to the (1) user group or (2) vpn template menus.

fortinet fortios
0.02EPSS
CVE-2015-1452
Alta 7.8

The Control and Provisioning of Wireless Access Points (CAPWAP) daemon in Fortinet FortiOS 5.0 Patch 7 build 4457 allows remote attackers to cause a denial of service (locked CAPWAP Access Controller) via a large number of ClientHello DTLS messages.

fortinet fortios
0.02EPSS
CVE-2023-26208
Bassa 3.7

A improper restriction of excessive authentication attempts vulnerability [CWE-307] in Fortinet FortiAuthenticator 6.4.x and before allows a remote unauthenticated attacker to partially exhaust CPU and memory via sending numerous HTTP requests to the login fo…

fortinet fortiauthenticator
0.02EPSS
CVE-2018-9195
Media 5.9

Use of a hardcoded cryptographic key in the FortiGuard services communication protocol may allow a Man in the middle with knowledge of the key to eavesdrop on and modify information (URL/SPAM services in FortiOS 5.6, and URL/SPAM/AV services in FortiOS 6.0.; U…

fortinet forticlient · fortinet fortios
0.02EPSS
CVE-2006-3222
Media 5.0

The FTP proxy module in Fortinet FortiOS (FortiGate) before 2.80 MR12 and 3.0 MR2 allows remote attackers to bypass anti-virus scanning via the Enhanced Passive (EPSV) FTP mode.

fortinet fortios
0.02EPSS
CVE-2022-29056
Bassa 3.7

A improper restriction of excessive authentication attempts vulnerability [CWE-307] in Fortinet FortiMail version 6.4.0, version 6.2.0 through 6.2.4 and before 6.0.9 allows a remote unauthenticated attacker to partially exhaust CPU and memory via sending nume…

fortinet fortimail
0.02EPSS
CVE-2019-15705
Alta 7.5

An Improper Input Validation vulnerability in the SSL VPN portal of FortiOS versions 6.2.1 and below, and 6.0.6 and below may allow an unauthenticated remote attacker to crash the SSL VPN service by sending a crafted POST request.

fortinet fortios
0.02EPSS
CVE-2014-2336
Media 4.3

Multiple cross-site scripting (XSS) vulnerabilities in the Web User Interface in Fortinet FortiManager before 5.0.7 and FortiAnalyzer before 5.0.7 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability …

fortinet fortianalyzer_firmware · fortinet fortimanager
0.02EPSS
CVE-2026-25836
Alta 7.2

An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox Cloud 5.0.4, FortiSandbox PaaS 5.0.4 may allow a privileged attacker with super-admin profile and CLI access to execute unauth…

fortinet fortisandbox_cloud
0.02EPSS
CVE-2018-13381
Media 5.3

A buffer overflow vulnerability in Fortinet FortiOS 6.0.0 through 6.0.4, 5.6.0 through 5.6.7, 5.4 and earlier versions and FortiProxy 2.0.0, 1.2.8 and earlier versions under SSL VPN web portal allows a non-authenticated attacker to perform a Denial-of-service …

fortinet fortios · fortinet fortiproxy
0.02EPSS
CVE-2023-26209
Bassa 3.7

A improper restriction of excessive authentication attempts vulnerability [CWE-307] in Fortinet FortiDeceptor 3.1.x and before allows a remote unauthenticated attacker to partially exhaust CPU and memory via sending numerous HTTP requests to the login form.

fortinet fortideceptor
0.02EPSS
CVE-2024-50569
Media 6.6

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWeb 7.0.0 through 7.6.0 allows attacker to execute unauthorized code or commands via crafted input.

fortinet fortiweb
0.02EPSS
CVE-2017-14182
Media 6.5

A Denial of Service (DoS) vulnerability in Fortinet FortiOS 5.4.0 to 5.4.5 allows an authenticated user to cause the web GUI to be temporarily unresponsive, via passing a specially crafted payload to the 'params' parameter of the JSON web API.

fortinet fortios
0.02EPSS
CVE-2025-64153
Alta 7.2

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiExtender 7.6.0 through 7.6.3, FortiExtender 7.4.0 through 7.4.7, FortiExtender 7.2 all versions, FortiExtender 7.0 all versions may allow an authentic…

fortinet fortiextender_firmware
0.02EPSS
CVE-2005-3221
Media 5.1

Multiple interpretation error in unspecified versions of Fortinet Antivirus allows remote attackers to bypass virus detection via a malicious executable in a specially crafted RAR file with malformed central and local headers, which can still be opened by prod…

fortinet fortinet_antivirus
0.02EPSS