VYPR

FortiWebManager

by Fortinet

CVEs (6)

  • CVE-2017-14189CriNov 29, 2017
    risk 0.64cvss 9.8epss 0.03

    An improper access control vulnerability in Fortinet FortiWebManager 5.8.0 allows anyone that can access the admin webUI to successfully log-in regardless the provided password.

  • CVE-2024-23668HigJun 3, 2024
    risk 0.57cvss 8.8epss 0.01

    An improper authorization in Fortinet FortiWebManager 7.2.0, FortiWebManager 7.0.0 through 7.0.4, FortiWebManager 6.3.0, FortiWebManager 6.2.3 through 6.2.4, FortiWebManager 6.0.2 allows attacker to execute unauthorized code or commands via HTTP requests or CLI.

  • CVE-2024-23670HigJun 3, 2024
    risk 0.51cvss 7.8epss 0.00

    An improper authorization in Fortinet FortiWebManager 7.2.0, FortiWebManager 7.0.0 through 7.0.4, FortiWebManager 6.3.0, FortiWebManager 6.2.3 through 6.2.4, FortiWebManager 6.0.2 allows attacker to execute unauthorized code or commands via HTTP requests or CLI.

  • CVE-2024-23667HigJun 3, 2024
    risk 0.51cvss 7.8epss 0.00

    An improper authorization in Fortinet FortiWebManager 7.2.0, FortiWebManager 7.0.0 through 7.0.4, FortiWebManager 6.3.0, FortiWebManager 6.2.3 through 6.2.4, FortiWebManager 6.0.2 allows attacker to execute unauthorized code or commands via HTTP requests or CLI.

  • CVE-2024-23669MedJun 5, 2024
    risk 0.42cvss 6.5epss 0.01

    An improper authorization in Fortinet FortiWebManager 7.2.0, FortiWebManager 7.0.0 through 7.0.4, FortiWebManager 6.3.0, FortiWebManager 6.2.3 through 6.2.4, FortiWebManager 6.0.2 allows attacker to execute unauthorized code or commands via HTTP requests or CLI.

  • CVE-2021-36175MedOct 6, 2021
    risk 0.27cvss 4.1epss 0.01

    An improper neutralization of input vulnerability [CWE-79] in FortiWebManager versions 6.2.3 and below, 6.0.2 and below may allow a remote authenticated attacker to inject malicious script/tags via the name/description/comments parameter of various sections of the device.