Fortinet Fortimail vulnerabilities
47 known vulnerabilities affecting fortinet/fortimail.
Total CVEs
47
CISA KEV
1
actively exploited
Public exploits
4
Exploited in wild
1
Severity breakdown
CRITICAL7HIGH15MEDIUM25
Vulnerabilities
Page 2 of 3
CVE-2021-36193P3HIGHCVSS 7.2≥ 7.0.0, ≤ 7.0.2≥ 6.4.0, ≤ 6.4.6+3 more2022-02-02
CVE-2021-36193 [HIGH] CWE-121 CVE-2021-36193: Multiple stack-based buffer overflows in the command line interpreter of FortiWeb before 6.4.2 may a
Multiple stack-based buffer overflows in the command line interpreter of FortiWeb before 6.4.2 may allow an authenticated attacker to achieve arbitrary code execution via specially crafted commands.
nvd
CVE-2022-22299P3HIGHCVSS 7.8≥ 6.4.0, ≤ 6.4.5≥ 7.0.0, ≤ 7.0.22022-08-05
CVE-2022-22299 [HIGH] CWE-134 CVE-2022-22299: A format string vulnerability [CWE-134] in the command line interpreter of FortiADC version 6.0.0 th
A format string vulnerability [CWE-134] in the command line interpreter of FortiADC version 6.0.0 through 6.0.4, FortiADC version 6.1.0 through 6.1.5, FortiADC version 6.2.0 through 6.2.1, FortiProxy version 1.0.0 through 1.0.7, FortiProxy version 1.1.0 through 1.1.6, FortiProxy version 1.2.0 through 1.2.13, FortiProxy version 2.0.0 through 2.0.7, For
nvd
CVE-2013-1471P4MEDIUMCVSS 4.3PoC≤ 4.0v3.0+1 more2013-02-04
CVE-2013-1471 [MEDIUM] CWE-79 CVE-2013-1471: Multiple cross-site scripting (XSS) vulnerabilities in admin/FEAdmin.html in Fortinet FortiMail befo
Multiple cross-site scripting (XSS) vulnerabilities in admin/FEAdmin.html in Fortinet FortiMail before 4.3.4 on FortiMail Identity-Based Encryption (IBE) appliances allow user-assisted remote attackers to inject arbitrary web script or HTML via (1) the Add field for the Black List under Antispam Management User Preferences or (2) the User name field fo
nvd
CVE-2019-15712P3HIGHCVSS 7.2≤ 5.4.10≥ 6.0.0, ≤ 6.0.6+1 more2020-01-23
CVE-2019-15712 [HIGH] CVE-2019-15712: An improper access control vulnerability in FortiMail admin webUI 6.2.0, 6.0.0 to 6.0.6, 5.4.10 and
An improper access control vulnerability in FortiMail admin webUI 6.2.0, 6.0.0 to 6.0.6, 5.4.10 and below may allow administrators to access web console they should not be authorized for.
nvd
CVE-2024-56497P3MEDIUMCVSS 6.7≥ 6.4.0, < 6.4.8≥ 7.0.0, < 7.0.7+4 more2025-01-14
CVE-2024-56497 [MEDIUM] CWE-78 CVE-2024-56497: An improper neutralization of special elements used in an os command ('os command injection') in For
An improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiMail versions 7.2.0 through 7.2.4 and 7.0.0 through 7.0.6 and 6.4.0 through 6.4.7, FortiRecorder versions 7.0.0 and 6.4.0 through 6.4.4 allows attacker to execute unauthorized code or commands via the CLI.
nvd
CVE-2022-39945P3MEDIUMCVSS 6.5≥ 6.0.0, ≤ 6.0.12≥ 6.2.0, ≤ 6.2.9+3 more2022-11-02
CVE-2022-39945 [MEDIUM] CWE-639 CVE-2022-39945: An improper access control vulnerability [CWE-284] in FortiMail 7.2.0, 7.0.0 through 7.0.3, 6.4 all
An improper access control vulnerability [CWE-284] in FortiMail 7.2.0, 7.0.0 through 7.0.3, 6.4 all versions, 6.2 all versions, 6.0 all versions may allow an authenticated admin user assigned to a specific domain to access and modify other domains information via insecure direct object references (IDOR).
