cbcvebase.

Fortinet Fortiadc vulnerabilities

44 known vulnerabilities affecting fortinet/fortiadc.

Total CVEs
44
CISA KEV
1
actively exploited
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL2HIGH18MEDIUM23LOW1

Vulnerabilities

Page 1 of 3
CVE-2018-13374P1MEDIUMCVSS 4.3KEVPoCRansomware≥ 5.4.0, < 5.4.5≥ 6.0.0, < 6.0.2+1 more2019-01-22
CVE-2018-13374 [MEDIUM] CWE-732 CVE-2018-13374: A Improper Access Control in Fortinet FortiOS 6.0.2, 5.6.7 and before, FortiADC 6.1.0, 6.0.0 to 6.0. A Improper Access Control in Fortinet FortiOS 6.0.2, 5.6.7 and before, FortiADC 6.1.0, 6.0.0 to 6.0.1, 5.4.0 to 5.4.4 allows attacker to obtain the LDAP server login credentials configured in FortiGate via pointing a LDAP server connectivity test request to a rogue LDAP server instead of the configured one.
nvd
CVE-2022-39947P2HIGHCVSS 8.8≥ 5.4.0, ≤ 5.4.5≥ 6.0.0, ≤ 6.0.4+5 more2023-01-03
CVE-2022-39947 [HIGH] CWE-78 CVE-2022-39947: A improper neutralization of special elements used in an os command ('os command injection') in Fort A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiADC version 7.0.0 through 7.0.2, FortiADC version 6.2.0 through 6.2.3, FortiADC version version 6.1.0 through 6.1.6, FortiADC version 6.0.0 through 6.0.4, FortiADC version 5.4.0 through 5.4.5 may allow an attacker to execute unauthorized code o
nvd
CVE-2022-35849P3HIGHCVSS 8.8fixed in 6.2.6≥ 7.0.0, < 7.0.4+5 more2023-09-13
CVE-2022-35849 [HIGH] CWE-78 CVE-2022-35849: An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in the m An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in the management interface of FortiADC 7.1.0 through 7.1.1, 7.0.0 through 7.0.3, 6.2.0 through 6.2.5 and 6.1.0 all versions may allow an authenticated attacker to execute unauthorized commands via specifically crafted arguments to existing commands.
nvd
CVE-2022-38381P3CRITICALCVSS 9.8≥ 5.0.0, ≤ 5.0.4≥ 5.1.0, ≤ 5.1.7+7 more2022-11-02
CVE-2022-38381 [CRITICAL] CVE-2022-38381: An improper handling of malformed request vulnerability [CWE-228] exists in FortiADC 5.0 all version An improper handling of malformed request vulnerability [CWE-228] exists in FortiADC 5.0 all versions, 6.0.0 all versions, 6.1.0 all versions, 6.2.0 through 6.2.3, and 7.0.0 through 7.0.2. This may allow a remote attacker without privileges to bypass some Web Application Firewall (WAF) protection such as the SQL Injection and XSS filters via a malformed H
nvd
CVE-2022-33875P3HIGHCVSS 8.8≥ 5.2.0, ≤ 6.2.4v7.0.0+9 more2022-12-06
CVE-2022-33875 [HIGH] CWE-89 CVE-2022-33875: An improper neutralization of special elements used in an SQL Command ('SQL Injection') vulnerabilit An improper neutralization of special elements used in an SQL Command ('SQL Injection') vulnerability in Fortinet FortiADC version 7.1.0, version 7.0.0 through 7.0.2 and version 6.2.4 and below allows an authenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests.
nvd
CVE-2022-26120P3HIGHCVSS 8.8≥ 5.0.0, < 6.2.3v7.0.0+1 more2022-07-18
CVE-2022-26120 [HIGH] CWE-89 CVE-2022-26120: Multiple improper neutralization of special elements used in an SQL Command ('SQL Injection') vulner Multiple improper neutralization of special elements used in an SQL Command ('SQL Injection') vulnerabilities [CWE-89] in FortiADC management interface 7.0.0 through 7.0.1, 5.0.0 through 6.2.2 may allow an authenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests.
nvd
CVE-2023-26205P3HIGHCVSS 8.8≥ 6.1.0, ≤ 6.1.6≥ 6.2.0, ≤ 6.2.6+5 more2023-11-14
