Skip to main content

Vendor archive

fortinet CVEs

Beta · best-effort

1,135 CVEs tagged to vendor fortinet92 Critical, 364 High, 603 Medium, 76 Low, 0 Unrated.

CVE-2017-7733

Published Oct 27, 2017

A Cross-Site-Scripting (XSS) vulnerability in Fortinet FortiOS 5.4.0 to 5.4.5 and 5.6.0 allows a remote unauthenticated attacker to execute arbitrary javascript code via webUI "Lo…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-14182

Published Oct 27, 2017

A Denial of Service (DoS) vulnerability in Fortinet FortiOS 5.4.0 to 5.4.5 allows an authenticated user to cause the web GUI to be temporarily unresponsive, via passing a speciall…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-7732

Published Oct 26, 2017

A reflected Cross-Site Scripting (XSS) vulnerability in Fortinet FortiMail 5.1 and earlier, 5.2.0 through 5.2.9, and 5.3.0 through 5.3.9 customized pre-authentication webmail logi…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-7341

Published Oct 26, 2017

An OS Command Injection vulnerability in Fortinet FortiWLC 6.1-2 through 6.1-5, 7.0-7 through 7.0-10, 8.0 through 8.2, and 8.3.0 through 8.3.2 file management AP script download w…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2017-7335

Published Oct 26, 2017

A Cross-Site Scripting (XSS) vulnerability in Fortinet FortiWLC 6.1-x (6.1-2, 6.1-4 and 6.1-5); 7.0-x (7.0-7, 7.0-8, 7.0-9, 7.0-10); and 8.x (8.0, 8.1, 8.2 and 8.3.0-8.3.2) allows…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-7735

Published Sep 12, 2017

A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.2.0 through 5.2.11 and 5.4.0 through 5.4.4 allows attackers to execute unauthorized code or commands via the "G…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-7734

Published Sep 12, 2017

A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.4.0 through 5.4.4 allows attackers to execute unauthorized code or commands via 'Comments' while saving Config…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-3133

Published Sep 12, 2017

A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.6.0 and earlier allows attackers to execute unauthorized code or commands via the Replacement Message HTML for…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-3132

Published Sep 12, 2017

A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.6.0 and earlier allows attackers to Execute unauthorized code or commands via the action input during the activ…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-3131

Published Sep 12, 2017

A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.4.0 through 5.4.4 and 5.6.0 allows attackers to execute unauthorized code or commands via the filter input in "…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-7737

Published Aug 10, 2017

An information disclosure vulnerability in Fortinet FortiWeb 5.8.2 and below versions allows logged-in admin user to view SNMPv3 user password in cleartext in webui via the HTML s…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-3130

Published Aug 10, 2017

An information disclosure vulnerability in Fortinet FortiOS 5.6.0, 5.4.4 and below versions allows attacker to get FortiOS version info by inspecting FortiOS IKE VendorID packets.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-7336

Published Jul 22, 2017

A hard-coded account named 'upgrade' in Fortinet FortiWLM 8.3.0 and lower versions allows a remote attacker to log-in and execute commands with 'upgrade' account privileges.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-8493

Published Jun 26, 2017

In FortiClientWindows 5.4.1 and 5.4.2, an attacker may escalate privilege via a FortiClientNamedPipe vulnerability.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-3127

Published Jun 1, 2017

A Cross-Site Scripting vulnerability in Fortinet FortiGate 5.2.0 through 5.2.10 allows attacker to execute unauthorized code or commands via the srcintf parameter during Firewall…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-7731

Published May 27, 2017

A weak password recovery vulnerability in Fortinet FortiPortal versions 4.0.0 and below allows attacker to carry out information disclosure via the Forgotten Password feature.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-7343

Published May 27, 2017

An open redirect vulnerability in Fortinet FortiPortal 4.0.0 and below allows attacker to execute unauthorized code or commands via the url parameter.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-7339

Published May 27, 2017

A Cross-Site Scripting vulnerability in Fortinet FortiPortal versions 4.0.0 and below allows an attacker to execute unauthorized code or commands via the 'Name' and 'Description'…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-7338

Published May 27, 2017

A password management vulnerability in Fortinet FortiPortal versions 4.0.0 and below allows an attacker to carry out information disclosure via the FortiAnalyzer Management View.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-7337

Published May 27, 2017

An improper Access Control vulnerability in Fortinet FortiPortal versions 4.0.0 and below allows an attacker to interact with unauthorized VDOMs or enumerate other ADOMs via anoth…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-3134

Published May 27, 2017

An escalation of privilege vulnerability in Fortinet FortiWLC-SD versions 8.2.4 and below allows attacker to gain root access via the CLI command 'copy running-config'.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort
Showing 1,001-1,025 of 1,135 CVEsPage 41 of 46