Skip to main content

Vendor archive

fortinet CVEs

Beta · best-effort

1,135 CVEs tagged to vendor fortinet92 Critical, 364 High, 603 Medium, 76 Low, 0 Unrated.

CVE-2016-4066

Published Jul 13, 2016

Cross-site request forgery (CSRF) vulnerability in Fortinet FortiWeb before 5.5.3 allows remote attackers to hijack the authentication of administrators for requests that change t…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-3978

Published Apr 8, 2016

The Web User Interface (WebUI) in FortiOS 5.0.x before 5.0.13, 5.2.x before 5.2.3, and 5.4.x before 5.4.0 allows remote attackers to redirect users to arbitrary web sites and cond…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-1909

Published Jan 15, 2016

Fortinet FortiAnalyzer before 5.0.12 and 5.2.x before 5.2.5; FortiSwitch 3.3.x before 3.3.3; FortiCache 3.0.x before 3.0.8; and FortiOS 4.1.x before 4.1.11, 4.2.x before 4.2.16, 4…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2015-7362

Published Jan 8, 2016

Fortinet FortiClient Linux SSLVPN before build 2313, when installed on Linux in a home directory that is world readable and executable, allows local users to gain privileges via t…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2015-8038

Published Nov 2, 2015

Multiple cross-site scripting (XSS) vulnerabilities in the Graphical User Interface (GUI) in Fortinet FortiManager before 5.2.4 allow remote attackers to inject arbitrary web scri…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-8037

Published Nov 2, 2015

Multiple cross-site scripting (XSS) vulnerabilities in the Graphical User Interface (GUI) in Fortinet FortiManager before 5.2.4 allow remote attackers to inject arbitrary web scri…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-7361

Published Oct 15, 2015

FortiOS 5.2.3, when configured to use High Availability (HA) and the dedicated management interface is enabled, does not require authentication for access to the ZebOS shell on th…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2015-5737

Published Sep 3, 2015

The (1) mdare64_48.sys, (2) mdare32_48.sys, (3) mdare32_52.sys, (4) mdare64_52.sys, and (5) Fortishield.sys drivers in Fortinet FortiClient before 5.2.4 do not properly restrict a…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2015-5736

Published Sep 3, 2015

The Fortishield.sys driver in Fortinet FortiClient before 5.2.4 allows local users to execute arbitrary code with kernel privileges by setting the callback function in a (1) 0x220…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2015-5735

Published Sep 3, 2015

The (1) mdare64_48.sys, (2) mdare32_48.sys, (3) mdare32_52.sys, and (4) mdare64_52.sys drivers in Fortinet FortiClient before 5.2.4 allow local users to write to arbitrary memory…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2015-4077

Published Sep 3, 2015

The (1) mdare64_48.sys, (2) mdare32_48.sys, (3) mdare32_52.sys, and (4) mdare64_52.sys drivers in Fortinet FortiClient before 5.2.4 allow local users to read arbitrary kernel memo…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2015-5965

Published Aug 11, 2015

The SSL-VPN feature in Fortinet FortiOS before 4.3.13 only checks the first byte of the TLS MAC in finished messages, which makes it easier for remote attackers to spoof encrypted…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-3626

Published Aug 11, 2015

Cross-site scripting (XSS) vulnerability in the DHCP Monitor page in the Web User Interface (WebUI) in Fortinet FortiOS before 5.2.4 on FortiGate devices allows remote attackers t…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-2323

Published Aug 11, 2015

FortiOS 5.0.x before 5.0.12 and 5.2.x before 5.2.4 supports anonymous, export, RC4, and possibly other weak ciphers when using TLS to connect to FortiGuard servers, which allows m…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-1880

Published May 12, 2015

Cross-site scripting (XSS) vulnerability in the sslvpn login page in Fortinet FortiOS 5.2.x before 5.2.3 allows remote attackers to inject arbitrary web script or HTML via unspeci…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-8619

Published May 12, 2015

Cross-site scripting (XSS) vulnerability in the autolearn configuration page in Fortinet FortiWeb 5.1.2 through 5.3.4 allows remote attackers to inject arbitrary web script or HTM…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-8616

Published May 12, 2015

Multiple cross-site scripting (XSS) vulnerabilities in Fortinet FortiOS 5.2.x before 5.2.3 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors to…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-3293

Published Apr 14, 2015

FortiMail 5.0.3 through 5.2.3 allows remote administrators to obtain credentials via the "diag debug application httpd" command.

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-2281

Published Mar 19, 2015

Stack-based buffer overflow in collectoragent.exe in Fortinet Single Sign On (FSSO) before build 164 allows remote attackers to execute arbitrary code via a large PROCESS_HELLO me…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-8617

Published Mar 4, 2015

Cross-site scripting (XSS) vulnerability in the Web Action Quarantine Release feature in the WebGUI in Fortinet FortiMail before 4.3.9, 5.0.x before 5.0.8, 5.1.x before 5.1.5, and…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-1571

Published Feb 10, 2015

The CAPWAP DTLS protocol implementation in Fortinet FortiOS 5.0 Patch 7 build 4457 uses the same certificate and private key across different customers' installations, which makes…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-1570

Published Feb 10, 2015

The Endpoint Control protocol implementation in Fortinet FortiClient 5.2.3.091 for Android and 5.2.028 for iOS does not validate certificates, which makes it easier for man-in-the…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1,051-1,075 of 1,135 CVEsPage 43 of 46