Skip to main content

Vendor/product archive

fortinet / fortianalyzer CVEs

Beta · best-effort

93 CVEs tagged to fortinet / fortianalyzer3 Critical, 25 High, 58 Medium, 7 Low, 0 Unrated.

CVE-2023-42787

Published Oct 10, 2023

A client-side enforcement of server-side security [CWE-602] vulnerability in Fortinet FortiManager version 7.4.0 and before 7.2.3 and FortiAnalyzer version 7.4.0 and before 7.2.3…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2023-42782

Published Oct 10, 2023

A insufficient verification of data authenticity vulnerability [CWE-345] in FortiAnalyzer version 7.4.0 and below 7.2.3 allows a remote unauthenticated attacker to send messages t…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-42477

Published Apr 11, 2023

An improper input validation vulnerability [CWE-20] in FortiAnalyzer version 7.2.1 and below, version 7.0.6 and below, 6.4 all versions may allow an authenticated attacker to disc…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2023-25611

Published Mar 7, 2023

A improper neutralization of formula elements in a CSV file vulnerability in Fortinet FortiAnalyzer 6.4.0 - 6.4.9, 7.0.0 - 7.0.5, and 7.2.0 - 7.2.1 allows local attacker to execut…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-23776

Published Mar 7, 2023

An exposure of sensitive information to an unauthorized actor [CWE-200] vulnerability in FortiAnalyzer versions 7.2.0 through 7.2.1, 7.0.0 through 7.0.4 and 6.4.0 through 6.4.10 m…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-30304

Published Feb 16, 2023

An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiAnalyzer versions prior to 7.2.1, 7.0.4 and 6.4.8 may allow a remote unauthenticated…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-26118

Published Jul 18, 2022

A privilege chaining vulnerability [CWE-268] in FortiManager and FortiAnalyzer 6.0.x, 6.2.x, 6.4.0 through 6.4.7, 7.0.0 through 7.0.3 may allow a local and authenticated attacker…

CVSS 6.7 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2021-42757

Published Dec 8, 2021

A buffer overflow [CWE-121] in the TFTP client library of FortiOS before 6.4.7 and FortiOS 7.0.0 through 7.0.2, may allow an authenticated local attacker to achieve arbitrary code…

CVSS 6.7 · Medium
Showing 51-75 of 93 CVEsPage 3 of 4