VYPR

Fortios

by Fortinet

CVEs (284)

  • CVE-2024-46666MedJan 14, 2025
    risk 0.35cvss 5.3epss 0.01

    An allocation of resources without limits or throttling [CWE-770] vulnerability in FortiOS versions 7.6.0, versions 7.4.4 through 7.4.0, 7.2 all versions, 7.0 all versions, 6.4 all versions may allow a remote unauthenticated attacker to prevent access to the GUI via specially…

  • CVE-2020-12820MedDec 19, 2024
    risk 0.35cvss 5.4epss 0.01

    Under non-default configuration, a stack-based buffer overflow in FortiOS version 6.0.10 and below, version 5.6.12 and below may allow a remote attacker authenticated to the SSL VPN to crash the FortiClient NAC daemon (fcnacd) and potentially execute arbitrary code via…

  • CVE-2020-12819MedDec 19, 2024
    risk 0.35cvss 5.4epss 0.01

    A heap-based buffer overflow vulnerability in the processing of Link Control Protocol messages in FortiGate versions 5.6.12, 6.0.10, 6.2.4 and 6.4.1 and earlier may allow a remote attacker with valid SSL VPN credentials to crash the SSL VPN daemon by sending a large LCP packet,…

  • CVE-2024-26007MedMay 14, 2024
    risk 0.35cvss 5.3epss 0.01

    An improper check or handling of exceptional conditions vulnerability [CWE-703] in Fortinet FortiOS version 7.4.1 allows an unauthenticated attacker to provoke a denial of service on the administrative interface via crafted HTTP requests.

  • CVE-2024-23662MedApr 9, 2024
    risk 0.35cvss 5.3epss 0.01

    An exposure of sensitive information to an unauthorized actor in Fortinet FortiOS at least version at least 7.4.0 through 7.4.1 and 7.2.0 through 7.2.5 and 7.0.0 through 7.0.15 and 6.4.0 through 6.4.15 allows attacker to information disclosure via HTTP requests.

  • CVE-2023-41675MedOct 10, 2023
    risk 0.35cvss 5.3epss 0.01

    A use after free vulnerability [CWE-416] in FortiOS version 7.2.0 through 7.2.4 and version 7.0.0 through 7.0.10 and FortiProxy version 7.2.0 through 7.2.2 and version 7.0.0 through 7.0.8 may allow an unauthenticated remote attacker to crash the WAD process via multiple crafted…

  • CVE-2022-22305MedSep 1, 2023
    risk 0.35cvss 5.4epss 0.00

    An improper certificate validation vulnerability [CWE-295] in FortiManager 7.0.1 and below, 6.4.6 and below; FortiAnalyzer 7.0.2 and below, 6.4.7 and below; FortiOS 6.2.x and 6.0.x; FortiSandbox 4.0.x, 3.2.x and 3.1.x may allow a network adjacent and unauthenticated attacker…

  • CVE-2022-22306MedMay 24, 2022
    risk 0.35cvss 5.4epss 0.00

    An improper certificate validation vulnerability [CWE-295] in FortiOS 6.0.0 through 6.0.14, 6.2.0 through 6.2.10, 6.4.0 through 6.4.8, 7.0.0 may allow a network adjacent and unauthenticated attacker to man-in-the-middle the communication between the FortiGate and some peers such…

  • CVE-2019-17656MedApr 12, 2021
    risk 0.35cvss 5.4epss 0.02

    A Stack-based Buffer Overflow vulnerability in the HTTPD daemon of FortiOS 6.0.10 and below, 6.2.2 and below and FortiProxy 1.0.x, 1.1.x, 1.2.9 and below, 2.0.0 and below may allow an authenticated remote attacker to crash the service by sending a malformed PUT request to the…

  • CVE-2020-12818MedSep 24, 2020
    risk 0.35cvss 5.3epss 0.01

    An insufficient logging vulnerability in FortiGate before 6.4.1 may allow the traffic from an unauthenticated attacker to Fortinet owned IP addresses to go unnoticed.

  • CVE-2019-17655MedJun 16, 2020
    risk 0.35cvss 5.3epss 0.01

    A cleartext storage in a file or on disk (CWE-313) vulnerability in FortiOS SSL VPN 6.2.0 through 6.2.2, 6.0.9 and earlier and FortiProxy 2.0.0, 1.2.9 and earlier may allow an attacker to retrieve a logged-in SSL VPN user's credentials should that attacker be able to read the…

  • CVE-2018-13367MedAug 23, 2019
    risk 0.35cvss 5.3epss 0.01

    An information exposure vulnerability in FortiOS 6.2.3, 6.2.0 and below may allow an unauthenticated attacker to gain platform information such as version, models, via parsing a JavaScript file through admin webUI.

  • CVE-2018-13381MedJun 4, 2019
    risk 0.35cvss 5.3epss 0.02

    A buffer overflow vulnerability in Fortinet FortiOS 6.0.0 through 6.0.4, 5.6.0 through 5.6.7, 5.4 and earlier versions and FortiProxy 2.0.0, 1.2.8 and earlier versions under SSL VPN web portal allows a non-authenticated attacker to perform a Denial-of-service attack via special…

  • CVE-2018-13365MedMay 29, 2019
    risk 0.35cvss 5.3epss 0.01

    An Information Exposure vulnerability in Fortinet FortiOS 6.0.1, 5.6.5 and below, allow attackers to learn private IP as well as the hostname of FortiGate via Application Control Block page.

  • CVE-2018-13366MedApr 9, 2019
    risk 0.35cvss 5.3epss 0.01

    An information disclosure vulnerability in Fortinet FortiOS 6.0.1, 5.6.7 and below allows attacker to reveals serial number of FortiGate via hostname field defined in connection control setup packets of PPTP protocol.

  • CVE-2017-14185MedMay 25, 2018
    risk 0.35cvss 5.3epss 0.01

    An Information Disclosure vulnerability in Fortinet FortiOS 5.6.0 to 5.6.2, 5.4.0 to 5.4.8 and 5.2 all versions allows SSL VPN web portal users to access internal FortiOS configuration information (eg:addresses) via specifically crafted URLs inside the SSL-VPN web portal.

  • CVE-2017-14186MedNov 29, 2017
    risk 0.35cvss 5.4epss 0.04

    A Cross-site Scripting (XSS) vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.7, 5.4 and below versions under SSL VPN web portal allows a remote user to inject arbitrary web script or HTML in the context of the victim's browser via the login redir parameter. An URL…

  • CVE-2017-7735MedSep 12, 2017
    risk 0.35cvss 5.4epss 0.01

    A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.2.0 through 5.2.11 and 5.4.0 through 5.4.4 allows attackers to execute unauthorized code or commands via the "Groups" input while creating or editing User Groups.

  • CVE-2017-7734MedSep 12, 2017
    risk 0.35cvss 5.4epss 0.01

    A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.4.0 through 5.4.4 allows attackers to execute unauthorized code or commands via 'Comments' while saving Config Revisions.

  • CVE-2026-71408MedAug 12, 2026
    risk 0.34cvss 5.3epss 0.01

    A allocation of resources without limits or throttling vulnerability in Fortinet FortiOS 7.6.0 through 7.6.6, FortiOS 7.4 all versions, FortiOS 7.2 all versions may allow attacker to denial of service via

Page 9 of 15