Skip to main content

Vendor/product archive

fortinet / fortios CVEs

Beta · best-effort

278 CVEs tagged to fortinet / fortios22 Critical, 64 High, 164 Medium, 28 Low, 0 Unrated.

CVE-2021-44171

Published Oct 10, 2022

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiOS version 6.0.0 through 6.0.14, FortiOS version 6.2.0 through 6.2.10…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-29053

Published Sep 6, 2022

A missing cryptographic steps vulnerability [CWE-325] in the functions that encrypt the keytab files in FortiOS version 7.2.0, 7.0.0 through 7.0.5 and below 7.0.0 may allow an att…

CVSS 2.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-27491

Published Sep 6, 2022

A improper verification of source of a communication channel in Fortinet FortiOS with IPS engine version 7.201 through 7.214, 7.001 through 7.113, 6.001 through 6.121, 5.001 throu…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-43080

Published Sep 6, 2022

An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiOS version 7.2.0, version 6.4.0 through 6.4.9, version 7.0.0 through 7.0.5 may allow…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-23442

Published Aug 3, 2022

An improper access control vulnerability [CWE-284] in FortiOS versions 6.2.0 through 6.2.11, 6.4.0 through 6.4.8 and 7.0.0 through 7.0.5 may allow an authenticated attacker with a…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-23438

Published Jul 18, 2022

An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in FortiOS version 7.0.5 and prior and 6.4.9 and prior may allow an…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-44170

Published Jul 18, 2022

A stack-based buffer overflow vulnerability [CWE-121] in the command line interpreter of FortiOS before 7.0.4 and FortiProxy before 2.0.8 may allow an authenticated attacker to ex…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-22306

Published May 24, 2022

An improper certificate validation vulnerability [CWE-295] in FortiOS 6.0.0 through 6.0.14, 6.2.0 through 6.2.10, 6.4.0 through 6.4.8, 7.0.0 may allow a network adjacent and unaut…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-43081

Published May 11, 2022

An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiOS version 7.0.3 and below, 6.4.8 and below, 6.2.10 and below, 6.0.14 to 6.0.0. and i…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-43206

Published May 4, 2022

A server-generated error message containing sensitive information in Fortinet FortiOS 7.0.0 through 7.0.3, 6.4.0 through 6.4.8, 6.2.x, 6.0.x and FortiProxy 7.0.0 through 7.0.1, 2.…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-41032

Published May 4, 2022

An improper access control vulnerability [CWE-284] in FortiOS versions 6.4.8 and prior and 7.0.3 and prior may allow an authenticated attacker with a restricted user profile to ga…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-15936

Published Mar 1, 2022

A improper input validation in Fortinet FortiGate version 6.4.3 and below, version 6.2.5 and below, version 6.0.11 and below, version 5.6.13 and below allows attacker to disclose…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2021-26092

Published Feb 24, 2022

Failure to sanitize input in the SSL VPN web portal of FortiOS 5.2.10 through 5.2.15, 5.4.0 through 5.4.13, 5.6.0 through 5.6.14, 6.0.0 through 6.0.12, 6.2.0 through 6.2.7, 6.4.0…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-44168

Published Jan 4, 2022

A download of code without integrity check vulnerability in the "execute restore src-vis" command of FortiOS before 7.0.3 may allow a local authenticated attacker to download arbi…

CVSS 3.3 · Low
evidence mentions
2
Buzz score
42.5
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2021-36169

Published Dec 13, 2021

A Hidden Functionality in Fortinet FortiOS 7.x before 7.0.1, FortiOS 6.4.x before 6.4.7 allows attacker to Execute unauthorized code or commands via specific hex read/write operat…

CVSS 4.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-36173

Published Dec 8, 2021

A heap-based buffer overflow in the firmware signature verification function of FortiOS versions 7.0.1, 7.0.0, 6.4.0 through 6.4.6, 6.2.0 through 6.2.9, and 6.0.0 through 6.0.13 m…

CVSS 8.0 · High

CVE-2021-41024

Published Dec 8, 2021

A relative path traversal [CWE-23] vulnerabiltiy in FortiOS versions 7.0.0 and 7.0.1 and FortiProxy verison 7.0.0 may allow an unauthenticated, unauthorized attacker to inject pat…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-26109

Published Dec 8, 2021

An integer overflow or wraparound vulnerability in the memory allocator of SSLVPN in FortiOS before 7.0.1 may allow an unauthenticated attacker to corrupt control data on the heap…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2021-26108

Published Dec 8, 2021

A use of hard-coded cryptographic key vulnerability in the SSLVPN of FortiOS before 7.0.1 may allow an attacker to retrieve the key by reverse engineering.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-26103

Published Dec 8, 2021

An insufficient verification of data authenticity vulnerability (CWE-345) in the user interface of FortiProxy verison 2.0.3 and below, 1.2.11 and below and FortiGate verison 7.0.0…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-42757

Published Dec 8, 2021

A buffer overflow [CWE-121] in the TFTP client library of FortiOS before 6.4.7 and FortiOS 7.0.0 through 7.0.2, may allow an authenticated local attacker to achieve arbitrary code…

CVSS 6.7 · Medium

CVE-2021-26110

Published Dec 8, 2021

An improper access control vulnerability [CWE-284] in FortiOS autod daemon 7.0.0, 6.4.6 and below, 6.2.9 and below, 6.0.12 and below and FortiProxy 2.0.1 and below, 1.2.9 and belo…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-32600

Published Nov 17, 2021

An exposure of sensitive information to an unauthorized actor vulnerability in FortiOS CLI 7.0.0, 6.4.0 through 6.4.6, 6.2.0 through 6.2.9, 6.0.x and 5.6.x may allow a local and a…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 176-200 of 278 CVEsPage 8 of 12