cbcvebase.

Fortinet Fortimanager vulnerabilities

116 known vulnerabilities affecting fortinet/fortimanager.

Total CVEs
116
CISA KEV
2
actively exploited
Public exploits
1
Exploited in wild
2
Severity breakdown
CRITICAL14HIGH39MEDIUM57LOW6

Vulnerabilities

Page 2 of 6
CVE-2026-22572P3HIGHCVSS 7.2≥ 7.2.2, < 7.4.8≥ 7.6.0, < 7.6.4+3 more2026-03-10
CVE-2026-22572 [HIGH] CWE-288 CVE-2026-22572: An authentication bypass using an alternate path or channel vulnerability in Fortinet FortiAnalyzer An authentication bypass using an alternate path or channel vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.3, FortiAnalyzer 7.4.0 through 7.4.7, FortiAnalyzer 7.2.2 through 7.2.11, FortiManager 7.6.0 through 7.6.3, FortiManager 7.4.0 through 7.4.7, FortiManager 7.2.2 through 7.2.11 may allow an attacker with knowledge of the admins password
nvd
CVE-2024-35273P3HIGHCVSS 8.8≥ 7.4.0, < 7.4.3≥ 7.4.0, ≤ 7.4.22025-01-14
CVE-2024-35273 [HIGH] CWE-787 CVE-2024-35273: A out-of-bounds write in Fortinet FortiManager version 7.4.0 through 7.4.2, FortiAnalyzer version 7. A out-of-bounds write in Fortinet FortiManager version 7.4.0 through 7.4.2, FortiAnalyzer version 7.4.0 through 7.4.2 allows attacker to escalation of privilege via specially crafted http requests.
nvd
CVE-2022-22300P3HIGHCVSS 8.8≥ 5.6.0, ≤ 5.6.11≥ 6.0.0, ≤ 6.0.11+3 more2022-03-01
CVE-2022-22300 [HIGH] CWE-755 CVE-2022-22300: A improper handling of insufficient permissions or privileges in Fortinet FortiAnalyzer version 5.6. A improper handling of insufficient permissions or privileges in Fortinet FortiAnalyzer version 5.6.0 through 5.6.11, FortiAnalyzer version 6.0.0 through 6.0.11, FortiAnalyzer version 6.2.0 through 6.2.9, FortiAnalyzer version 6.4.0 through 6.4.7, FortiAnalyzer version 7.0.0 through 7 .0.2, FortiManager version 5.6.0 through 5.6.11, FortiManager versi
nvd
CVE-2024-40584P3HIGHCVSS 7.2≥ 6.2.2, ≤ 6.2.13≥ 6.4.0, < 7.2.6+5 more2025-02-11
CVE-2024-40584 [HIGH] CWE-78 CVE-2024-40584: An improper neutralization of special elements used in an OS command ('OS Command Injection') vulner An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiAnalyzer version 7.4.0 through 7.4.3, 7.2.0 through 7.2.5, 7.0.0 through 7.0.13, 6.4.0 through 6.4.15 and 6.2.2 through 6.2.13, Fortinet FortiManager version 7.4.0 through 7.4.3, 7.2.0 through 7.2.5, 7.0.0 through 7.0.13
nvd
CVE-2024-48889P3HIGHCVSS 7.2≥ 6.4.10, < 6.4.15≥ 7.0.5, < 7.0.13+7 more2024-12-18
CVE-2024-48889 [HIGH] CWE-78 CVE-2024-48889: An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulner An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] in FortiManager version 7.6.0, version 7.4.4 and below, version 7.2.7 and below, version 7.0.12 and below, version 6.4.14 and below and FortiManager Cloud version 7.4.4 and below, version 7.2.7 to 7.2.1, version 7.0.12 to 7.0.1 may allow
nvd
CVE-2021-26104P3HIGHCVSS 7.8≥ 5.6.0, < 6.0.11≥ 6.2.0, < 6.2.8+1 more2022-04-06
CVE-2021-26104 [HIGH] CWE-78 CVE-2021-26104: Multiple OS command injection (CWE-78) vulnerabilities in the command line interface of FortiManager Multiple OS command injection (CWE-78) vulnerabilities in the command line interface of FortiManager 6.2.7 and below, 6.4.5 and below and all versions of 6.2.x, 6.0.x and 5.6.x, FortiAnalyzer 6.2.7 and below, 6.4.5 and below and all versions of 6.2.x, 6.0.x and 5.6.x, and FortiPortal 5.2.5 and below, 5.3.5 and below and 6.0.4 and below may allow a loca
nvd
CVE-2022-27483P3HIGHCVSS 7.2≥ 6.0.0, ≤ 6.0.11≥ 6.2.0, ≤ 6.2.9+2 more2022-07-19
