cbcvebase.

Fortinet Fortimanager vulnerabilities

114 known vulnerabilities affecting fortinet/fortimanager.

Total CVEs
114
CISA KEV
2
actively exploited
Public exploits
1
Exploited in wild
2
Severity breakdown
CRITICAL14HIGH38MEDIUM56LOW6

Vulnerabilities

Page 2 of 6
CVE-2024-35273P3HIGHCVSS 8.8≥ 7.4.0, < 7.4.3≥ 7.4.0, ≤ 7.4.22025-01-14
CVE-2024-35273 [HIGH] CWE-787 CVE-2024-35273: A out-of-bounds write in Fortinet FortiManager version 7.4.0 through 7.4.2, FortiAnalyzer version 7. A out-of-bounds write in Fortinet FortiManager version 7.4.0 through 7.4.2, FortiAnalyzer version 7.4.0 through 7.4.2 allows attacker to escalation of privilege via specially crafted http requests.
nvd
CVE-2022-22300P3HIGHCVSS 8.8≥ 5.6.0, ≤ 5.6.11≥ 6.0.0, ≤ 6.0.11+3 more2022-03-01
CVE-2022-22300 [HIGH] CWE-755 CVE-2022-22300: A improper handling of insufficient permissions or privileges in Fortinet FortiAnalyzer version 5.6. A improper handling of insufficient permissions or privileges in Fortinet FortiAnalyzer version 5.6.0 through 5.6.11, FortiAnalyzer version 6.0.0 through 6.0.11, FortiAnalyzer version 6.2.0 through 6.2.9, FortiAnalyzer version 6.4.0 through 6.4.7, FortiAnalyzer version 7.0.0 through 7 .0.2, FortiManager version 5.6.0 through 5.6.11, FortiManager versi
nvd
CVE-2024-40584P3HIGHCVSS 7.2≥ 6.2.2, ≤ 6.2.13≥ 6.4.0, < 7.2.6+5 more2025-02-11
CVE-2024-40584 [HIGH] CWE-78 CVE-2024-40584: An improper neutralization of special elements used in an OS command ('OS Command Injection') vulner An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiAnalyzer version 7.4.0 through 7.4.3, 7.2.0 through 7.2.5, 7.0.0 through 7.0.13, 6.4.0 through 6.4.15 and 6.2.2 through 6.2.13, Fortinet FortiManager version 7.4.0 through 7.4.3, 7.2.0 through 7.2.5, 7.0.0 through 7.0.13
nvd
CVE-2024-48889P3HIGHCVSS 7.2≥ 6.4.10, < 6.4.15≥ 7.0.5, < 7.0.13+7 more2024-12-18
CVE-2024-48889 [HIGH] CWE-78 CVE-2024-48889: An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulner An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] in FortiManager version 7.6.0, version 7.4.4 and below, version 7.2.7 and below, version 7.0.12 and below, version 6.4.14 and below and FortiManager Cloud version 7.4.4 and below, version 7.2.7 to 7.2.1, version 7.0.12 to 7.0.1 may allow
nvd
CVE-2021-26104P3HIGHCVSS 7.8≥ 5.6.0, < 6.0.11≥ 6.2.0, < 6.2.8+1 more2022-04-06
CVE-2021-26104 [HIGH] CWE-78 CVE-2021-26104: Multiple OS command injection (CWE-78) vulnerabilities in the command line interface of FortiManager Multiple OS command injection (CWE-78) vulnerabilities in the command line interface of FortiManager 6.2.7 and below, 6.4.5 and below and all versions of 6.2.x, 6.0.x and 5.6.x, FortiAnalyzer 6.2.7 and below, 6.4.5 and below and all versions of 6.2.x, 6.0.x and 5.6.x, and FortiPortal 5.2.5 and below, 5.3.5 and below and 6.0.4 and below may allow a loca
nvd
CVE-2022-27483P3HIGHCVSS 7.2≥ 6.0.0, ≤ 6.0.11≥ 6.2.0, ≤ 6.2.9+2 more2022-07-19
CVE-2022-27483 [HIGH] CWE-78 CVE-2022-27483: A improper neutralization of special elements used in an os command ('os command injection') in Fort A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiManager version 7.0.0 through 7.0.3, 6.4.0 through 6.4.7, 6.2.x and 6.0.x and FortiAnalyzer version 7.0.0 through 7.0.3, version 6.4.0 through 6.4.7, 6.2.x and 6.0.x allows attacker to execute arbitrary shell code as `root` user via `diagnose s
nvd
CVE-2021-24006P3HIGHCVSS 8.8≥ 6.4.0, < 6.4.42021-09-06
