VYPR

Fortinet

by Fortinet

CVEs (95)

  • CVE-2017-7733MedOct 27, 2017
    risk 0.40cvss 6.1epss 0.01

    A Cross-Site-Scripting (XSS) vulnerability in Fortinet FortiOS 5.4.0 to 5.4.5 and 5.6.0 allows a remote unauthenticated attacker to execute arbitrary javascript code via webUI "Login Disclaimer" redir parameter.

  • CVE-2022-38381MedNov 2, 2022
    risk 0.35cvss 5.3epss 0.01

    An improper handling of malformed request vulnerability [CWE-228] exists in FortiADC 5.0 all versions, 6.0.0 all versions, 6.1.0 all versions, 6.2.0 through 6.2.3, and 7.0.0 through 7.0.2. This may allow a remote attacker without privileges to bypass some Web Application…

  • CVE-2022-27484MedAug 3, 2022
    risk 0.35cvss 5.4epss 0.00

    A unverified password change in Fortinet FortiADC version 6.2.0 through 6.2.3, 6.1.x, 6.0.x, 5.x.x allows an authenticated attacker to bypass the Old Password check in the password change form via a crafted HTTP request.

  • CVE-2022-29057MedJul 19, 2022
    risk 0.35cvss 5.4epss 0.01

    A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiEDR version 5.1.0, 5.0.0 through 5.0.3 Patch 6 and 4.0.0 allows a remote authenticated attacker to perform a reflected cross site scripting attack (XSS) by injecting malicious…

  • CVE-2022-26120MedJul 18, 2022
    risk 0.35cvss 5.4epss 0.01

    Multiple improper neutralization of special elements used in an SQL Command ('SQL Injection') vulnerabilities [CWE-89] in FortiADC management interface 7.0.0 through 7.0.1, 5.0.0 through 6.2.2 may allow an authenticated attacker to execute unauthorized code or commands via…

  • CVE-2022-22306MedMay 24, 2022
    risk 0.35cvss 5.4epss 0.00

    An improper certificate validation vulnerability [CWE-295] in FortiOS 6.0.0 through 6.0.14, 6.2.0 through 6.2.10, 6.4.0 through 6.4.8, 7.0.0 may allow a network adjacent and unauthenticated attacker to man-in-the-middle the communication between the FortiGate and some peers such…

  • CVE-2021-43070MedMar 2, 2022
    risk 0.35cvss 5.4epss 0.01

    Multiple relative path traversal vulnerabilities [CWE-23] in FortiWLM management interface 8.6.2 and below, 8.5.2 and below, 8.4.2 and below, 8.3.3 and below, 8.2.2 may allow an authenticated attacker to retrieve arbitrary files from the underlying filesystem via specially…

  • CVE-2021-42752MedDec 8, 2021
    risk 0.35cvss 5.4epss 0.01

    A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiWLM version 8.6.1 and below allows attacker to execute malicious javascript code on victim's host via crafted HTTP requests

  • CVE-2020-12815MedSep 24, 2020
    risk 0.35cvss 5.4epss 0.01

    An improper neutralization of input vulnerability in FortiTester before 3.9.0 may allow a remote authenticated attacker to inject script related HTML tags via IPv4/IPv6 address fields.

  • CVE-2020-12818MedSep 24, 2020
    risk 0.35cvss 5.3epss 0.01

    An insufficient logging vulnerability in FortiGate before 6.4.1 may allow the traffic from an unauthenticated attacker to Fortinet owned IP addresses to go unnoticed.

  • CVE-2020-9288MedJun 22, 2020
    risk 0.35cvss 5.4epss 0.01

    An improper neutralization of input vulnerability in FortiWLC 8.5.1 allows a remote authenticated attacker to perform a stored cross site scripting attack (XSS) via the ESS profile or the Radius Profile.

  • CVE-2019-6699MedMar 13, 2020
    risk 0.35cvss 5.4epss 0.01

    An improper neutralization of input vulnerability in Fortinet FortiADC 5.3.3 and earlier may allow an attacker to execute a stored Cross Site Scripting (XSS) via a field in the traffic group interface.

  • CVE-2018-13365MedMay 29, 2019
    risk 0.35cvss 5.3epss 0.01

    An Information Exposure vulnerability in Fortinet FortiOS 6.0.1, 5.6.5 and below, allow attackers to learn private IP as well as the hostname of FortiGate via Application Control Block page.

  • CVE-2018-13366MedApr 9, 2019
    risk 0.35cvss 5.3epss 0.01

    An information disclosure vulnerability in Fortinet FortiOS 6.0.1, 5.6.7 and below allows attacker to reveals serial number of FortiGate via hostname field defined in connection control setup packets of PPTP protocol.

  • CVE-2021-44168LowKEVJan 4, 2022
    risk 0.34cvss 3.3epss 0.01

    A download of code without integrity check vulnerability in the "execute restore src-vis" command of FortiOS before 7.0.3 may allow a local authenticated attacker to download arbitrary files on the device via specially crafted update packages.

  • CVE-2021-32600MedNov 17, 2021
    risk 0.33cvss 5.0epss 0.01

    An exposure of sensitive information to an unauthorized actor vulnerability in FortiOS CLI 7.0.0, 6.4.0 through 6.4.6, 6.2.0 through 6.2.9, 6.0.x and 5.6.x may allow a local and authenticated user assigned to a specific VDOM to retrieve other VDOMs information such as the admin…

  • CVE-2022-23439MedJan 22, 2025
    risk 0.31cvss 4.7epss 0.00

    A externally controlled reference to a resource in another sphere vulnerability in Fortinet allows attacker to poison web caches via crafted HTTP requests, where the `Host` header points to an arbitrary webserver

  • CVE-2022-23438MedJul 18, 2022
    risk 0.31cvss 4.7epss 0.01

    An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in FortiOS version 7.0.5 and prior and 6.4.9 and prior may allow an unauthenticated remote attacker to perform a reflected cross site scripting (XSS) attack in the…

  • CVE-2020-15937MedMar 3, 2021
    risk 0.31cvss 4.7epss 0.01

    An improper neutralization of input vulnerability in FortiGate version 6.2.x below 6.2.5 and 6.4.x below 6.4.1 may allow a remote attacker to perform a stored cross site scripting attack (XSS) via the IPS and WAF logs dashboard.

  • CVE-2017-3128MedMay 23, 2017
    risk 0.31cvss 4.8epss 0.01

    A stored XSS (Cross-Site-Scripting) vulnerability in Fortinet FortiOS allows attackers to execute unauthorized code or commands via the policy global-label parameter.

Page 4 of 5