CVE-2022-27483 [HIGH] CWE-78 CVE-2022-27483: A improper neutralization of special elements used in an os command ('os command injection') in Fort A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiManager version 7.0.0 through 7.0.3, 6.4.0 through 6.4.7, 6.2.x and 6.0.x and FortiAnalyzer version 7.0.0 through 7.0.3, version 6.4.0 through 6.4.7, 6.2.x and 6.0.x allows attacker to execute arbitrary shell code as `root` user via `diagnose s
nvd
CVE-2021-24006P3HIGHCVSS 8.8≥ 6.4.0, < 6.4.42021-09-06
CVE-2021-24006 [HIGH] CVE-2021-24006: An improper access control vulnerability in FortiManager versions 6.4.0 to 6.4.3 may allow an authen An improper access control vulnerability in FortiManager versions 6.4.0 to 6.4.3 may allow an authenticated attacker with a restricted user profile to access the SD-WAN Orchestrator panel via directly visiting its URL.
nvd
CVE-2023-25607P3HIGHCVSS 7.8≥ 6.0.0, ≤ 6.0.12≥ 6.2.0, ≤ 6.2.12+6 more2023-10-10
CVE-2023-25607 [HIGH] CWE-78 CVE-2023-25607: An improper neutralization of special elements used in an OS Command ('OS Command Injection') vulner An improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78 ] in FortiManager 7.2.0 through 7.2.2, 7.0.0 through 7.0.7, 6.4.0 through 6.4.11, 6.2 all versions, 6.0 all versions, FortiAnalyzer 7.2.0 through 7.2.2, 7.0.0 through 7.0.7, 6.4.0 through 6.4.11, 6.2 all versions, 6.0 all versions and For
nvd
CVE-2024-35277P3HIGHCVSS 7.5≥ 6.4.0, < 6.4.15≥ 7.0.0, < 7.0.13+6 more2025-01-14
CVE-2024-35277 [HIGH] CWE-306 CVE-2024-35277: A missing authentication for critical function in Fortinet FortiPortal version 6.0.0 through 6.0.15, A missing authentication for critical function in Fortinet FortiPortal version 6.0.0 through 6.0.15, FortiManager version 7.4.0 through 7.4.2, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14 allows attacker to access to the configuration of the managed devices by sending specifically crafted packets
nvd
CVE-2025-61848P3HIGHCVSS 7.2≥ 7.0.0, < 7.4.9≥ 7.6.0, < 7.6.5+1 more2026-04-14
CVE-2025-61848 [HIGH] CWE-89 CVE-2025-61848: An improper neutralization of special elements used in an sql command ('sql injection') vulnerabilit An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0 through 7.4.8, FortiAnalyzer 7.2 all versions, FortiAnalyzer 7.0 all versions, FortiAnalyzer Cloud 7.6.2 through 7.6.3, FortiAnalyzer-BigData 7.6.0 through 7.6.1, FortiAnalyzer-BigData
nvd
CVE-2023-22642P3HIGHCVSS 8.1≥ 6.4.8, < 6.4.11≥ 7.0.0, < 7.0.6+5 more2023-04-11
CVE-2023-22642 [HIGH] CWE-295 CVE-2023-22642: An improper certificate validation vulnerability [CWE-295] in FortiAnalyzer and FortiManager 7.2.0 t An improper certificate validation vulnerability [CWE-295] in FortiAnalyzer and FortiManager 7.2.0 through 7.2.1, 7.0.0 through 7.0.5, 6.4.8 through 6.4.10 may allow a remote and unauthenticated attacker to perform a Man-in-the-Middle attack on the communication channel between the device and the remote FortiGuard server hosting outbreakalert ressourc
nvd
CVE-2024-36512P3HIGHCVSS 7.2≥ 6.2.10, < 7.0.13≥ 7.2.0, < 7.2.6+5 more2025-01-14
CVE-2024-36512 [HIGH] CWE-22 CVE-2024-36512: An improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiM An improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiManager, FortiAnalyzer 7.4.0 through 7.4.3 and 7.2.0 through 7.2.5 and 7.0.2 through 7.0.12 and 6.2.10 through 6.2.13 allows attacker to execute unauthorized code or commands via crafted HTTP or HTTPS requests.
nvd
