Skip to main content

Vendor/product archive

fortinet / fortios CVEs

Beta · best-effort

278 CVEs tagged to fortinet / fortios22 Critical, 64 High, 164 Medium, 28 Low, 0 Unrated.

CVE-2023-22640

Published May 3, 2023

A out-of-bounds write in Fortinet FortiOS version 7.2.0 through 7.2.3, FortiOS version 7.0.0 through 7.0.10, FortiOS version 6.4.0 through 6.4.11, FortiOS version 6.2.0 through 6.…

CVSS 7.5 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2023-22641

Published Apr 11, 2023

A url redirection to untrusted site ('open redirect') in Fortinet FortiOS version 7.2.0 through 7.2.3, FortiOS version 7.0.0 through 7.0.9, FortiOS versions 6.4.0 through 6.4.12,…

CVSS 4.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-43947

Published Apr 11, 2023

An improper restriction of excessive authentication attempts vulnerability [CWE-307] in Fortinet FortiOS version 7.2.0 through 7.2.3 and before 7.0.10, FortiProxy version 7.2.0 th…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-42469

Published Apr 11, 2023

A permissive list of allowed inputs vulnerability [CWE-183] in FortiGate version 7.2.3 and below, version 7.0.9 and below Policy-based NGFW Mode may allow an authenticated SSL-VPN…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-41330

Published Apr 11, 2023

An improper neutralization of input during web page generation vulnerability ('Cross-site Scripting') [CWE-79] in Fortinet FortiOS version 7.2.0 through 7.2.3, version 7.0.0 throu…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2022-45861

Published Mar 7, 2023

An access of uninitialized pointer vulnerability [CWE-824] in the SSL VPN portal of Fortinet FortiOS version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.9 and before 6.4.11 and…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-41329

Published Mar 7, 2023

An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in Fortinet FortiProxy version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.7, FortiOS version 7…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-41328

Published Mar 7, 2023

A improper limitation of a pathname to a restricted directory vulnerability ('path traversal') [CWE-22] in Fortinet FortiOS version 7.2.0 through 7.2.3, 7.0.0 through 7.0.9 and be…

CVSS 6.7 · Medium
evidence mentions
16
Buzz score
67.8
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2022-41334

Published Feb 16, 2023

An improper neutralization of input during web page generation [CWE-79] vulnerability in FortiOS versions 7.0.0 to 7.0.7 and 7.2.0 to 7.2.3 may allow a remote, unauthenticated att…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-39948

Published Feb 16, 2023

An improper certificate validation vulnerability [CWE-295] in FortiOS 7.2.0 through 7.2.3, 7.0.0 through 7.0.7, 6.4 all versions, 6.2 all versions, 6.0 all versions and FortiProxy…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-38378

Published Feb 16, 2023

An improper privilege management vulnerability [CWE-269] in Fortinet FortiOS version 7.2.0 and before 7.0.7 and FortiProxy version 7.2.0 through 7.2.1 and before 7.0.7 allows an a…

CVSS 4.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-29054

Published Feb 16, 2023

A missing cryptographic steps vulnerability [CWE-325] in the functions that encrypt the DHCP and DNS keys in Fortinet FortiOS version 7.2.0, 7.0.0 through 7.0.5, 6.4.0 through 6.4…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-40680

Published Dec 6, 2022

A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiOS 6.0.7 - 6.0.15, 6.2.2 - 6.2.12, 6.4.0 - 6.4.9 and 7.0.0 - 7.0.3 allows a…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-35843

Published Dec 6, 2022

An authentication bypass by assumed-immutable data vulnerability [CWE-302] in the FortiOS SSH login component 7.2.0, 7.0.0 through 7.0.7, 6.4.0 through 6.4.9, 6.2 all versions,…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2022-38380

Published Nov 2, 2022

An improper access control [CWE-284] vulnerability in FortiOS version 7.2.0 and versions 7.0.0 through 7.0.7 may allow a remote authenticated read-only user to modify the interfac…

CVSS 4.3 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2022-35842

Published Nov 2, 2022

An exposure of sensitive information to an unauthorized actor vulnerabiltiy [CWE-200] in FortiOS SSL-VPN versions 7.2.0, versions 7.0.0 through 7.0.6 and versions 6.4.0 through 6.…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-30307

Published Nov 2, 2022

A key management error vulnerability [CWE-320] affecting the RSA SSH host key in FortiOS 7.2.0 and below, 7.0.6 and below, 6.4.9 and below may allow an unauthenticated attacker to…

CVSS 3.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-29055

Published Oct 18, 2022

A access of uninitialized pointer in Fortinet FortiOS version 7.2.0, 7.0.0 through 7.0.5, 6.4.0 through 6.4.8, 6.2.0 through 6.2.10, 6.0.x, FortiProxy version 7.0.0 through 7.0.4,…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 151-175 of 278 CVEsPage 7 of 12