nvd
CVE-2021-24013P3MEDIUMCVSS 6.5≥ 5.4.0, ≤ 5.4.12≥ 6.0.0, < 6.0.11+2 more2021-07-12
CVE-2021-24013 [MEDIUM] CWE-22 CVE-2021-24013: Multiple Path traversal vulnerabilities in the Webmail of FortiMail before 6.4.4 may allow a regular
Multiple Path traversal vulnerabilities in the Webmail of FortiMail before 6.4.4 may allow a regular user to obtain unauthorized access to files and data via specifically crafted web requests.
nvd
CVE-2024-46663P4MEDIUMCVSS 6.7≥ 6.4.0, < 7.2.7≥ 7.4.0, < 7.4.4+6 more2025-03-11
CVE-2024-46663 [MEDIUM] CWE-121 CVE-2024-46663: A stack-buffer overflow vulnerability [CWE-121] in Fortinet FortiMail CLI version 7.6.0 through 7.6.
A stack-buffer overflow vulnerability [CWE-121] in Fortinet FortiMail CLI version 7.6.0 through 7.6.1 and before 7.4.3 allows a privileged attacker to execute arbitrary code or commands via specifically crafted CLI commands.
nvd
CVE-2022-29056P4MEDIUMCVSS 5.3≥ 6.0.0, < 6.0.10≥ 6.2.1, < 6.2.5+4 more2023-03-09
CVE-2022-29056 [MEDIUM] CWE-307 CVE-2022-29056: A improper restriction of excessive authentication attempts vulnerability [CWE-307] in Fortinet Fort
A improper restriction of excessive authentication attempts vulnerability [CWE-307] in Fortinet FortiMail version 6.4.0, version 6.2.0 through 6.2.4 and before 6.0.9 allows a remote unauthenticated attacker to partially exhaust CPU and memory via sending numerous HTTP requests to the login form.
nvd
CVE-2022-23439P4MEDIUMCVSS 6.1≥ 6.4.0, < 7.0.4≥ 7.0.0, ≤ 7.0.3+4 more2025-01-22
CVE-2022-23439 [MEDIUM] CWE-610 CVE-2022-23439: A externally controlled reference to a resource in another sphere vulnerability in Fortinet allows
A externally controlled reference to a resource in another sphere vulnerability in Fortinet allows attacker to poison web caches via crafted HTTP requests, where the `Host` header points to an arbitrary webserver
nvd
CVE-2021-32591P4MEDIUMCVSS 5.3≥ 5.0, ≤ 5.6.3≥ 6.0.0, ≤ 6.0.11+4 more2021-12-08
CVE-2021-32591 [MEDIUM] CVE-2021-32591: A missing cryptographic steps vulnerability in the function that encrypts users' LDAP and RADIUS cre
A missing cryptographic steps vulnerability in the function that encrypts users' LDAP and RADIUS credentials in FortiSandbox before 4.0.1, FortiWeb before 6.3.12, FortiADC before 6.2.1, FortiMail 7.0.1 and earlier may allow an attacker in possession of the password store to compromise the confidentiality of the encrypted secrets.
nvd
CVE-2023-36633P4MEDIUMCVSS 5.4≥ 6.0.0, < 7.0.6≥ 7.2.0, < 7.2.3+5 more2023-11-14
CVE-2023-36633 [MEDIUM] CWE-285 CVE-2023-36633: An improper authorization vulnerability [CWE-285] in FortiMail webmail version 7.2.0 through 7.2.2 a
An improper authorization vulnerability [CWE-285] in FortiMail webmail version 7.2.0 through 7.2.2 and before 7.0.5 allows an authenticated attacker to see and modify the title of address book folders of other users via crafted HTTP or HTTPs requests.
nvd
CVE-2021-42757P4MEDIUMCVSS 6.7≥ 5.4.0, ≤ 6.2.7≥ 6.4.0, ≤ 6.4.6+3 more2021-12-08
CVE-2021-42757 [MEDIUM] CWE-120 CVE-2021-42757: A buffer overflow [CWE-121] in the TFTP client library of FortiOS before 6.4.7 and FortiOS 7.0.0 thr
A buffer overflow [CWE-121] in the TFTP client library of FortiOS before 6.4.7 and FortiOS 7.0.0 through 7.0.2, may allow an authenticated local attacker to achieve arbitrary code execution via specially crafted command line arguments.