CVE-2024-26013P3HIGHCVSS 7.5≥ 6.2.0, < 6.2.14≥ 6.4.0, < 6.4.15+8 more2025-04-08
CVE-2024-26013 [HIGH] CWE-923 CVE-2024-26013: A improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in For A improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in Fortinet FortiOS version 7.4.0 through 7.4.4, 7.2.0 through 7.2.8, 7.0.0 through 7.0.15, 6.4.0 through 6.4.15 and before 6.2.16, Fortinet FortiProxy version 7.4.0 through 7.4.2, 7.2.0 through 7.2.9 and before 7.0.15, Fortinet FortiManager version 7.4.0 thr
nvd
CVE-2025-68648P3HIGHCVSS 7.2≥ 7.0.0, < 7.4.8≥ 7.6.0, < 7.6.5+4 more2026-03-10
CVE-2025-68648 [HIGH] CWE-134 CVE-2025-68648: A use of externally-controlled format string vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7 A use of externally-controlled format string vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0 through 7.4.7, FortiAnalyzer 7.2 all versions, FortiAnalyzer 7.0 all versions, FortiAnalyzer Cloud 7.6.2, FortiAnalyzer Cloud 7.4.1 through 7.4.7, FortiAnalyzer Cloud 7.2 all versions, FortiAnalyzer Cloud 7.0 all versions, Fort
nvd
CVE-2025-48418P3HIGHCVSS 7.2≥ 6.4.0, < 7.0.15≥ 7.2.0, < 7.2.11+7 more2026-03-10
CVE-2025-48418 [HIGH] CWE-912 CVE-2025-48418: A hidden functionality vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.3, FortiAnalyzer 7. A hidden functionality vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.3, FortiAnalyzer 7.4.0 through 7.4.7, FortiAnalyzer 7.2.0 through 7.2.10, FortiAnalyzer 7.0.0 through 7.0.14, FortiAnalyzer 6.4 all versions, FortiAnalyzer Cloud 7.6.2, FortiAnalyzer Cloud 7.4.1 through 7.4.7, FortiAnalyzer Cloud 7.2.1 through 7.2.10, FortiAnalyzer Cloud
nvd
CVE-2015-3613P3CRITICALCVSS 9.8≥ 5.0.0, ≤ 5.0.10≥ 5.2.0, ≤ 5.2.12020-02-04
CVE-2015-3613 [CRITICAL] CWE-269 CVE-2015-3613: A vulnerability exists in in FortiManager 5.2.1 and earlier and 5.0.10 and earlier in the WebUI FTP A vulnerability exists in in FortiManager 5.2.1 and earlier and 5.0.10 and earlier in the WebUI FTP backup page
nvd
CVE-2024-33502P3HIGHCVSS 7.2≥ 6.0.0, < 7.2.6≥ 7.4.0, < 7.4.3+6 more2025-01-14
CVE-2024-33502 [HIGH] CWE-22 CVE-2024-33502: An improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiM An improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiManager, FortiAnalyzer versions 7.4.0 through 7.4.2 and 7.2.0 through 7.2.5 and 7.0.0 through 7.0.12 and 6.4.0 through 6.4.14 and 6.2.0 through 6.2.12 and 6.0.0 through 6.0.12 allows attacker to execute unauthorized code or commands via crafted HTTP or HT
nvd
CVE-2024-50571P3HIGHCVSS 7.2≥ 6.0.0, < 7.0.14≥ 7.2.0, < 7.2.10+9 more2025-10-14
CVE-2024-50571 [HIGH] CWE-122 CVE-2024-50571: A heap-based buffer overflow vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.2, FortiAnaly A heap-based buffer overflow vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.2, FortiAnalyzer 7.4.0 through 7.4.5, FortiAnalyzer 7.2.0 through 7.2.9, FortiAnalyzer 7.0.0 through 7.0.13, FortiAnalyzer 6.4 all versions, FortiAnalyzer 6.2 all versions, FortiAnalyzer 6.0 all versions, FortiAnalyzer Cloud 7.4.1 through 7.4.5, FortiAnalyzer Cloud
nvd
CVE-2019-6695P3CRITICALCVSS 9.8≤ 6.0.6v6.2.02019-08-23
CVE-2019-6695 [CRITICAL] CWE-345 CVE-2019-6695: Lack of root file system integrity checking in Fortinet FortiManager VM application images of 6.2.0, Lack of root file system integrity checking in Fortinet FortiManager VM application images of 6.2.0, 6.0.6 and below may allow an attacker to implant third-party programs by recreating the image through specific methods.
nvd