cbcvebase.

Fortinet Fortimanager vulnerabilities

114 known vulnerabilities affecting fortinet/fortimanager.

Total CVEs
114
CISA KEV
2
actively exploited
Public exploits
1
Exploited in wild
2
Severity breakdown
CRITICAL14HIGH38MEDIUM56LOW6

Vulnerabilities

Page 1 of 6
CVE-2024-47575P1CRITICALCVSS 9.8KEVPoC≥ 6.2.0, < 6.2.13≥ 6.4.0, < 6.4.15+9 more2024-10-23
CVE-2024-47575 [CRITICAL] CWE-306 CVE-2024-47575: A missing authentication for critical function in FortiManager 7.6.0, FortiManager 7.4.0 through 7.4 A missing authentication for critical function in FortiManager 7.6.0, FortiManager 7.4.0 through 7.4.4, FortiManager 7.2.0 through 7.2.7, FortiManager 7.0.0 through 7.0.12, FortiManager 6.4.0 through 6.4.14, FortiManager 6.2.0 through 6.2.12, Fortinet FortiManager Cloud 7.4.1 through 7.4.4, FortiManager Cloud 7.2.1 through 7.2.7, FortiManager Clou
nvd
CVE-2026-24858P1CRITICALCVSS 9.8KEV≥ 7.0.0, ≤ 7.0.15≥ 7.2.0, ≤ 7.2.11+4 more2026-01-27
CVE-2026-24858 [CRITICAL] CWE-288 CVE-2026-24858: An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.5, FortiAnalyzer 7.4.0 through 7.4.9, FortiAnalyzer 7.2.0 through 7.2.11, FortiAnalyzer 7.0.0 through 7.0.15, FortiManager 7.6.0 through 7.6.5, FortiManager 7.4.0 through 7.4.9, FortiManager 7.2.0 through 7.
nvd
CVE-2023-25610P2CRITICALCVSS 9.8≥ 6.0.0, < 6.0.12≥ 6.2.0, < 6.2.11+7 more2025-03-24
CVE-2023-25610 [CRITICAL] CWE-124 CVE-2023-25610: A buffer underwrite ('buffer underflow') vulnerability in the administrative interface of Fortinet F A buffer underwrite ('buffer underflow') vulnerability in the administrative interface of Fortinet FortiOS version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.6, version 6.4.0 through 6.4.11 and version 6.2.12 and below, FortiProxy version 7.2.0 through 7.2.2, version 7.0.0 through 7.0.8, version 2.0.12 and below and FortiOS-6K7K version 7.0.5,
nvd
CVE-2024-48884P2CRITICALCVSS 9.1≥ 7.4.1, < 7.4.4≥ 7.6.0, < 7.6.2+2 more2025-01-14
CVE-2024-48884 [CRITICAL] CWE-22 CVE-2024-48884: A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fo A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiManager 7.6.0 through 7.6.1, FortiManager 7.4.1 through 7.4.3, FortiManager Cloud 7.4.1 through 7.4.3, FortiOS 7.6.0, FortiOS 7.4.0 through 7.4.4, FortiOS 7.2.0 through 7.2.9, FortiOS 7.0.0 through 7.0.15, FortiOS 6.4.0 through 6.4.15, Fo
nvd
CVE-2021-32589P2CRITICALCVSS 9.8≥ 5.0.0, < 5.6.11≥ 6.0.0, < 6.0.11+10 more2024-12-19
CVE-2021-32589 [CRITICAL] CWE-416 CVE-2021-32589: A Use After Free (CWE-416) vulnerability in FortiManager version 7.0.0, version 6.4.5 and below, ver A Use After Free (CWE-416) vulnerability in FortiManager version 7.0.0, version 6.4.5 and below, version 6.2.7 and below, version 6.0.10 and below, version 5.6.10 and below, version 5.4.7 and below, version 5.2.10 and below, version 5.0.12 and below and FortiAnalyzer version 7.0.0, version 6.4.5 and below, version 6.2.7 and below, version 6.0.10 a
nvd
CVE-2025-54820P2HIGHCVSS 8.1≥ 6.4.0, < 7.2.11≥ 7.4.0, < 7.4.3+3 more2026-03-10
CVE-2025-54820 [HIGH] CWE-121 CVE-2025-54820: A Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in Fortinet FortiManager 7.4.0 t A Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in Fortinet FortiManager 7.4.0 through 7.4.2, FortiManager 7.2.0 through 7.2.10, FortiManager 6.4 all versions may allow a remote unauthenticated attacker to execute unauthorized commands via crafted requests, if the service is enabled. The success of the attack depends on the ability
nvd
CVE-2024-26011P2CRITICALCVSS 9.8≥ 6.4.0, < 6.4.15≥ 7.0.0, < 7.0.12+6 more2024-11-12