nvd
CVE-2021-24008P4MEDIUMCVSS 5.3≥ 6.0.0, < 6.0.10≥ 6.2.0, < 6.2.5+1 more2025-03-28
CVE-2021-24008 [MEDIUM] CWE-200 CVE-2021-24008: An exposure of sensitive system information to an unauthorized control sphere vulnerability [CWE-497
An exposure of sensitive system information to an unauthorized control sphere vulnerability [CWE-497] in FortiDDoS version 5.4.0, version 5.3.2 and below, version 5.2.0, version 5.1.0, version 5.0.0, version 4.7.0, version 4.6.0, version 4.5.0, version 4.4.2 and below, FortiDDoS-CM version 5.3.0, version 5.2.0, version 5.1.0, version 5.0.0, version
nvd
CVE-2017-7732P4MEDIUMCVSS 6.1v4.1.0v4.2.0+34 more2017-10-26
CVE-2017-7732 [MEDIUM] CWE-79 CVE-2017-7732: A reflected Cross-Site Scripting (XSS) vulnerability in Fortinet FortiMail 5.1 and earlier, 5.2.0 th
A reflected Cross-Site Scripting (XSS) vulnerability in Fortinet FortiMail 5.1 and earlier, 5.2.0 through 5.2.9, and 5.3.0 through 5.3.9 customized pre-authentication webmail login page allows attacker to inject arbitrary web script or HTML via crafted HTTP requests.
nvd
CVE-2020-15933P4MEDIUMCVSS 5.3≤ 6.0.9v6.2.0+6 more2022-01-05
CVE-2020-15933 [MEDIUM] CWE-200 CVE-2020-15933: A exposure of sensitive information to an unauthorized actor in Fortinet FortiMail versions 6.0.9 an
A exposure of sensitive information to an unauthorized actor in Fortinet FortiMail versions 6.0.9 and below, FortiMail versions 6.2.4 and below FortiMail versions 6.4.1 and 6.4.0 allows attacker to obtain potentially sensitive software-version information via client-side resources inspection.
nvd
CVE-2017-3125P4MEDIUMCVSS 6.1v5.0v5.0.5+30 more2017-04-12
CVE-2017-3125 [MEDIUM] CWE-79 CVE-2017-3125: An unauthenticated XSS vulnerability with FortiMail 5.0.0 - 5.2.9 and 5.3.0 - 5.3.8 could allow an a
An unauthenticated XSS vulnerability with FortiMail 5.0.0 - 5.2.9 and 5.3.0 - 5.3.8 could allow an attacker to execute arbitrary scripts in the security context of the browser of a victim logged in FortiMail, assuming the victim is social engineered into clicking an URL crafted by the attacker.
nvd
CVE-2022-26114P4MEDIUMCVSS 6.1fixed in 7.2.02022-09-06
CVE-2022-26114 [MEDIUM] CWE-79 CVE-2022-26114: An improper neutralization of input during web page generation vulnerability [CWE-79] in the Webmail
An improper neutralization of input during web page generation vulnerability [CWE-79] in the Webmail of FortiMail before 7.2.0 may allow an unauthenticated attacker to trigger a cross-site scripting (XSS) attack via sending specially crafted mail messages.
nvd
CVE-2019-15707P4MEDIUMCVSS 4.9≤ 5.4.10≥ 6.0.0, ≤ 6.0.6+1 more2020-01-23
CVE-2019-15707 [MEDIUM] CVE-2019-15707: An improper access control vulnerability in FortiMail admin webUI 6.2.0, 6.0.0 to 6.0.6, 5.4.10 and
An improper access control vulnerability in FortiMail admin webUI 6.2.0, 6.0.0 to 6.0.6, 5.4.10 and below may allow administrators to perform system backup config download they should not be authorized for.
nvd
CVE-2021-26099P4MEDIUMCVSS 4.9≥ 5.0, < 7.0.02021-07-12
CVE-2021-26099 [MEDIUM] CVE-2021-26099: Missing cryptographic steps in the Identity-Based Encryption service of FortiMail before 7.0.0 may a
Missing cryptographic steps in the Identity-Based Encryption service of FortiMail before 7.0.0 may allow an attacker who comes in possession of the encrypted master keys to compromise their confidentiality by observing a few invariant properties of the ciphertext.
nvd