CVE-2021-24006 [HIGH] CVE-2021-24006: An improper access control vulnerability in FortiManager versions 6.4.0 to 6.4.3 may allow an authen An improper access control vulnerability in FortiManager versions 6.4.0 to 6.4.3 may allow an authenticated attacker with a restricted user profile to access the SD-WAN Orchestrator panel via directly visiting its URL.
nvd
CVE-2023-25607P3HIGHCVSS 7.8≥ 6.0.0, ≤ 6.0.12≥ 6.2.0, ≤ 6.2.12+6 more2023-10-10
CVE-2023-25607 [HIGH] CWE-78 CVE-2023-25607: An improper neutralization of special elements used in an OS Command ('OS Command Injection') vulner An improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78 ] in FortiManager 7.2.0 through 7.2.2, 7.0.0 through 7.0.7, 6.4.0 through 6.4.11, 6.2 all versions, 6.0 all versions, FortiAnalyzer 7.2.0 through 7.2.2, 7.0.0 through 7.0.7, 6.4.0 through 6.4.11, 6.2 all versions, 6.0 all versions and For
nvd
CVE-2024-35277P3HIGHCVSS 7.5≥ 6.4.0, < 6.4.15≥ 7.0.0, < 7.0.13+6 more2025-01-14
CVE-2024-35277 [HIGH] CWE-306 CVE-2024-35277: A missing authentication for critical function in Fortinet FortiPortal version 6.0.0 through 6.0.15, A missing authentication for critical function in Fortinet FortiPortal version 6.0.0 through 6.0.15, FortiManager version 7.4.0 through 7.4.2, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14 allows attacker to access to the configuration of the managed devices by sending specifically crafted packets
nvd
CVE-2025-61848P3HIGHCVSS 7.2≥ 7.0.0, < 7.4.9≥ 7.6.0, < 7.6.5+1 more2026-04-14
CVE-2025-61848 [HIGH] CWE-89 CVE-2025-61848: An improper neutralization of special elements used in an sql command ('sql injection') vulnerabilit An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0 through 7.4.8, FortiAnalyzer 7.2 all versions, FortiAnalyzer 7.0 all versions, FortiAnalyzer Cloud 7.6.0 through 7.6.4, FortiAnalyzer Cloud 7.4.0 through 7.4.8, FortiAnalyzer Cloud 7.2
nvd
CVE-2024-50571P3HIGHCVSS 7.2≥ 6.0.0, < 7.0.14≥ 7.2.0, < 7.2.10+9 more2025-10-14
CVE-2024-50571 [HIGH] CWE-122 CVE-2024-50571: A heap-based buffer overflow vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.2, FortiAnaly A heap-based buffer overflow vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.2, FortiAnalyzer 7.4.0 through 7.4.5, FortiAnalyzer 7.2.0 through 7.2.9, FortiAnalyzer 7.0.0 through 7.0.13, FortiAnalyzer 6.4 all versions, FortiAnalyzer 6.2 all versions, FortiAnalyzer 6.0 all versions, FortiAnalyzer Cloud 7.4.1 through 7.4.5, FortiAnalyzer Cloud
nvd
CVE-2023-22642P3HIGHCVSS 8.1≥ 6.4.8, < 6.4.11≥ 7.0.0, < 7.0.6+5 more2023-04-11
CVE-2023-22642 [HIGH] CWE-295 CVE-2023-22642: An improper certificate validation vulnerability [CWE-295] in FortiAnalyzer and FortiManager 7.2.0 t An improper certificate validation vulnerability [CWE-295] in FortiAnalyzer and FortiManager 7.2.0 through 7.2.1, 7.0.0 through 7.0.5, 6.4.8 through 6.4.10 may allow a remote and unauthenticated attacker to perform a Man-in-the-Middle attack on the communication channel between the device and the remote FortiGuard server hosting outbreakalert ressourc
nvd
CVE-2024-36512P3HIGHCVSS 7.2≥ 6.2.10, < 7.0.13≥ 7.2.0, < 7.2.6+5 more2025-01-14
CVE-2024-36512 [HIGH] CWE-22 CVE-2024-36512: An improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiM An improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiManager, FortiAnalyzer 7.4.0 through 7.4.3 and 7.2.0 through 7.2.5 and 7.0.2 through 7.0.12 and 6.2.10 through 6.2.13 allows attacker to execute unauthorized code or commands via crafted HTTP or HTTPS requests.
nvd
CVE-2024-26013P3HIGHCVSS 7.5≥ 6.2.0, < 6.2.14≥ 6.4.0, < 6.4.15+8 more2025-04-08
