Fortinet Fortimanager vulnerabilities
122 known vulnerabilities affecting fortinet/fortimanager.
Total CVEs
122
CISA KEV
3
actively exploited
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL15HIGH42MEDIUM59LOW6
Vulnerabilities
Page 2 of 7
CVE-2024-26013HIGHCVSS 7.5≥ 6.2.0, < 6.2.14≥ 6.4.0, < 6.4.15+8 more2025-04-08
CVE-2024-26013 [HIGH] CWE-923 CVE-2024-26013: A improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in For
A improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in Fortinet FortiOS version 7.4.0 through 7.4.4, 7.2.0 through 7.2.8, 7.0.0 through 7.0.15, 6.4.0 through 6.4.15 and before 6.2.16, Fortinet FortiProxy version 7.4.0 through 7.4.2, 7.2.0 through 7.2.9 and before 7.0.15, Fortinet FortiManager version 7.4.0 thr
nvdfortinet
CVE-2024-52962MEDIUMCVSS 5.3≥ 7.0.0, < 7.0.14≥ 7.2.0, < 7.2.9+6 more2025-04-08
CVE-2024-52962 [MEDIUM] CWE-117 CVE-2024-52962: An Improper Output Neutralization for Logs vulnerability [CWE-117] in FortiAnalyzer version 7.6.1 an
An Improper Output Neutralization for Logs vulnerability [CWE-117] in FortiAnalyzer version 7.6.1 and below, version 7.4.5 and below, version 7.2.8 and below, version 7.0.13 and below and FortiManager version 7.6.1 and below, version 7.4.5 and below, version 7.2.8 and below, version 7.0.12 and below may allow an unauthenticated remote attacker to po
nvdfortinet
CVE-2023-25610CRITICALCVSS 9.8≥ 6.0.0, < 6.0.12≥ 6.2.0, < 6.2.11+7 more2025-03-24
CVE-2023-25610 [CRITICAL] CWE-124 CVE-2023-25610: A buffer underwrite ('buffer underflow') vulnerability in the administrative interface of Fortinet F
A buffer underwrite ('buffer underflow') vulnerability in the administrative interface of Fortinet FortiOS version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.6, version 6.4.0 through 6.4.11 and version 6.2.12 and below, FortiProxy version 7.2.0 through 7.2.2, version 7.0.0 through 7.0.8, version 2.0.12 and below and FortiOS-6K7K version 7.0.5,
nvdfortinet
CVE-2024-46662HIGHCVSS 8.8≥ 7.4.1, < 7.4.4≥ 7.4.1, ≤ 7.4.32025-03-14
CVE-2024-46662 [HIGH] CWE-77 CVE-2024-46662: A improper neutralization of special elements used in a command ('command injection') in Fortinet Fo
A improper neutralization of special elements used in a command ('command injection') in Fortinet FortiManager versions 7.4.1 through 7.4.3, FortiManager Cloud versions 7.4.1 through 7.4.3 allows attacker to escalation of privilege via specifically crafted packets
nvdfortinet
CVE-2024-40590MEDIUMCVSS 4.82025-03-14
CVE-2024-40590 [MEDIUM] CWE-295 An improper certificate validation vulnerability [CWE-295] in FortiPortal version 7.4.0, version 7.2.4 and below, versio...
FG-IR-22-155: An improper certificate validation vulnerability [CWE-295] in FortiPortal version 7.4.0, version 7.2.4 and below, versio...
