Skip to main content

Vendor archive

fortinet CVEs

Beta · best-effort

1,135 CVEs tagged to vendor fortinet92 Critical, 364 High, 603 Medium, 76 Low, 0 Unrated.

CVE-2015-1569

Published Feb 10, 2015

Fortinet FortiClient 5.2.028 for iOS does not validate certificates, which makes it easier for man-in-the-middle attackers to spoof SSL VPN servers via a crafted certificate.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-1459

Published Feb 3, 2015

Cross-site scripting (XSS) vulnerability in Fortinet FortiAuthenticator 3.0.0 allows remote attackers to inject arbitrary web script or HTML via the operation parameter to cert/sc…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-1458

Published Feb 3, 2015

Fortinet FortiAuthenticator 3.0.0 allows local users to bypass intended restrictions and gain privileges by creating /tmp/privexec/dbgcore_enable_shell_access and executing the "s…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-1456

Published Feb 3, 2015

Fortinet FortiAuthenticator 3.0.0 logs the PostgreSQL usernames and passwords in cleartext, which allows remote administrators to obtain sensitive information by reading the log a…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-1455

Published Feb 3, 2015

Fortinet FortiAuthenticator 3.0.0 has a password of (1) slony for the slony PostgreSQL user and (2) www-data for the www-data PostgreSQL user, which makes it easier for remote att…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2015-1453

Published Feb 2, 2015

The qm class in Fortinet FortiClient 5.2.3.091 for Android uses a hardcoded encryption key of FoRtInEt!AnDrOiD, which makes it easier for attackers to obtain passwords and possibl…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-1452

Published Feb 2, 2015

The Control and Provisioning of Wireless Access Points (CAPWAP) daemon in Fortinet FortiOS 5.0 Patch 7 build 4457 allows remote attackers to cause a denial of service (locked CAPW…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2015-1451

Published Feb 2, 2015

Multiple cross-site scripting (XSS) vulnerabilities in Fortinet FortiOS 5.0 Patch 7 build 4457 allow remote authenticated users to inject arbitrary web script or HTML via the (1)…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2014-2335

Published Oct 31, 2014

Multiple cross-site scripting (XSS) vulnerabilities in the Web User Interface in Fortinet FortiManager before 5.0.7 allow remote attackers to inject arbitrary web script or HTML v…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-2334

Published Oct 31, 2014

Multiple cross-site scripting (XSS) vulnerabilities in the Web User Interface in Fortinet FortiAnalyzer before 5.0.7 allow remote attackers to inject arbitrary web script or HTML…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-0351

Published Sep 10, 2014

The FortiManager protocol service in Fortinet FortiOS before 4.3.16 and 5.x before 5.0.8 on FortiGate devices does not prevent use of anonymous ciphersuites, which makes it easier…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-2216

Published Aug 25, 2014

The FortiManager protocol service in Fortinet FortiOS before 4.3.16 and 5.0.0 before 5.0.8 on FortiGate devices allows remote attackers to cause a denial of service and possibly e…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-4738

Published Jul 11, 2014

Multiple cross-site scripting (XSS) vulnerabilities in FortiGuard FortiWeb 5.0.x, 5.1.x, and 5.2.x before 5.2.1 allow remote attackers to inject arbitrary web script or HTML via u…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-3115

Published May 8, 2014

Multiple cross-site request forgery (CSRF) vulnerabilities in the web administration console in Fortinet FortiWeb before 5.2.0 allow remote attackers to hijack the authentication…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-1957

Published Apr 30, 2014

FortiGuard FortiWeb before 5.0.3 allows remote authenticated users to gain privileges via unspecified vectors.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-1956

Published Apr 30, 2014

CRLF injection vulnerability in FortiGuard FortiWeb before 5.0.3 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecifi…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-1955

Published Apr 30, 2014

Cross-site scripting (XSS) vulnerability in FortiGuard FortiWeb before 5.0.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-6990

Published Apr 30, 2014

FortiGuard FortiAuthenticator before 3.0 allows remote administrators to gain privileges via the command line interface.

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2014-0331

Published Apr 10, 2014

Cross-site scripting (XSS) vulnerability in the web administration interface in FortiADC with firmware before 3.2.1 allows remote attackers to inject arbitrary web script or HTML…

CVSS 4.3 · Medium

CVE-2014-1458

Published Feb 4, 2014

Cross-site scripting (XSS) vulnerability in the web administration interface in FortiGuard FortiWeb 5.0.3 and earlier allows remote authenticated administrators to inject arbitrar…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2013-7182

Published Feb 4, 2014

Cross-site scripting (XSS) vulnerability in firewall/schedule/recurrdlg in Fortinet FortiOS 5.0.5 allows remote attackers to inject arbitrary web script or HTML via the mkey param…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-7181

Published Feb 4, 2014

Cross-site scripting (XSS) vulnerability in user/ldap_user/add in Fortinet FortiOS 5.0.3 allows remote attackers to inject arbitrary web script or HTML via the filter parameter.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1,076-1,100 of 1,135 CVEsPage 44 of 46