Skip to main content

Vendor/product archive

fortinet / fortios CVEs

Beta · best-effort

278 CVEs tagged to fortinet / fortios22 Critical, 64 High, 164 Medium, 28 Low, 0 Unrated.

CVE-2023-28002

Published Nov 14, 2023

An improper validation of integrity check value vulnerability [CWE-354] in FortiOS 7.2.0 through 7.2.3, 7.0.0 through 7.0.12, 6.4 all versions, 6.2 all versions, 6.0 all versions…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-41841

Published Oct 10, 2023

An improper authorization vulnerability in Fortinet FortiOS 7.0.0 - 7.0.11 and 7.2.0 - 7.2.4 allows an attacker belonging to the prof-admin profile to perform elevated actions.

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2023-41675

Published Oct 10, 2023

A use after free vulnerability [CWE-416] in FortiOS version 7.2.0 through 7.2.4 and version 7.0.0 through 7.0.10 and FortiProxy version 7.2.0 through 7.2.2 and version 7.0.0 throu…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-37935

Published Oct 10, 2023

A use of GET request method with sensitive query strings vulnerability in Fortinet FortiOS 7.0.0 - 7.0.12, 7.2.0 - 7.2.5 and 7.4.0 allows an attacker to view plaintext passwords o…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-36555

Published Oct 10, 2023

An improper neutralization of script-related html tags in a web page (basic xss) in Fortinet FortiOS 7.2.0 - 7.2.4 allows an attacker to execute unauthorized code or commands via…

CVSS 3.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-33301

Published Oct 10, 2023

An improper access control vulnerability in Fortinet FortiOS 7.2.0 - 7.2.4 and 7.4.0 allows an attacker to access a restricted resource from a non trusted host.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-29183

Published Sep 13, 2023

An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiProxy 7.2.0 through 7.2.4, 7.0.0 through 7.0.10 and FortiOS…

CVSS 8.0 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-29182

Published Aug 17, 2023

A stack-based buffer overflow vulnerability [CWE-121] in Fortinet FortiOS before 7.0.3 allows a privileged attacker to execute arbitrary code via specially crafted CLI commands, p…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-33308

Published Jul 26, 2023

A stack-based overflow vulnerability [CWE-124] in Fortinet FortiOS version 7.0.0 through 7.0.10 and 7.2.0 through 7.2.3 and FortiProxy version 7.0.0 through 7.0.9 and 7.2.0 throug…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2023-28001

Published Jul 11, 2023

An insufficient session expiration in Fortinet FortiOS 7.0.0 - 7.0.12 and 7.2.0 - 7.2.4 allows an attacker to execute unauthorized code or commands via reusing the session of a de…

CVSS 4.1 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-33307

Published Jun 16, 2023

A null pointer dereference in Fortinet FortiOS before 7.2.5 and before 7.0.11, FortiProxy before 7.2.3 and before 7.0.9 allows attacker to denial of sslvpn service via specificall…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-33306

Published Jun 16, 2023

A null pointer dereference in Fortinet FortiOS before 7.2.5, before 7.0.11 and before 6.4.13, FortiProxy before 7.2.4 and before 7.0.10 allows attacker to denial of sslvpn servic…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-29178

Published Jun 13, 2023

A access of uninitialized pointer vulnerability [CWE-824] in Fortinet FortiProxy version 7.2.0 through 7.2.3 and before 7.0.9 and FortiOS version 7.2.0 through 7.2.4 and before 7…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-29175

Published Jun 13, 2023

An improper certificate validation vulnerability [CWE-295] in FortiOS 6.2 all versions, 6.4 all versions, 7.0.0 through 7.0.10, 7.2.0 and FortiProxy 1.2 all versions, 2.0 all vers…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-26207

Published Jun 13, 2023

An insertion of sensitive information into log file vulnerability in Fortinet FortiOS 7.2.0 through 7.2.4 and FortiProxy 7.0.0 through 7.0.10. 7.2.0 through 7.2.1 allows an attack…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-22639

Published Jun 13, 2023

A out-of-bounds write in Fortinet FortiOS version 7.2.0 through 7.2.3, FortiOS version 7.0.0 through 7.0.10, FortiOS version 6.4.0 through 6.4.12, FortiOS all versions 6.2, FortiO…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-43953

Published Jun 13, 2023

A use of externally-controlled format string in Fortinet FortiOS version 7.2.0 through 7.2.4, FortiOS all versions 7.0, FortiOS all versions 6.4, FortiOS all versions 6.2, FortiPr…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-41327

Published Jun 13, 2023

A cleartext transmission of sensitive information vulnerability [CWE-319] in Fortinet FortiOS version 7.2.0 through 7.2.4, 7.0.0 through 7.0.8, FortiProxy version 7.2.0 through 7.…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort
Showing 126-150 of 278 CVEsPage 6 of 12