CVE-2024-26011 [CRITICAL] CWE-306 CVE-2024-26011: A missing authentication for critical function in Fortinet FortiManager version 7.4.0 through 7.4.2, A missing authentication for critical function in Fortinet FortiManager version 7.4.0 through 7.4.2, 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through 6.4.14, FortiPAM version 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiProxy version 7.4.0 through 7.4.2, 7.2.0 through 7.2.9, 7.0.0 through 7.0.17, 2.0.0 through 2.0.14, 1.2.0 throug
nvd
CVE-2023-42791P2HIGHCVSS 8.8≥ 6.2.0, < 6.2.12≥ 6.4.0, < 6.4.13+7 more2024-02-20
CVE-2023-42791 [HIGH] CWE-23 CVE-2023-42791: A relative path traversal in Fortinet FortiManager version 7.4.0 and 7.2.0 through 7.2.3 and 7.0.0 t A relative path traversal in Fortinet FortiManager version 7.4.0 and 7.2.0 through 7.2.3 and 7.0.0 through 7.0.8 and 6.4.0 through 6.4.12 and 6.2.0 through 6.2.11 allows attacker to execute unauthorized code or commands via crafted HTTP requests.
nvd
CVE-2024-50563P2CRITICALCVSS 9.8≥ 7.4.1, < 7.4.4≥ 7.6.0, < 7.6.2+2 more2025-01-16
CVE-2024-50563 [CRITICAL] CWE-1390 CVE-2024-50563: A weak authentication in Fortinet FortiManager Cloud, FortiAnalyzer versions 7.6.0 through 7.6.1, 7. A weak authentication in Fortinet FortiManager Cloud, FortiAnalyzer versions 7.6.0 through 7.6.1, 7.4.1 through 7.4.3, FortiAnalyzer Cloud versions 7.4.1 through 7.4.3, FortiManager versions 7.6.0 through 7.6.1, 7.4.1 through 7.4.3, FortiManager Cloud versions 7.4.1 through 7.4.3 allows attacker to execute unauthorized code or commands via a brut
nvd
CVE-2024-50566P2HIGHCVSS 8.8≥ 7.2.1, < 7.2.9≥ 7.4.0, < 7.4.6+4 more2025-01-14
CVE-2024-50566 [HIGH] CWE-78 CVE-2024-50566: A improper neutralization of special elements used in an os command ('os command injection') vulnera A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiManager Cloud 7.6.0 through 7.6.1, FortiManager Cloud 7.4.0 through 7.4.4, FortiManager Cloud 7.2.2 through 7.2.7, FortiManager 7.6.0 through 7.6.1, FortiManager 7.4.0 through 7.4.5, FortiManager 7.2.1 through 7.2.8 may allow an a
nvd
CVE-2023-36554P2CRITICALCVSS 9.8≥ 6.2.0, ≤ 6.2.12≥ 6.4.0, ≤ 6.4.13+3 more2024-03-12
CVE-2023-36554 [CRITICAL] CWE-284 CVE-2023-36554: A improper access control in Fortinet FortiManager version 7.4.0, version 7.2.0 through 7.2.3, versi A improper access control in Fortinet FortiManager version 7.4.0, version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.10, version 6.4.0 through 6.4.13, 6.2 all versions allows attacker to execute unauthorized code or commands via specially crafted HTTP requests.
nvd
CVE-2024-23666P2HIGHCVSS 8.8≥ 6.4.0, < 6.4.15≥ 7.0.0, < 7.0.13+6 more2024-11-12
CVE-2024-23666 [HIGH] CWE-602 CVE-2024-23666: A client-side enforcement of server-side security in Fortinet FortiAnalyzer-BigData at least versi A client-side enforcement of server-side security in Fortinet FortiAnalyzer-BigData at least version 7.4.0 and 7.2.0 through 7.2.6 and 7.0.1 through 7.0.6 and 6.4.5 through 6.4.7 and 6.2.5, FortiManager version 7.4.0 through 7.4.1 and 7.2.0 through 7.2.4 and 7.0.0 through 7.0.11 and 6.4.0 through 6.4.14, FortiAnalyzer version 7.4.0 through 7.4.1 and 7.2
nvd
CVE-2024-46662P2HIGHCVSS 8.8≥ 7.4.1, < 7.4.4≥ 7.4.1, ≤ 7.4.32025-03-14
CVE-2024-46662 [HIGH] CWE-77 CVE-2024-46662: A improper neutralization of special elements used in a command ('command injection') in Fortinet Fo A improper neutralization of special elements used in a command ('command injection') in Fortinet FortiManager versions 7.4.1 through 7.4.3, FortiManager Cloud versions 7.4.1 through 7.4.3 allows attacker to escalation of privilege via specifically crafted packets