CVE-2024-26013 [HIGH] CWE-923 CVE-2024-26013: A improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in For A improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in Fortinet FortiOS version 7.4.0 through 7.4.4, 7.2.0 through 7.2.8, 7.0.0 through 7.0.15, 6.4.0 through 6.4.15 and before 6.2.16, Fortinet FortiProxy version 7.4.0 through 7.4.2, 7.2.0 through 7.2.9 and before 7.0.15, Fortinet FortiManager version 7.4.0 thr
nvd
CVE-2025-68648P3HIGHCVSS 7.2≥ 7.0.0, < 7.4.8≥ 7.6.0, < 7.6.5+4 more2026-03-10
CVE-2025-68648 [HIGH] CWE-134 CVE-2025-68648: A use of externally-controlled format string vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7 A use of externally-controlled format string vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0 through 7.4.7, FortiAnalyzer 7.2 all versions, FortiAnalyzer 7.0 all versions, FortiAnalyzer Cloud 7.6.2, FortiAnalyzer Cloud 7.4.1 through 7.4.7, FortiAnalyzer Cloud 7.2 all versions, FortiAnalyzer Cloud 7.0 all versions, Fort
nvd
CVE-2025-48418P3HIGHCVSS 7.2≥ 6.4.0, < 7.0.15≥ 7.2.0, < 7.2.11+7 more2026-03-10
CVE-2025-48418 [HIGH] CWE-912 CVE-2025-48418: A hidden functionality vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.3, FortiAnalyzer 7. A hidden functionality vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.3, FortiAnalyzer 7.4.0 through 7.4.7, FortiAnalyzer 7.2.0 through 7.2.10, FortiAnalyzer 7.0.0 through 7.0.14, FortiAnalyzer 6.4 all versions, FortiAnalyzer Cloud 7.6.2, FortiAnalyzer Cloud 7.4.1 through 7.4.7, FortiAnalyzer Cloud 7.2.1 through 7.2.10, FortiAnalyzer Cloud
nvd
CVE-2015-3613P3CRITICALCVSS 9.8≥ 5.0.0, ≤ 5.0.10≥ 5.2.0, ≤ 5.2.12020-02-04
CVE-2015-3613 [CRITICAL] CWE-269 CVE-2015-3613: A vulnerability exists in in FortiManager 5.2.1 and earlier and 5.0.10 and earlier in the WebUI FTP A vulnerability exists in in FortiManager 5.2.1 and earlier and 5.0.10 and earlier in the WebUI FTP backup page
nvd
CVE-2024-33502P3HIGHCVSS 7.2≥ 6.0.0, < 7.2.6≥ 7.4.0, < 7.4.3+6 more2025-01-14
CVE-2024-33502 [HIGH] CWE-22 CVE-2024-33502: An improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiM An improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiManager, FortiAnalyzer versions 7.4.0 through 7.4.2 and 7.2.0 through 7.2.5 and 7.0.0 through 7.0.12 and 6.4.0 through 6.4.14 and 6.2.0 through 6.2.12 and 6.0.0 through 6.0.12 allows attacker to execute unauthorized code or commands via crafted HTTP or HT
nvd
CVE-2024-50565P3HIGHCVSS 7.5≥ 6.2.0, < 6.2.14≥ 6.4.0, < 6.4.15+3 more2025-04-08
CVE-2024-50565 [HIGH] CWE-300 CVE-2024-50565: A improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in For A improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in Fortinet FortiOS version 7.4.0 through 7.4.3, 7.2.0 through 7.2.7, 7.0.0 through 7.0.14, 6.4.0 through 6.4.15 and 6.2.0 through 6.2.16, Fortinet FortiProxy version 7.4.0 through 7.4.2, 7.2.0 through 7.2.9, 7.0.0 through 7.0.15 and 2.0.0 through 2.0.14, For
nvd
CVE-2024-33504P3HIGHCVSS 7.7≥ 6.4.0, < 7.2.10≥ 7.4.0, < 7.4.6+6 more2025-02-11
CVE-2024-33504 [HIGH] CWE-321 CVE-2024-33504: A use of hard-coded cryptographic key to encrypt sensitive data vulnerability [CWE-321] in FortiMana A use of hard-coded cryptographic key to encrypt sensitive data vulnerability [CWE-321] in FortiManager 7.6.0 through 7.6.1, 7.4.0 through 7.4.5, 7.2.0 through 7.2.9, 7.0 all versions, 6.4 all versions may allow an attacker with JSON API access permissions to decrypt some secrets even if the 'private-data-encryption' setting is enabled.
nvd
Fortinet Fortimanager vulnerabilities | cvebase