CVE-2023-26205 [HIGH] CWE-284 CVE-2023-26205: An improper access control vulnerability [CWE-284] in FortiADC automation feature 7.1.0 through 7.1. An improper access control vulnerability [CWE-284] in FortiADC automation feature 7.1.0 through 7.1.2, 7.0 all versions, 6.2 all versions, 6.1 all versions may allow an authenticated low-privileged attacker to escalate their privileges to super_admin via a specific crafted configuration of fabric automation CLI script.
nvd
CVE-2025-31104P3HIGHCVSS 7.2≥ 6.1.0, < 7.1.5≥ 7.2.0, < 7.2.8+9 more2025-06-10
CVE-2025-31104 [HIGH] CWE-78 CVE-2025-31104: An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulner An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] in FortiADC 7.6.0 through 7.6.1, 7.4.0 through 7.4.6, 7.2.0 through 7.2.7, 7.1.0 through 7.1.4, 7.0 all versions, 6.2 all versions, 6.1 all versions may allow an authenticated attacker to execute unauthorized code via crafted HTTP reques
nvd
CVE-2023-25607P3HIGHCVSS 7.8≥ 6.0.0, ≤ 6.0.4≥ 6.1.0, ≤ 6.1.6+3 more2023-10-10
CVE-2023-25607 [HIGH] CWE-78 CVE-2023-25607: An improper neutralization of special elements used in an OS Command ('OS Command Injection') vulner An improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78 ] in FortiManager 7.2.0 through 7.2.2, 7.0.0 through 7.0.7, 6.4.0 through 6.4.11, 6.2 all versions, 6.0 all versions, FortiAnalyzer 7.2.0 through 7.2.2, 7.0.0 through 7.0.7, 6.4.0 through 6.4.11, 6.2 all versions, 6.0 all versions and For
nvd
CVE-2025-49813P3HIGHCVSS 7.2≥ 6.2.0, ≤ 6.2.6≥ 7.1.0, < 7.1.2+2 more2025-08-12
CVE-2025-49813 [HIGH] CWE-78 CVE-2025-49813: An improper neutralization of special elements used in an OS Command ("OS Command Injection") vulner An improper neutralization of special elements used in an OS Command ("OS Command Injection") vulnerability [CWE-78] in Fortinet FortiADC version 7.2.0 and before 7.1.1 allows a remote and authenticated attacker with low privilege to execute unauthorized code via specifically crafted HTTP parameters.
nvd
CVE-2022-43948P3HIGHCVSS 7.8≥ 5.1.0, < 6.2.6≥ 7.0.0, < 7.0.4+10 more2023-04-11
CVE-2022-43948 [HIGH] CWE-78 CVE-2022-43948: A improper neutralization of special elements used in an os command ('os command injection') in Fort A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWeb version 7.0.0 through 7.0.3, FortiADC version 7.1.0 through 7.1.1, FortiADC version 7.0.0 through 7.0.3, FortiADC 6.2 all versions, FortiADC 6.1 all versions, FortiADC 6.0 all versions, FortiADC 5.4 all versions, FortiADC 5.3 all versions,
nvd
CVE-2023-25603P3CRITICALCVSS 9.1v7.1.0v7.1.1+1 more2023-11-14
CVE-2023-25603 [CRITICAL] CWE-942 CVE-2023-25603: A permissive cross-domain policy with untrusted domains vulnerability in Fortinet FortiADC 7.1.0 - 7 A permissive cross-domain policy with untrusted domains vulnerability in Fortinet FortiADC 7.1.0 - 7.1.1, FortiDDoS-F 6.3.0 - 6.3.4 and 6.4.0 - 6.4.1 allow an unauthorized attacker to carry out privileged actions and retrieve sensitive information via crafted web requests.
nvd
CVE-2022-27482P3HIGHCVSS 7.8≥ 5.0.0, ≤ 5.0.4≥ 5.1.0, ≤ 5.1.7+10 more2023-02-16
CVE-2022-27482 [HIGH] CWE-78 CVE-2022-27482: A improper neutralization of special elements used in an os command ('os command injection') in Fort A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiADC version 7.0.0 through 7.0.1, 6.2.0 through 6.2.2, 6.1.0 through 6.1.6, 6.0.x, 5.x.x allows attacker to execute arbitrary shell code as `root` via CLI commands.