nvd
CVE-2024-48886P2CRITICALCVSS 9.8≥ 7.4.1, < 7.4.4≥ 7.6.0, < 7.6.22025-01-14
CVE-2024-48886 [CRITICAL] CWE-1390 CVE-2024-48886: A weak authentication in Fortinet FortiOS versions 7.4.0 through 7.4.4, 7.2.0 through 7.2.8, 7.0.0 t A weak authentication in Fortinet FortiOS versions 7.4.0 through 7.4.4, 7.2.0 through 7.2.8, 7.0.0 through 7.0.15, 6.4.0 through 6.4.15, FortiProxy versions 7.4.0 through 7.4.4, 7.2.0 through 7.2.10, 7.0.0 through 7.0.17, 2.0.0 through 2.0.14, FortiManager versions 7.6.0 through 7.6.1, 7.4.1 through 7.4.3, FortiManager Cloud versions 7.4.1 throug
nvd
CVE-2024-35276P3CRITICALCVSS 9.8≥ 6.4.0, < 6.4.15≥ 7.0.0, < 7.0.13+6 more2025-01-14
CVE-2024-35276 [CRITICAL] CWE-121 CVE-2024-35276: A stack-based buffer overflow vulnerability in Fortinet FortiAnalyzer 7.4.0 through 7.4.3, FortiAnal A stack-based buffer overflow vulnerability in Fortinet FortiAnalyzer 7.4.0 through 7.4.3, FortiAnalyzer 7.2.0 through 7.2.5, FortiAnalyzer 7.0.0 through 7.0.12, FortiAnalyzer 6.4.0 through 6.4.14, FortiAnalyzer Cloud 7.4.1 through 7.4.3, FortiAnalyzer Cloud 7.2.1 through 7.2.5, FortiAnalyzer Cloud 7.0.1 through 7.0.11, FortiAnalyzer Cloud 6.4 all
nvd
CVE-2023-41679P3CRITICALCVSS 9.6≥ 6.0.0, ≤ 6.0.12≥ 6.2.0, ≤ 6.2.12+6 more2023-10-10
CVE-2023-41679 [CRITICAL] CWE-284 CVE-2023-41679: An improper access control vulnerability [CWE-284] in FortiManager management interface 7.2.0 throug An improper access control vulnerability [CWE-284] in FortiManager management interface 7.2.0 through 7.2.2, 7.0.0 through 7.0.7, 6.4.0 through 6.4.11, 6.2 all versions, 6.0 all versions may allow a remote and authenticated attacker with at least "device management" permission on his profile and belonging to a specific ADOM to add and delete CLI s
nvd
CVE-2024-47571P3CRITICALCVSS 9.8≥ 7.0.7, < 7.0.9v6.4.12+3 more2025-01-14
CVE-2024-47571 [CRITICAL] CWE-672 CVE-2024-47571: An operation on a resource after expiration or release in Fortinet FortiManager 6.4.12 through 7.4.0 An operation on a resource after expiration or release in Fortinet FortiManager 6.4.12 through 7.4.0 allows an attacker to gain improper access to FortiGate via valid credentials.
nvd
CVE-2024-35275P3HIGHCVSS 8.8≥ 7.4.0, < 7.4.3≥ 7.4.0, ≤ 7.4.22025-01-14
CVE-2024-35275 [HIGH] CWE-89 CVE-2024-35275: A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet F A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiAnalyzer version 7.4.0 through 7.4.2, FortiManager version 7.4.0 through 7.4.2 allows attacker to escalation of privilege via specially crafted http requests.
nvd
CVE-2015-3611P3HIGHCVSS 8.8≥ 5.0.0, ≤ 5.0.10≥ 5.2.0, ≤ 5.2.12020-02-04
CVE-2015-3611 [HIGH] CWE-78 CVE-2015-3611: A Command Injection vulnerability exists in FortiManager 5.2.1 and earlier and FortiManager 5.0.10 a A Command Injection vulnerability exists in FortiManager 5.2.1 and earlier and FortiManager 5.0.10 and earlier via unspecified vectors, which could let a malicious user run systems commands when executing a report.
nvd
CVE-2026-22572P3HIGHCVSS 7.2≥ 7.2.2, < 7.4.8≥ 7.6.0, < 7.6.4+3 more2026-03-10
CVE-2026-22572 [HIGH] CWE-288 CVE-2026-22572: An authentication bypass using an alternate path or channel vulnerability in Fortinet FortiAnalyzer An authentication bypass using an alternate path or channel vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.3, FortiAnalyzer 7.4.0 through 7.4.7, FortiAnalyzer 7.2.2 through 7.2.11, FortiManager 7.6.0 through 7.6.3, FortiManager 7.4.0 through 7.4.7, FortiManager 7.2.2 through 7.2.11 may allow an attacker with knowledge of the admins password
nvd
Fortinet Fortimanager vulnerabilities | cvebase