Fortinet Fortiadc vulnerabilities
44 known vulnerabilities affecting fortinet/fortiadc.
Total CVEs
44
CISA KEV
1
actively exploited
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL2HIGH18MEDIUM23LOW1
Vulnerabilities
Page 3 of 3
CVE-2023-50180P4MEDIUMCVSS 5.5≤ 6.2.6≥ 7.0.0, ≤ 7.0.5+6 more2024-05-14
CVE-2023-50180 [MEDIUM] CWE-497 CVE-2023-50180: An exposure of sensitive system information to an unauthorized control sphere vulnerability [CWE-497
An exposure of sensitive system information to an unauthorized control sphere vulnerability [CWE-497] in FortiADC version 7.4.1 and below, version 7.2.3 and below, version 7.1.4 and below, version 7.0.5 and below, version 6.2.6 and below may allow a read-only admin to view data pertaining to other admins.
nvd
CVE-2022-43952P4MEDIUMCVSS 5.4≥ 6.2.0, < 6.2.6≥ 7.0.0, < 7.0.4+4 more2023-04-11
CVE-2022-43952 [MEDIUM] CWE-79 CVE-2022-43952: An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerabilit
An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiADC version 7.1.1 and below, version 7.0.3 and below, version 6.2.5 and below may allow an authenticated attacker to perform a cross-site scripting attack via crafted HTTP requests.
nvd
CVE-2020-15935P4MEDIUMCVSS 4.3≥ 5.0.0, ≤ 5.4.3≥ 6.0.0, ≤ 6.0.12021-11-02
CVE-2020-15935 [MEDIUM] CWE-312 CVE-2020-15935: A cleartext storage of sensitive information in GUI in FortiADC versions 5.4.3 and below, 6.0.0 and
A cleartext storage of sensitive information in GUI in FortiADC versions 5.4.3 and below, 6.0.0 and below may allow a remote authenticated attacker to retrieve some sensitive information such as users LDAP passwords and RADIUS shared secret by deobfuscating the passwords entry fields.
nvd
CVE-2024-36511P4LOWCVSS 3.7≥ 6.0.0, < 7.4.5≥ 7.4.0, ≤ 7.4.4+6 more2024-09-10
CVE-2024-36511 [LOW] CWE-358 CVE-2024-36511: An improperly implemented security check for standard vulnerability [CWE-358] in FortiADC Web Applic
An improperly implemented security check for standard vulnerability [CWE-358] in FortiADC Web Application Firewall (WAF) 7.4.0 through 7.4.4, 7.2 all versions, 7.1 all versions, 7.0 all versions, 6.2 all versions, 6.1 all versions, 6.0 all versions when cookie security policy is enabled may allow an attacker, under specific conditions, to retrieve the
nvd
← Previous3 / 3