An improper certificate validation vulnerability [CWE-295] in FortiPortal version 7.4.0, version 7.2.4 and below, version 7.0.8 and below, version 6.0.15 and below when connecting to a FortiManager device,
fortinet
CVE-2024-40585MEDIUMCVSS 6.5≥ 6.2.0, < 7.0.9≥ 7.2.0, < 7.2.4+5 more2025-03-14
CVE-2024-40585 [MEDIUM] CWE-532 CVE-2024-40585: An insertion of sensitive information into log file vulnerabilities [CWE-532] in FortiManager versio
An insertion of sensitive information into log file vulnerabilities [CWE-532] in FortiManager version 7.4.0, version 7.2.3 and below, version 7.0.8 and below, version 6.4.12 and below, version 6.2.11 and below and FortiAnalyzer version 7.4.0, version 7.2.3 and below, version 7.0.8 and below, version 6.4.12 and below, version 6.2.11 and below eventlo
nvdfortinet
CVE-2024-32123MEDIUMCVSS 6.7≥ 4.3.4, < 7.2.6≥ 7.4.0, < 7.4.4+11 more2025-03-11
CVE-2024-32123 [MEDIUM] CWE-78 CVE-2024-32123: Multiple improper neutralization of special elements used in an os command ('os command injection')
Multiple improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiManager, FortiAnalyzer versions 7.4.0 through 7.4.2
7.2.0 through 7.2.5 and 7.0.0 through 7.0.12 and 6.4.0 through 6.4.14 and 6.2.0 through 6.2.12 and 6.0.0 through 6.0.12 and 5.6.0 through 5.6.11 and 5.4.0 through 5.4.7 and 5.2.0 throu
nvdfortinet
CVE-2024-33501MEDIUMCVSS 6.7≥ 6.0.10, ≤ 6.0.12≥ 6.2.8, < 7.2.6+6 more2025-03-11
CVE-2024-33501 [MEDIUM] CWE-89 CVE-2024-33501: Two improper neutralization of special elements used in an SQL Command ('SQL Injection') vulnerabili
Two improper neutralization of special elements used in an SQL Command ('SQL Injection') vulnerability [CWE-89] in Fortinet FortiAnalyzer version 7.4.0 through 7.4.2 and before 7.2.5, FortiManager version 7.4.0 through 7.4.2 and before 7.2.5 and FortiAnalyzer-BigData version 7.4.0 and before 7.2.7 allows a privileged attacker to execute unauthorized
nvdfortinet
CVE-2024-33504HIGHCVSS 7.7≥ 6.4.0, < 7.2.10≥ 7.4.0, < 7.4.6+6 more2025-02-11
CVE-2024-33504 [HIGH] CWE-321 CVE-2024-33504: A use of hard-coded cryptographic key to encrypt sensitive data vulnerability [CWE-321] in FortiMana
A use of hard-coded cryptographic key to encrypt sensitive data vulnerability [CWE-321] in FortiManager 7.6.0 through 7.6.1, 7.4.0 through 7.4.5, 7.2.0 through 7.2.9, 7.0 all versions, 6.4 all versions may allow an attacker with JSON API access permissions to decrypt some secrets even if the 'private-data-encryption' setting is enabled.
nvdfortinet
CVE-2024-40584HIGHCVSS 7.2≥ 6.2.2, ≤ 6.2.13≥ 6.4.0, < 7.2.6+5 more2025-02-11
CVE-2024-40584 [HIGH] CWE-78 CVE-2024-40584: An improper neutralization of special elements used in an OS command ('OS Command Injection') vulner
An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiAnalyzer version 7.4.0 through 7.4.3, 7.2.0 through 7.2.5, 7.0.0 through 7.0.13, 6.4.0 through 6.4.15 and 6.2.2 through 6.2.13, Fortinet FortiManager version 7.4.0 through 7.4.3, 7.2.0 through 7.2.5, 7.0.0 through 7.0.13
nvdfortinet
CVE-2024-36508MEDIUMCVSS 6.0≥ 6.4.0, < 7.2.6≥ 7.4.0, < 7.4.3+4 more2025-02-11
CVE-2024-36508 [MEDIUM] CWE-22 CVE-2024-36508: An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE
An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in Fortinet FortiManager version 7.4.0 through 7.4.2 and before 7.2.5 and Fortinet FortiAnalyzer version 7.4.0 through 7.4.2 and before 7.2.5 CLI allows an authenticated admin user with diagnose privileges to delete files on the system.
nvdfortinet
CVE-2022-23439MEDIUMCVSS 6.1≥ 7.4.0, ≤ 7.4.3≥ 7.2.0, ≤ 7.2.11+3 more2025-01-22
CVE-2022-23439 [MEDIUM] CWE-610 CVE-2022-23439: A externally controlled reference to a resource in another sphere vulnerability in Fortinet allows
A externally controlled reference to a resource in another sphere vulnerability in Fortinet allows attacker to poison web caches via crafted HTTP requests, where the `Host` header points to an arbitrary webserver
nvd
CVE-2024-50563CRITICALCVSS 9.8≥ 7.4.1, < 7.4.4≥ 7.6.0, < 7.6.2+2 more2025-01-16
CVE-2024-50563 [CRITICAL] CWE-1390 CVE-2024-50563: A weak authentication in Fortinet FortiManager Cloud, FortiAnalyzer versions 7.6.0 through 7.6.1, 7.
