Skip to main content

Vendor/product archive

fortinet / fortiwan CVEs

Beta · best-effort

16 CVEs tagged to fortinet / fortiwan2 Critical, 8 High, 6 Medium, 0 Low, 0 Unrated.

CVE-2021-26102

Published Dec 19, 2024

A relative path traversal vulnerability (CWE-23) in FortiWAN version 4.5.7 and below, 4.4 all versions may allow a remote non-authenticated attacker to delete files on the system…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-26115

Published Dec 19, 2024

An OS command injection (CWE-78) vulnerability in FortiWAN version 4.5.7 and below Command Line Interface may allow a local, authenticated and unprivileged attacker to escalate th…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-44252

Published Dec 13, 2023

** UNSUPPORTED WHEN ASSIGNED **An improper authentication vulnerability [CWE-287] in Fortinet FortiWAN version 5.2.0 through 5.2.1 and version 5.1.1 through 5.1.2 may allow an aut…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-44251

Published Dec 13, 2023

** UNSUPPORTED WHEN ASSIGNED **A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability [CWE-22] in Fortinet FortiWAN version 5.2.0 through 5…

CVSS 8.3 · High
Vendor/product tagsBeta · best-effort

CVE-2022-33869

Published Feb 16, 2023

An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in the management interface of FortiWAN 4.0.0 through 4.5.9 may allow an authenticated…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-32585

Published Apr 6, 2022

An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiWAN before 4.5.9 may allow an attacker to perform a stored cross-site scripting attac…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2021-26113

Published Apr 6, 2022

A use of a one-way hash with a predictable salt vulnerability [CWE-760] in FortiWAN before 4.5.9 may allow an attacker who has previously come in possession of the password file t…

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-32593

Published Apr 6, 2022

A use of a broken or risky cryptographic algorithm vulnerability [CWE-327] in the Dynamic Tunnel Protocol of FortiWAN before 4.5.9 may allow an unauthenticated remote attacker to…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-26114

Published Apr 6, 2022

Multiple improper neutralization of special elements used in an SQL command vulnerabilities in FortiWAN before 4.5.9 may allow an unauthenticated attacker to execute unauthorized…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-26112

Published Apr 6, 2022

Multiple stack-based buffer overflow vulnerabilities [CWE-121] both in network daemons and in the command line interpreter of FortiWAN before 4.5.9 may allow an unauthenticated at…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2021-24009

Published Apr 6, 2022

Multiple improper neutralization of special elements used in an OS command vulnerabilities (CWE-78) in the Web GUI of FortiWAN before 4.5.9 may allow an authenticated attacker to…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2016-4969

Published Sep 21, 2016

Cross-site scripting (XSS) vulnerability in Fortinet FortiWan (formerly AscernLink) before 4.2.5 allows remote attackers to inject arbitrary web script or HTML via the IP paramete…

CVSS 6.1 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2016-4968

Published Sep 21, 2016

The linkreport/tmp/admin_global page in Fortinet FortiWan (formerly AscernLink) before 4.2.5 allows remote authenticated users to discover administrator cookies via a GET request.

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2016-4967

Published Sep 21, 2016

Fortinet FortiWan (formerly AscernLink) before 4.2.5 allows remote authenticated users to obtain sensitive information from (1) a backup of the device configuration via script/cfg…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2016-4966

Published Sep 21, 2016

The diagnosis_control.php page in Fortinet FortiWan (formerly AscernLink) before 4.2.5 allows remote authenticated users to download PCAP files via vectors related to the UserName…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2016-4965

Published Sep 21, 2016

Fortinet FortiWan (formerly AscernLink) before 4.2.5 allows remote authenticated users with access to the nslookup functionality to execute arbitrary commands with root privileges…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 1-16 of 16 CVEsPage 1 of 1