VYPR

Fortinet

by Fortinet

CVEs (95)

  • CVE-2022-38380MedNov 2, 2022
    risk 0.30cvss 4.3epss 0.23

    An improper access control [CWE-284] vulnerability in FortiOS version 7.2.0 and versions 7.0.0 through 7.0.7 may allow a remote authenticated read-only user to modify the interface settings via the API.

  • CVE-2021-43080MedSep 6, 2022
    risk 0.30cvss 4.6epss 0.00

    An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiOS version 7.2.0, version 6.4.0 through 6.4.9, version 7.0.0 through 7.0.5 may allow an authenticated attacker to perform a stored cross site scripting (XSS) attack through the URI…

  • CVE-2022-39949MedNov 2, 2022
    risk 0.29cvss 4.4epss 0.00

    An improper control of a resource through its lifetime vulnerability [CWE-664] in FortiEDR CollectorWindows 4.0.0 through 4.1, 5.0.0 through 5.0.3.751, 5.1.0 may allow a privileged user to terminate the FortiEDR processes with special tools and bypass the EDR protection.

  • CVE-2022-23446MedApr 6, 2022
    risk 0.29cvss 4.4epss 0.00

    A improper control of a resource through its lifetime in Fortinet FortiEDR version 5.0.3 and earlier allows attacker to make the whole application unresponsive via changing its root directory access permission.

  • CVE-2022-23442MedAug 3, 2022
    risk 0.28cvss 4.3epss 0.01

    An improper access control vulnerability [CWE-284] in FortiOS versions 6.2.0 through 6.2.11, 6.4.0 through 6.4.8 and 7.0.0 through 7.0.5 may allow an authenticated attacker with a restricted user profile to gather the checksum information about the other VDOMs via CLI commands.

  • CVE-2020-15935MedNov 2, 2021
    risk 0.28cvss 4.3epss 0.01

    A cleartext storage of sensitive information in GUI in FortiADC versions 5.4.3 and below, 6.0.0 and below may allow a remote authenticated attacker to retrieve some sensitive information such as users LDAP passwords and RADIUS shared secret by deobfuscating the passwords entry…

  • CVE-2021-24018MedAug 4, 2021
    risk 0.28cvss 4.3epss 0.01

    A buffer underwrite vulnerability in the firmware verification routine of FortiOS before 7.0.1 may allow an attacker located in the adjacent network to potentially execute arbitrary code via a specifically crafted firmware image.

  • CVE-2021-36169MedDec 13, 2021
    risk 0.27cvss 4.2epss 0.00

    A Hidden Functionality in Fortinet FortiOS 7.x before 7.0.1, FortiOS 6.4.x before 6.4.7 allows attacker to Execute unauthorized code or commands via specific hex read/write operations.

  • CVE-2020-15938MedMar 4, 2021
    risk 0.26cvss 4.0epss 0.01

    When traffic other than HTTP/S (eg: SSH traffic, etc...) traverses the FortiGate in version below 6.2.5 and below 6.4.2 on port 80/443, it is not redirected to the transparent proxy policy for processing, as it doesn't have a valid HTTP header.

  • CVE-2022-30307LowNov 2, 2022
    risk 0.25cvss 3.9epss 0.00

    A key management error vulnerability [CWE-320] affecting the RSA SSH host key in FortiOS 7.2.0 and below, 7.0.6 and below, 6.4.9 and below may allow an unauthenticated attacker to perform a man in the middle attack.

  • CVE-2022-35842LowNov 2, 2022
    risk 0.24cvss 3.7epss 0.01

    An exposure of sensitive information to an unauthorized actor vulnerabiltiy [CWE-200] in FortiOS SSL-VPN versions 7.2.0, versions 7.0.0 through 7.0.6 and versions 6.4.0 through 6.4.9 may allow a remote unauthenticated attacker to gain information about LDAP and SAML settings…

  • CVE-2021-41019LowNov 2, 2021
    risk 0.23cvss 3.5epss 0.01

    An improper validation of certificate with host mismatch [CWE-297] vulnerability in FortiOS versions 6.4.6 and below may allow the connection to a malicious LDAP server via options in GUI, leading to disclosure of sensitive information, such as AD credentials.

  • CVE-2020-15936LowMar 1, 2022
    risk 0.17cvss 2.6epss 0.01

    A improper input validation in Fortinet FortiGate version 6.4.3 and below, version 6.2.5 and below, version 6.0.11 and below, version 5.6.13 and below allows attacker to disclose sensitive information via SNI Client Hello TLS packets.

  • CVE-2022-29053LowSep 6, 2022
    risk 0.15cvss 2.3epss 0.00

    A missing cryptographic steps vulnerability [CWE-325] in the functions that encrypt the keytab files in FortiOS version 7.2.0, 7.0.0 through 7.0.5 and below 7.0.0 may allow an attacker in possession of the encrypted file to decipher it.

  • CVE-2005-3400Nov 1, 2005
    risk 0.00cvss epss 0.01

    Multiple interpretation error in Fortinet 2.48.0.0 allows remote attackers to bypass virus scanning via a file such as BAT, HTML, and EML with an "MZ" magic byte sequence which is normally associated with EXE, which causes the file to be treated as a safe type that could still…

Page 5 of 5