Skip to main content

Vendor/product archive

fortinet / fortiweb CVEs

Beta · best-effort

124 CVEs tagged to fortinet / fortiweb9 Critical, 37 High, 73 Medium, 5 Low, 0 Unrated.

CVE-2022-39951

Published Mar 7, 2023

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWeb version 7.0.0 through 7.0.2, FortiWeb version 6.3.6 through 6.3.2…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2023-22636

Published Feb 27, 2023

An unauthorized configuration download vulnerability in FortiWeb 6.3.6 through 6.3.21, 6.4.0 through 6.4.2 and 7.0.0 through 7.0.4 may allow a local attacker to access confidentia…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2023-25602

Published Feb 16, 2023

A stack-based buffer overflow in Fortinet FortiWeb 6.4 all versions, FortiWeb versions 6.3.17 and earlier, FortiWeb versions 6.2.6 and earlier, FortiWeb versions 6.1.2 and earlier…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-23784

Published Feb 16, 2023

A relative path traversal in Fortinet FortiWeb version 7.0.0 through 7.0.2, FortiWeb version 6.3.6 through 6.3.20, FortiWeb 6.4 all versions allows attacker to information disclos…

CVSS 5.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-23783

Published Feb 16, 2023

A use of externally-controlled format string in Fortinet FortiWeb version 7.0.0 through 7.0.1, FortiWeb 6.4 all versions allows attacker to execute unauthorized code or commands v…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-23782

Published Feb 16, 2023

A heap-based buffer overflow in Fortinet FortiWeb version 7.0.0 through 7.0.1, FortiWeb version 6.3.0 through 6.3.19, FortiWeb 6.4 all versions, FortiWeb 6.2 all versions, FortiWe…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-23781

Published Feb 16, 2023

A stack-based buffer overflow vulnerability [CWE-121] in FortiWeb version 7.0.1 and below, 6.4 all versions, version 6.3.19 and below SAML server configuration may allow an authen…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-23780

Published Feb 16, 2023

A stack-based buffer overflow in Fortinet FortiWeb version 7.0.0 through 7.0.1, Fortinet FortiWeb version 6.3.6 through 6.3.19, Fortinet FortiWeb 6.4 all versions allows attacker…

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2023-23779

Published Feb 16, 2023

Multiple improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerabilities [CWE-78] in FortiWeb version 7.0.1 and below, 6.4 all versions,…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-23778

Published Feb 16, 2023

A relative path traversal vulnerability [CWE-23] in FortiWeb version 7.0.1 and below, 6.4 all versions, 6.3 all versions, 6.2 all versions may allow an authenticated user to obtai…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-40683

Published Feb 16, 2023

A double free in Fortinet FortiWeb version 7.0.0 through 7.0.3 may allows attacker to execute unauthorized code or commands via specially crafted commands

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-33871

Published Feb 16, 2023

A stack-based buffer overflow vulnerability [CWE-121] in FortiWeb version 7.0.1 and earlier, 6.4 all versions, version 6.3.19 and earlier may allow a privileged attacker to execut…

CVSS 6.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-30306

Published Feb 16, 2023

A stack-based buffer overflow vulnerability [CWE-121] in the CA sign functionality of FortiWeb version 7.0.1 and below, 6.4 all versions, version 6.3.19 and below may allow an aut…

CVSS 6.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-30303

Published Feb 16, 2023

An improper neutralization of special elements used in an os command ('OS Command Injection') [CWE-78] in FortiWeb 7.0.0 through 7.0.1, 6.3.0 through 6.3.19, 6.4 all versions may…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-30300

Published Feb 16, 2023

A relative path traversal vulnerability [CWE-23] in FortiWeb 7.0.0 through 7.0.1, 6.3.6 through 6.3.18, 6.4 all versions may allow an authenticated attacker to obtain unauthorized…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-30299

Published Feb 16, 2023

A path traversal vulnerability [CWE-23] in the API of FortiWeb 7.0.0 through 7.0.1, 6.3.0 through 6.3.19, 6.4 all versions, 6.2 all versions, 6.1 all versions, 6.0 all versions ma…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-42761

Published Feb 16, 2023

A condition for session fixation vulnerability [CWE-384] in the session management of FortiWeb versions 6.4 all versions, 6.3.0 through 6.3.16, 6.2.0 through 6.2.6, 6.1.0 through…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-42756

Published Feb 16, 2023

Multiple stack-based buffer overflow vulnerabilities [CWE-121] in the proxy daemon of FortiWeb 5.x all versions, 6.0.7 and below, 6.1.2 and below, 6.2.6 and below, 6.3.16 and belo…

CVSS 9.8 · Critical
evidence mentions
6
Buzz score
32.5
Vendor/product tagsBeta · best-effort

CVE-2022-42471

Published Jan 3, 2023

An improper neutralization of CRLF sequences in HTTP headers ('HTTP Response Splitting') vulnerability [CWE-113] In FortiWeb version 7.0.0 through 7.0.2, FortiWeb version 6.4.0 th…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-41026

Published Apr 6, 2022

A relative path traversal in FortiWeb versions 6.4.1, 6.4.0, and 6.3.0 through 6.3.15 may allow an authenticated attacker to retrieve arbitrary files from the underlying filesyste…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-41018

Published Feb 2, 2022

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below allows attacker to exec…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-36193

Published Feb 2, 2022

Multiple stack-based buffer overflows in the command line interpreter of FortiWeb before 6.4.2 may allow an authenticated attacker to achieve arbitrary code execution via speciall…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-43073

Published Feb 2, 2022

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWeb version 6.4.1 and 6.4.0, version 6.3.15 and below, version 6.2.6…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 51-75 of 124 CVEsPage 3 of 5