Skip to main content

Vendor archive

fortinet CVEs

Beta · best-effort

1,135 CVEs tagged to vendor fortinet92 Critical, 364 High, 603 Medium, 76 Low, 0 Unrated.

CVE-2024-54027

Published Mar 17, 2025

A Use of Hard-coded Cryptographic Key vulnerability [CWE-321] in FortiSandbox version 4.4.6 and below, version 4.2.7 and below, version 4.0.5 and below, version 3.2.4 and below, v…

CVSS 8.2 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2021-32584

Published Mar 17, 2025

An improper access control (CWE-284) vulnerability in FortiWLC version 8.6.0, version 8.5.3 and below, version 8.4.8 and below, version 8.3.3 and below, version 8.2.7 to 8.2.4, ve…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-26087

Published Mar 17, 2025

An improper neutralization of input during web page generation in FortiWLC version 8.6.0, version 8.5.3 and below, version 8.4.8 and below, version 8.3.3 web interface may allow b…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-22126

Published Mar 17, 2025

A use of hard-coded password vulnerability in FortiWLC version 8.5.2 and below, version 8.4.8 and below, version 8.3.3 to 8.3.2, version 8.2.7 to 8.2.6 may allow a local, authenti…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-29010

Published Mar 17, 2025

An exposure of sensitive information to an unauthorized actor vulnerability in FortiOS version 6.2.4 and below, version 6.0.10 and belowmay allow remote authenticated actors to re…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-6697

Published Mar 17, 2025

An Improper Neutralization of Input vulnerability affecting FortiGate version 6.2.0 through 6.2.1, 6.0.0 through 6.0.6 in the hostname parameter of a DHCP packet under DHCP monito…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-17659

Published Mar 17, 2025

A use of hard-coded cryptographic key vulnerability in FortiSIEM version 5.2.6 may allow a remote unauthenticated attacker to obtain SSH access to the supervisor as the restricted…

CVSS 3.7 · Low
evidence mentions
3
Buzz score
20.4
Vendor/product tagsBeta · best-effort

CVE-2019-15706

Published Mar 17, 2025

An improper neutralization of input during web page generation in the SSL VPN portal of FortiProxy version 2.0.0, version 1.2.9 and below and FortiOS version 6.2.1 and below, vers…

CVSS 4.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-55594

Published Mar 14, 2025

An improper handling of syntactically invalid structure in Fortinet FortiWeb at least vesrions 7.4.0 through 7.4.6 and 7.2.0 through 7.2.10 and 7.0.0 through 7.0.10 allows attacke…

CVSS 5.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-48785

Published Mar 14, 2025

An improper certificate validation vulnerability [CWE-295] in FortiNAC-F version 7.2.4 and below may allow a remote and unauthenticated attacker to perform a Man-in-the-Middle att…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-45588

Published Mar 14, 2025

An external control of file name or path vulnerability [CWE-73] in FortiClientMac version 7.2.3 and below, version 7.0.10 and below installer may allow a local attacker to execut…

CVSS 8.2 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-33300

Published Mar 14, 2025

A improper neutralization of special elements used in a command ('command injection') in Fortinet FortiNAC 7.2.1 and earlier, 9.4.3 and earlier allows attacker a limited, unauthor…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2022-29059

Published Mar 14, 2025

An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] in FortiWeb version 7.0.1 and below, 6.4.2 and below, 6.3.20 and bel…

CVSS 2.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-47573

Published Mar 14, 2025

An improper validation of integrity check value vulnerability [CWE-354] in FortiNDR version 7.4.2 and below, version 7.2.1 and below, version 7.1.1 and below, version 7.0.6 and be…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-40590

Published Mar 14, 2025

An improper certificate validation vulnerability [CWE-295] in FortiPortal version 7.4.0, version 7.2.4 and below, version 7.0.8 and below, version 6.0.15 and below when connecting…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-26006

Published Mar 14, 2025

An improper neutralization of input during web page Generation vulnerability [CWE-79] in FortiOS version 7.4.3 and below, version 7.2.7 and below, version 7.0.13 and below and For…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-55597

Published Mar 11, 2025

A improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiWeb versions 7.0.0 through 7.6.0 allows attacker to execute unauthorized code or…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-55592

Published Mar 11, 2025

An incorrect authorization vulnerability [CWE-863] in FortiSIEM 7.2 all versions, 7.1 all versions, 7.0 all versions, 6.7 all versions, 6.6 all versions, 6.5 all versions, 6.4 all…

CVSS 3.8 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-55590

Published Mar 11, 2025

Multiple improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] in Fortinet FortiIsolator version 2.4.0 through 2.4.5…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-54018

Published Mar 11, 2025

Multiple improper neutralization of special elements used in an OS Command vulnerabilities [CWE-78] in FortiSandbox before 4.4.5 allows a privileged attacker to execute unauthoriz…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2024-52961

Published Mar 11, 2025

An improper neutralization of special elements used in an OS Command vulnerability [CWE-78] vulnerability in Fortinet FortiSandbox 5.0.0, FortiSandbox 4.4.0 through 4.4.6, FortiSa…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 226-250 of 1,135 CVEsPage 10 of 46