Skip to main content

Vendor archive

fortinet CVEs

Beta · best-effort

1,135 CVEs tagged to vendor fortinet92 Critical, 364 High, 603 Medium, 76 Low, 0 Unrated.

CVE-2019-5586

Published Jun 4, 2019

A reflected Cross-Site-Scripting (XSS) vulnerability in Fortinet FortiOS 5.2.0 to 5.6.10, 6.0.0 to 6.0.4 under SSL VPN web portal may allow an attacker to execute unauthorized mal…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-13384

Published Jun 4, 2019

A Host Header Redirection vulnerability in Fortinet FortiOS all versions below 6.0.5 under SSL VPN web portal allows a remote attacker to potentially poison HTTP cache and subsequ…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-13382

Published Jun 4, 2019

An Improper Authorization vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.8 and 5.4.1 to 5.4.10 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 to 1.1.6, 1.0.0 to 1.0.7…

CVSS 9.1 · Critical
evidence mentions
9
Buzz score
56.0
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2018-13381

Published Jun 4, 2019

A buffer overflow vulnerability in Fortinet FortiOS 6.0.0 through 6.0.4, 5.6.0 through 5.6.7, 5.4 and earlier versions and FortiProxy 2.0.0, 1.2.8 and earlier versions under SSL V…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-13380

Published Jun 4, 2019

A Cross-site Scripting (XSS) vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.7, 5.4.0 to 5.4.12, 5.2 and below and Fortinet FortiProxy 2.0.0, 1.2.8 and below under…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-13379

Published Jun 4, 2019

An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.3 to 5.6.7 and 5.4.6 to 5.4.12 and FortiProxy 2.0.0, 1.2.…

CVSS 9.1 · Critical
evidence mentions
84
Buzz score
82.5
KEV listedPublic PoC observed
Vendor/product tagsBeta · best-effort

CVE-2018-9193

Published May 30, 2019

A researcher has disclosed several vulnerabilities against FortiClient for Windows version 6.0.5 and below, version 5.6.6, the combination of these vulnerabilities can turn into a…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-9191

Published May 30, 2019

A local privilege escalation in Fortinet FortiClient for Windows 6.0.4 and earlier allows attackers to execute unauthorized code or commands via the named pipe responsible for For…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-13368

Published May 30, 2019

A local privilege escalation in Fortinet FortiClient for Windows 6.0.4 and earlier allows attacker to execute unauthorized code or commands via the command injection.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-13365

Published May 29, 2019

An Information Exposure vulnerability in Fortinet FortiOS 6.0.1, 5.6.5 and below, allow attackers to learn private IP as well as the hostname of FortiGate via Application Control…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-13383

Published May 29, 2019

A heap buffer overflow in Fortinet FortiOS 6.0.0 through 6.0.4, 5.6.0 through 5.6.10, 5.4.0 through 5.4.12, 5.2.14 and earlier and FortiProxy 2.0.0, 1.2.8 and earlier in the SSL V…

CVSS 4.3 · Medium
evidence mentions
5
Buzz score
50.9
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2019-5589

Published May 28, 2019

An Unsafe Search Path vulnerability in FortiClient Online Installer (Windows version before 6.0.6) may allow an unauthenticated, remote attacker with control over the directory in…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-1360

Published Apr 25, 2019

A cleartext transmission of sensitive information vulnerability in Fortinet FortiManager 5.2.0 through 5.2.7, 5.4.0 and 5.4.1 may allow an unauthenticated attacker in a man in the…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2018-13378

Published Apr 17, 2019

An information disclosure vulnerability in Fortinet FortiSIEM 5.2.0 and below versions exposes the LDAP server plaintext password via the HTML source code.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2018-1356

Published Apr 9, 2019

A reflected Cross-Site-Scripting (XSS) vulnerability in Fortinet FortiSandbox before 3.0 may allow an attacker to execute unauthorized code or commands via the back_url parameter…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-13366

Published Apr 9, 2019

An information disclosure vulnerability in Fortinet FortiOS 6.0.1, 5.6.7 and below allows attacker to reveals serial number of FortiGate via hostname field defined in connection c…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-17544

Published Apr 9, 2019

A privilege escalation vulnerability in Fortinet FortiOS 6.0.0 to 6.0.6, 5.6.0 to 5.6.10, 5.4 and below allows admin users to elevate their profile to super_admin via restoring mo…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2017-7342

Published Mar 25, 2019

A weak password recovery process vulnerability in Fortinet FortiPortal versions 4.0.0 and below allows an attacker to execute unauthorized code or commands via a hidden Close butt…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-7340

Published Mar 25, 2019

A Cross-Site Scripting vulnerability in Fortinet FortiPortal versions 4.0.0 and below allows an attacker to execute unauthorized code or commands via the applicationSearch paramet…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-9190

Published Feb 8, 2019

A null pointer dereference vulnerability in Fortinet FortiClientWindows 6.0.2 and earlier allows attacker to cause a denial of service via the NDIS miniport driver.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1352

Published Feb 8, 2019

A format string vulnerability in Fortinet FortiOS 5.6.0 allows attacker to execute unauthorized code or commands via the SSH username variable.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-13374

Published Jan 22, 2019

A Improper Access Control in Fortinet FortiOS 6.0.2, 5.6.7 and before, FortiADC 6.1.0, 6.0.0 to 6.0.1, 5.4.0 to 5.4.4 allows attacker to obtain the LDAP server login credentials c…

CVSS 4.3 · Medium
evidence mentions
3
Buzz score
53.9
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2018-13376

Published Nov 27, 2018

An uninitialized memory buffer leak exists in Fortinet FortiOS 5.6.1 to 5.6.3, 5.4.6 to 5.4.7, 5.2 all versions under web proxy's disclaimer response web pages, potentially causin…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-9194

Published Sep 5, 2018

A plaintext recovery of encrypted messages or a Man-in-the-middle (MiTM) attack on RSA PKCS #1 v1.5 encryption may be possible without knowledge of the server's private key. Forti…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort
Showing 951-975 of 1,135 CVEsPage 39 of 46