Skip to main content

Vendor/product archive

fortinet / fortios CVEs

Beta · best-effort

278 CVEs tagged to fortinet / fortios22 Critical, 64 High, 164 Medium, 28 Low, 0 Unrated.

CVE-2024-54021

Published Jan 14, 2025

An Improper Neutralization of CRLF Sequences in HTTP Headers ('http response splitting') vulnerability [CWE-113] in Fortinet FortiOS 7.2.0 through 7.6.0, FortiProxy 7.2.0 through…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-52963

Published Jan 14, 2025

A out-of-bounds write in Fortinet FortiOS versions 7.6.0, 7.4.0 through 7.4.6, 7.2.0 through 7.2.10, 7.0.0 through 7.0.16, 6.4.0 through 6.4.15 allows attacker to trigger a denial…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-46670

Published Jan 14, 2025

An Out-of-bounds Read vulnerability [CWE-125] in FortiOS version 7.6.0, version 7.4.4 and below, version 7.2.9 and below and FortiSASE FortiOS tenant version 24.3.b IPsec IKE serv…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-46669

Published Jan 14, 2025

An Integer Overflow or Wraparound vulnerability [CWE-190] in version 7.4.4 and below, version 7.2.10 and below; FortiSASE version 23.4.b FortiOS tenant IPsec IKE service may allow…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-46668

Published Jan 14, 2025

An allocation of resources without limits or throttling vulnerability [CWE-770] in FortiOS versions 7.4.0 through 7.4.4, versions 7.2.0 through 7.2.8, versions 7.0.0 through 7.0.1…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-46666

Published Jan 14, 2025

An allocation of resources without limits or throttling [CWE-770] vulnerability in FortiOS versions 7.6.0, versions 7.4.4 through 7.4.0, 7.2 all versions, 7.0 all versions, 6.4 al…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-46665

Published Jan 14, 2025

An insertion of sensitive information into sent data vulnerability [CWE-201] in FortiOS 7.6.0, 7.4.0 through 7.4.4 may allow an attacker in a man-in-the-middle position to retriev…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-36504

Published Jan 14, 2025

An out-of-bounds read vulnerability [CWE-125] in FortiOS SSLVPN web portal versions 7.4.0 through 7.4.4, versions 7.2.0 through 7.2.8, 7.0 all verisons, and 6.4 all versions may a…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-46715

Published Jan 14, 2025

An origin validation error [CWE-346] vulnerability in Fortinet FortiOS IPSec VPN version 7.4.0 through 7.4.1 and version 7.2.6 and below allows an authenticated IPSec VPN user wi…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-42786

Published Jan 14, 2025

A null pointer dereference in FortiOS versions 7.4.0 through 7.4.1, 7.2.0 through 7.2.5, 7.0 all versions, 6.4 all versions , 6.2 all versions and 6.0 all versions allows attacker…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-42785

Published Jan 14, 2025

A null pointer dereference in FortiOS versions 7.4.0 through 7.4.1, 7.2.0 through 7.2.5, 7.0 all versions, 6.4 all versions , 6.2 all versions and 6.0 all versions allows attacker…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-12820

Published Dec 19, 2024

Under non-default configuration, a stack-based buffer overflow in FortiOS version 6.0.10 and below, version 5.6.12 and below may allow a remote attacker authenticated to the SSL V…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-12819

Published Dec 19, 2024

A heap-based buffer overflow vulnerability in the processing of Link Control Protocol messages in FortiGate versions 5.6.12, 6.0.10, 6.2.4 and 6.4.1 and earlier may allow a remote…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-33510

Published Nov 12, 2024

An improper neutralization of special elements in output used by a downstream component ('Injection') vulnerability [CWE-74] in FortiOS version 7.4.3 and below, version 7.2.8 and…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-50176

Published Nov 12, 2024

A session fixation in Fortinet FortiOS version 7.4.0 through 7.4.3 and 7.2.0 through 7.2.7 and 7.0.0 through 7.0.13 allows attacker to execute unauthorized code or commands via ph…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-36505

Published Aug 13, 2024

An improper access control vulnerability [CWE-284] in FortiOS 7.4.0 through 7.4.3, 7.2.5 through 7.2.7, 7.0.12 through 7.0.14 and 6.4.x may allow an attacker who has already succe…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-23111

Published Jun 11, 2024

An improper neutralization of input during web page Generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiOS version 7.4.3 and below, 7.2 all versions, 7.0 all versio…

CVSS 6.8 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-23110

Published Jun 11, 2024

A stack-based buffer overflow in Fortinet FortiOS version 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, 6.0 all versi…

CVSS 7.8 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2024-21754

Published Jun 11, 2024

A use of password hash with insufficient computational effort vulnerability [CWE-916] affecting FortiOS version 7.4.3 and below, 7.2 all versions, 7.0 all versions, 6.4 all versio…

CVSS 1.8 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 76-100 of 278 CVEsPage 4 of 12