Skip to main content

Vendor archive

fortinet CVEs

Beta · best-effort

1,135 CVEs tagged to vendor fortinet92 Critical, 364 High, 603 Medium, 76 Low, 0 Unrated.

CVE-2018-9192

Published Sep 5, 2018

A plaintext recovery of encrypted messages or a Man-in-the-middle (MiTM) attack on RSA PKCS #1 v1.5 encryption may be possible without knowledge of the server's private key. Forti…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1353

Published Sep 5, 2018

An information disclosure vulnerability in Fortinet FortiManager 6.0.1 and below versions allows a standard user with adom assignment read the interface settings of vdoms unrelate…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-9185

Published Jul 5, 2018

An information disclosure vulnerability in Fortinet FortiOS 6.0.0 and below versions reveals user's web portal login credentials in a Javascript file sent to client-side when page…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2018-1351

Published Jun 28, 2018

A Cross-site Scripting (XSS) vulnerability in Fortinet FortiManager 6.0.0, 5.6.6 and below versions allows attacker to execute HTML/javascript code via managed remote devices CLI…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-9186

Published May 31, 2018

A cross-site scripting (XSS) vulnerability in Fortinet FortiAuthenticator in versions 4.0.0 to before 5.3.0 "CSRF validation failure" page allows attacker to execute unauthorized…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-14185

Published May 25, 2018

An Information Disclosure vulnerability in Fortinet FortiOS 5.6.0 to 5.6.2, 5.4.0 to 5.4.8 and 5.2 all versions allows SSL VPN web portal users to access internal FortiOS configur…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-14187

Published May 24, 2018

A local privilege escalation and local code execution vulnerability in Fortinet FortiOS 5.6.0 to 5.6.2, 5.4.0 to 5.4.8, and 5.2 and below versions allows attacker to execute unaut…

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-17540

Published May 8, 2018

The presence of a hardcoded account in Fortinet FortiWLC 8.3.3 allows attackers to gain unauthorized read/write access via a remote shell.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-17539

Published May 8, 2018

The presence of a hardcoded account in Fortinet FortiWLC 7.0.11 and earlier allows attackers to gain unauthorized read/write access via a remote shell.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-14191

Published Mar 20, 2018

An Improper Access Control vulnerability in Fortinet FortiWeb 5.6.0 up to but not including 6.1.0 under "Signed Security Mode", allows attacker to bypass the signed user cookie pr…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-6347

Published Feb 9, 2018

Multiple cross-site scripting (XSS) vulnerabilities in Java number format exception handling in FortiGate FortiDB before 4.4.2 allow remote attackers to inject arbitrary web scrip…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-6346

Published Feb 9, 2018

Multiple cross-site scripting (XSS) vulnerabilities in FortiWeb before 4.4.4 allow remote attackers to inject arbitrary web script or HTML via the (1) redir or (2) mkey parameter…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-0941

Published Feb 8, 2018

Multiple cross-site scripting (XSS) vulnerabilities in Fortinet FortiGate UTM WAF appliances with FortiOS 4.3.x before 4.3.6 allow remote attackers to inject arbitrary web script…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-14190

Published Jan 29, 2018

A Cross-site Scripting vulnerability in Fortinet FortiOS 5.6.0 to 5.6.2, 5.4.0 to 5.4.7, 5.2 and earlier, allows attacker to inject arbitrary web script or HTML via maliciously cr…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-7344

Published Dec 14, 2017

A privilege escalation in Fortinet FortiClient Windows 5.4.3 and earlier as well as 5.6.0 allows attacker to gain privilege via exploiting the Windows "security alert" dialog ther…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2017-7738

Published Dec 13, 2017

An Information Disclosure vulnerability in Fortinet FortiOS 5.6.0 to 5.6.2, 5.4.0 to 5.4.5, 5.2 and below versions allow an admin user with super_admin privileges to view the curr…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2017-14189

Published Nov 29, 2017

An improper access control vulnerability in Fortinet FortiWebManager 5.8.0 allows anyone that can access the admin webUI to successfully log-in regardless the provided password.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-14186

Published Nov 29, 2017

A Cross-site Scripting (XSS) vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.7, 5.4 and below versions under SSL VPN web portal allows a remote user to inject arbit…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-7736

Published Nov 22, 2017

A stored Cross-site Scripting (XSS) vulnerability in Fortinet FortiWeb webUI Certificate View page in 5.8.0, 5.7.1 and earlier, allows attackers to inject arbitrary web script or…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-7739

Published Nov 13, 2017

A reflected Cross-site Scripting (XSS) vulnerability in web proxy disclaimer response web pages in Fortinet FortiOS 5.6.0, 5.4.0 to 5.4.5, 5.2.0 to 5.2.11 allows an unauthenticate…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 976-1,000 of 1,135 CVEsPage 40 of 46