Fortinet Fortiadc Firmware vulnerabilities
5 known vulnerabilities affecting fortinet/fortiadc_firmware.
Total CVEs
5
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
MEDIUM5
Vulnerabilities
Page 1 of 1
CVE-2020-9286MEDIUMCVSS 6.5≤ 5.3.42020-04-07
CVE-2020-9286 [MEDIUM] CVE-2020-9286: An improper authorization vulnerability in FortiADC may allow a remote authenticated user with low p
An improper authorization vulnerability in FortiADC may allow a remote authenticated user with low privileges to perform certain actions such as rebooting the system.
nvd
CVE-2020-6647MEDIUMCVSS 5.4≤ 5.3.4v5.4.02020-04-07
CVE-2020-6647 [MEDIUM] CWE-79 CVE-2020-6647: An improper neutralization of input vulnerability in the dashboard of FortiADC may allow an authenti
An improper neutralization of input vulnerability in the dashboard of FortiADC may allow an authenticated attacker to perform a cross site scripting attack (XSS) via the name parameter.
nvd
CVE-2014-8618MEDIUMCVSS 4.3≤ 4.1.02015-05-12
CVE-2014-8618 [MEDIUM] CWE-79 CVE-2014-8618: Cross-site scripting (XSS) vulnerability in the theme login page in Fortinet FortiADC D models befor
Cross-site scripting (XSS) vulnerability in the theme login page in Fortinet FortiADC D models before 4.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2014-8582MEDIUMCVSS 6.4v3.1.1v3.2.0+2 more2014-11-01
CVE-2014-8582 [MEDIUM] CVE-2014-8582: FortiNet FortiADC-E with firmware 3.1.1 before 4.0.5 and Coyote Point Equalizer with firmware 10.2.0
FortiNet FortiADC-E with firmware 3.1.1 before 4.0.5 and Coyote Point Equalizer with firmware 10.2.0a allows remote attackers to obtain access to arbitrary subnets via unspecified vectors.
nvd
CVE-2014-0331MEDIUMCVSS 4.3≤ 3.2.02014-04-10
CVE-2014-0331 [MEDIUM] CWE-79 CVE-2014-0331: Cross-site scripting (XSS) vulnerability in the web administration interface in FortiADC with firmwa
Cross-site scripting (XSS) vulnerability in the web administration interface in FortiADC with firmware before 3.2.1 allows remote attackers to inject arbitrary web script or HTML via the locale parameter to gui_partA/.
nvd