A weak authentication in Fortinet FortiManager Cloud, FortiAnalyzer versions 7.6.0 through 7.6.1, 7.4.1 through 7.4.3, FortiAnalyzer Cloud versions 7.4.1 through 7.4.3, FortiManager versions 7.6.0 through 7.6.1, 7.4.1 through 7.4.3, FortiManager Cloud versions 7.4.1 through 7.4.3 allows attacker to execute unauthorized code or commands via a brut
nvd
CVE-2024-45331HIGHCVSS 7.8≥ 6.4.0, < 7.2.6≥ 7.4.0, < 7.4.4+4 more2025-01-16
CVE-2024-45331 [HIGH] CWE-266 CVE-2024-45331: A incorrect privilege assignment in Fortinet FortiAnalyzer versions 7.4.0 through 7.4.3, 7.2.0 throu
A incorrect privilege assignment in Fortinet FortiAnalyzer versions 7.4.0 through 7.4.3, 7.2.0 through 7.2.5, 7.0.0 through 7.0.13, 6.4.0 through 6.4.15, FortiManager versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.5, 7.0.0 through 7.0.13, 6.4.0 through 6.4.15, FortiAnalyzer Cloud versions 7.4.1 through 7.4.2, 7.2.1 through 7.2.6, 7.0.1 through 7.0.13
nvd
CVE-2024-47571CRITICALCVSS 9.8≥ 7.0.7, < 7.0.9v6.4.12+3 more2025-01-14
CVE-2024-47571 [CRITICAL] CWE-672 CVE-2024-47571: An operation on a resource after expiration or release in Fortinet FortiManager 6.4.12 through 7.4.0
An operation on a resource after expiration or release in Fortinet FortiManager 6.4.12 through 7.4.0 allows an attacker to gain improper access to FortiGate via valid credentials.
nvdfortinet
CVE-2024-35276CRITICALCVSS 9.8≥ 6.4.0, < 6.4.15≥ 7.0.0, < 7.0.13+6 more2025-01-14
CVE-2024-35276 [CRITICAL] CWE-121 CVE-2024-35276: A stack-based buffer overflow in Fortinet FortiAnalyzer versions 7.4.0 through 7.4.3, 7.2.0 through
A stack-based buffer overflow in Fortinet FortiAnalyzer versions 7.4.0 through 7.4.3, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14, FortiManager versions 7.4.0 through 7.4.3, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14, FortiManager Cloud versions 7.4.1 through 7.4.3, 7.2.1 through 7.2.5, 7.0.1 through 7.0.11,
nvdfortinet
CVE-2024-48884CRITICALCVSS 9.1≥ 7.4.1, < 7.4.4≥ 7.6.0, < 7.6.2+2 more2025-01-14
CVE-2024-48884 [CRITICAL] CWE-22 CVE-2024-48884: A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fo
A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiManager 7.6.0 through 7.6.1, FortiManager 7.4.1 through 7.4.3, FortiManager Cloud 7.4.1 through 7.4.3, FortiOS 7.6.0, FortiOS 7.4.0 through 7.4.4, FortiOS 7.2.0 through 7.2.9, FortiOS 7.0.0 through 7.0.15, FortiOS 6.4.0 through 6.4.15, Fo
nvdfortinet
CVE-2024-48886CRITICALCVSS 9.8≥ 7.4.1, < 7.4.4≥ 7.6.0, < 7.6.22025-01-14
CVE-2024-48886 [CRITICAL] CWE-1390 CVE-2024-48886: A weak authentication in Fortinet FortiOS versions 7.4.0 through 7.4.4, 7.2.0 through 7.2.8, 7.0.0 t
A weak authentication in Fortinet FortiOS versions 7.4.0 through 7.4.4, 7.2.0 through 7.2.8, 7.0.0 through 7.0.15, 6.4.0 through 6.4.15, FortiProxy versions 7.4.0 through 7.4.4, 7.2.0 through 7.2.10, 7.0.0 through 7.0.17, 2.0.0 through 2.0.14, FortiManager versions 7.6.0 through 7.6.1, 7.4.1 through 7.4.3, FortiManager Cloud versions 7.4.1 throug
nvdfortinet
CVE-2024-33503HIGHCVSS 7.8≥ 6.4.0, < 7.2.6≥ 7.4.0, < 7.4.4+4 more2025-01-14
CVE-2024-33503 [HIGH] CWE-266 CVE-2024-33503: A improper privilege management in Fortinet FortiManager version 7.4.0 through 7.4.3, 7.2.0 through
A improper privilege management in Fortinet FortiManager version 7.4.0 through 7.4.3, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14, FortiAnalyzer version 7.4.0 through 7.4.2, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14 allows attacker to escalation of privilege via specific shell commands
nvdfortinet
CVE-2024-35273HIGHCVSS 8.8≥ 7.4.0, < 7.4.3≥ 7.4.0, ≤ 7.4.22025-01-14
CVE-2024-35273 [HIGH] CWE-787 CVE-2024-35273: A out-of-bounds write in Fortinet FortiManager version 7.4.0 through 7.4.2, FortiAnalyzer version 7.
A out-of-bounds write in Fortinet FortiManager version 7.4.0 through 7.4.2, FortiAnalyzer version 7.4.0 through 7.4.2 allows attacker to escalation of privilege via specially crafted http requests.
nvdfortinet