Skip to main content

Vendor/product archive

fortinet / fortiweb CVEs

Beta · best-effort

124 CVEs tagged to fortinet / fortiweb9 Critical, 37 High, 73 Medium, 5 Low, 0 Unrated.

CVE-2021-42753

Published Feb 2, 2022

An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in FortiWeb management interface 6.4.1 and below, 6.3.15 and below, 6.2.x,…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2021-43071

Published Dec 9, 2021

A heap-based buffer overflow in Fortinet FortiWeb version 6.4.1 and 6.4.0, version 6.3.15 and below, version 6.2.6 and below allows attacker to execute unauthorized code or comman…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-36194

Published Dec 9, 2021

Multiple stack-based buffer overflows in the API controllers of FortiWeb 6.4.1, 6.4.0, and 6.3.0 through 6.3.15 may allow an authenticated attacker to achieve arbitrary code execu…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-41025

Published Dec 8, 2021

Multiple vulnerabilities in the authentication mechanism of confd in FortiWeb versions 6.4.1, 6.4.0, 6.3.0 through 6.3.15, 6.2.0 through 6.2.6, 6.1.0 through 6.1.2, 6.0.0 thorugh…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2021-41017

Published Dec 8, 2021

Multiple heap-based buffer overflow vulnerabilities in some web API controllers of FortiWeb 6.4.1, 6.4.0, and 6.3.0 through 6.3.15 may allow a remote authenticated attacker to exe…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-36195

Published Dec 8, 2021

Multiple command injection vulnerabilities in the command line interpreter of FortiWeb versions 6.4.1, 6.4.0, 6.3.0 through 6.3.15, 6.2.0 through 6.2.6, and 6.1.0 through 6.1.2 ma…

CVSS 4.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-41013

Published Dec 8, 2021

An improper access control vulnerability [CWE-284] in FortiWeb versions 6.4.1 and below and 6.3.15 and below in the Report Browse section of Log & Report may allow an unauthorized…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-36188

Published Dec 8, 2021

A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below allows attacker to execute un…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-43063

Published Dec 8, 2021

A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiWeb version 6.4.1 and 6.4.0, version 6.3.15 and below, version 6.2.6 and be…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-36190

Published Dec 8, 2021

A unintended proxy or intermediary ('confused deputy') in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below allows an unauthenticated attacker to access protected hosts…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-43064

Published Dec 8, 2021

A url redirection to untrusted site ('open redirect') in Fortinet FortiWeb version 6.4.1 and 6.4.0, version 6.3.15 and below, version 6.2.6 and below allows attacker to use the de…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-41027

Published Dec 8, 2021

A stack-based buffer overflow in Fortinet FortiWeb version 6.4.1 and 6.4.0, allows an authenticated attacker to execute unauthorized code or commands via crafted certificates load…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2021-41015

Published Dec 8, 2021

A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below allows attacker to execute un…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-41014

Published Dec 8, 2021

A uncontrolled resource consumption in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below allows an unauthenticated attacker to make the httpsd daemon unresponsive via hu…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-36191

Published Dec 8, 2021

A url redirection to untrusted site ('open redirect') in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below allows attacker to use the device as proxy via crafted GET par…

CVSS 4.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-42757

Published Dec 8, 2021

A buffer overflow [CWE-121] in the TFTP client library of FortiOS before 6.4.7 and FortiOS 7.0.0 through 7.0.2, may allow an authenticated local attacker to achieve arbitrary code…

CVSS 6.7 · Medium

CVE-2021-36180

Published Dec 8, 2021

Multiple improper neutralization of special elements used in a command vulnerabilities [CWE-77] in FortiWeb management interface 6.4.1 and below, 6.3.15 and below, 6.2.5 and below…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2021-36187

Published Nov 2, 2021

A uncontrolled resource consumption in Fortinet FortiWeb version 6.4.0, version 6.3.15 and below, 6.2.5 and below allows attacker to cause a denial of service for webserver daemon…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-36186

Published Nov 2, 2021

A stack-based buffer overflow in Fortinet FortiWeb version 6.4.0, version 6.3.15 and below, 6.2.5 and below allows attacker to execute unauthorized code or commands via crafted HT…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-36175

Published Oct 6, 2021

An improper neutralization of input vulnerability [CWE-79] in FortiWebManager versions 6.2.3 and below, 6.0.2 and below may allow a remote authenticated attacker to inject malicio…

CVSS 4.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-36182

Published Sep 8, 2021

A Improper neutralization of special elements used in a command ('Command Injection') in Fortinet FortiWeb version 6.3.13 and below allows attacker to execute unauthorized code or…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-36179

Published Sep 8, 2021

A stack-based buffer overflow in Fortinet FortiWeb version 6.3.14 and below, 6.2.4 and below allows attacker to execute unauthorized code or commands via crafted parameters in CLI…

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2021-22123

Published Jun 1, 2021

An OS command injection vulnerability in FortiWeb's management interface 6.3.7 and below, 6.2.3 and below, 6.1.x, 6.0.x, 5.9.x may allow a remote authenticated attacker to execute…

CVSS 7.6 · High
evidence mentions
4
Buzz score
24.1
Vendor/product tagsBeta · best-effort

CVE-2020-15942

Published Apr 12, 2021

An information disclosure vulnerability in Web Vulnerability Scan profile of Fortinet's FortiWeb version 6.2.x below 6.2.4 and version 6.3.x below 6.3.5 may allow a remote authent…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 76-100 of 124 CVEsPage 4 of 5