Skip to main content

Vendor/product archive

fortinet / fortiswitch CVEs

Beta · best-effort

14 CVEs tagged to fortinet / fortiswitch5 Critical, 3 High, 6 Medium, 0 Low, 0 Unrated.

CVE-2024-48887

Published Apr 8, 2025

A unverified password change vulnerability in Fortinet FortiSwitch GUI may allow a remote unauthenticated attacker to change admin passwords via a specially crafted request

CVSS 9.8 · Critical
evidence mentions
4
Buzz score
24.1
Vendor/product tagsBeta · best-effort

CVE-2022-23439

Published Jan 22, 2025

A externally controlled reference to a resource in another sphere vulnerability in Fortinet allows attacker to poison web caches via crafted HTTP requests, where the `Host` heade…

CVSS 4.7 · Medium

CVE-2023-37937

Published Jan 14, 2025

An improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiSwitch version 7.4.0 and 7.2.0 through 7.2.5 and 7.0.0 through 7.0.7…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-37936

Published Jan 14, 2025

A use of hard-coded cryptographic key in Fortinet FortiSwitch version 7.4.0 and 7.2.0 through 7.2.5 and 7.0.0 through 7.0.7 and 6.4.0 through 6.4.13 and 6.2.0 through 6.2.7 and 6.…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2021-42757

Published Dec 8, 2021

A buffer overflow [CWE-121] in the TFTP client library of FortiOS before 6.4.7 and FortiOS 7.0.0 through 7.0.2, may allow an authenticated local attacker to achieve arbitrary code…

CVSS 6.7 · Medium

CVE-2021-26111

Published Jun 1, 2021

A missing release of memory after effective lifetime vulnerability in FortiSwitch 6.4.0 to 6.4.6, 6.2.0 to 6.2.6, 6.0.0 to 6.0.6, 3.6.11 and below may allow an attacker on an adja…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-6909

Published Aug 24, 2016

Buffer overflow in the Cookie parser in Fortinet FortiOS 4.x before 4.1.11, 4.2.x before 4.2.13, and 4.3.x before 4.3.9 and FortiSwitch before 3.4.3 allows remote attackers to exe…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-14 of 14 CVEsPage 1 of 1