nvd
CVE-2023-26210P3HIGHCVSS 7.8≥ 5.2.0, ≤ 5.2.8≥ 5.3.0, ≤ 5.3.7+10 more2023-06-13
CVE-2023-26210 [HIGH] CWE-78 CVE-2023-26210: Multiple improper neutralization of special elements used in an os command ('OS Command Injection') Multiple improper neutralization of special elements used in an os command ('OS Command Injection') vulnerabilties [CWE-78] vulnerability in Fortinet allows a local authenticated attacker to execute arbitrary shell code as `root` user via crafted CLI requests.
nvd
CVE-2023-50178P3HIGHCVSS 7.4≥ 6.0.0, ≤ 6.0.4≥ 6.1.0, ≤ 6.1.6+5 more2024-07-09
CVE-2023-50178 [HIGH] CWE-295 CVE-2023-50178: An improper certificate validation vulnerability [CWE-295] in FortiADC 7.4.0, 7.2.0 through 7.2.3, 7 An improper certificate validation vulnerability [CWE-295] in FortiADC 7.4.0, 7.2.0 through 7.2.3, 7.1 all versions, 7.0 all versions, 6.2 all versions, 6.1 all versions and 6.0 all versions may allow a remote and unauthenticated attacker to perform a Man-in-the-Middle attack on the communication channel between the device and various remote servers s
nvd
CVE-2023-27999P3HIGHCVSS 7.8≥ 7.1.0, < 7.1.2v7.2.0+1 more2023-05-03
CVE-2023-27999 [HIGH] CWE-78 CVE-2023-27999: An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in Forti An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in FortiADC 7.2.0, 7.1.0 through 7.1.1 may allow an authenticated attacker to execute unauthorized commands via specifically crafted arguments to existing commands.
nvd
CVE-2022-40679P3HIGHCVSS 7.8≥ 5.0.0, < 6.2.5v7.1.0+9 more2023-04-11
CVE-2022-40679 [HIGH] CWE-78 CVE-2022-40679: An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in Forti An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in FortiADC 5.x all versions, 6.0 all versions, 6.1 all versions, 6.2.0 through 6.2.4, 7.0.0 through 7.0.3, 7.1.0; FortiDDoS 4.x all versions, 5.0 all versions, 5.1 all versions, 5.2 all versions, 5.3 all versions, 5.4 all versions, 5.5 all versions, 5.6 all ver
nvd
CVE-2023-28000P3HIGHCVSS 7.8≥ 6.0.0, ≤ 6.0.4≥ 6.1.0, ≤ 6.1.6+3 more2023-06-13
CVE-2023-28000 [HIGH] CWE-78 CVE-2023-28000: An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in Forti An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in FortiADC CLI 7.1.0, 7.0.0 through 7.0.3, 6.2.0 through 6.2.4, 6.1 all versions, 6.0 all versions may allow a local and authenticated attacker to execute unauthorized commands via specifically crafted arguments in diagnose system df CLI command.
nvd
CVE-2021-36193P3HIGHCVSS 7.2v7.0.0≥ 6.2.0, ≤ 6.2.2+7 more2022-02-02
CVE-2021-36193 [HIGH] CWE-121 CVE-2021-36193: Multiple stack-based buffer overflows in the command line interpreter of FortiWeb before 6.4.2 may a Multiple stack-based buffer overflows in the command line interpreter of FortiWeb before 6.4.2 may allow an authenticated attacker to achieve arbitrary code execution via specially crafted commands.
nvd
CVE-2025-48839P3MEDIUMCVSS 6.6≥ 6.2.0, < 7.4.8≥ 7.6.0, < 7.6.3+7 more2025-11-18
CVE-2025-48839 [MEDIUM] CWE-787 CVE-2025-48839: An Out-of-bounds Write vulnerability [CWE-787] in FortiADC 8.0.0, 7.6.0 through 7.6.2, 7.4.0 through An Out-of-bounds Write vulnerability [CWE-787] in FortiADC 8.0.0, 7.6.0 through 7.6.2, 7.4.0 through 7.4.7, 7.2 all versions, 7.1 all versions, 7.0 all versions, 6.2 all versions may allow an authenticated attacker to execute arbitrary code via specially crafted HTTP requests.
nvd
Fortinet Fortiadc vulnerabilities | cvebase