cbcvebase.

Fortinet Fortimanager vulnerabilities

122 known vulnerabilities affecting fortinet/fortimanager.

Total CVEs
122
CISA KEV
3
actively exploited
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL15HIGH42MEDIUM59LOW6

Vulnerabilities

Page 3 of 7
CVE-2024-35275HIGHCVSS 8.8≥ 7.4.0, < 7.4.3≥ 7.4.0, ≤ 7.4.22025-01-14
CVE-2024-35275 [HIGH] CWE-89 CVE-2024-35275: A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet F A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiAnalyzer version 7.4.0 through 7.4.2, FortiManager version 7.4.0 through 7.4.2 allows attacker to escalation of privilege via specially crafted http requests.
nvdfortinet
CVE-2024-36512HIGHCVSS 7.2≥ 6.2.10, < 7.0.13≥ 7.2.0, < 7.2.6+5 more2025-01-14
CVE-2024-36512 [HIGH] CWE-22 CVE-2024-36512: An improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiM An improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiManager, FortiAnalyzer 7.4.0 through 7.4.3 and 7.2.0 through 7.2.5 and 7.0.2 through 7.0.12 and 6.2.10 through 6.2.13 allows attacker to execute unauthorized code or commands via crafted HTTP or HTTPS requests.
nvdfortinet
CVE-2024-35277HIGHCVSS 7.5≥ 6.4.0, < 6.4.15≥ 7.0.0, < 7.0.13+6 more2025-01-14
CVE-2024-35277 [HIGH] CWE-306 CVE-2024-35277: A missing authentication for critical function in Fortinet FortiPortal version 6.0.0 through 6.0.15, A missing authentication for critical function in Fortinet FortiPortal version 6.0.0 through 6.0.15, FortiManager version 7.4.0 through 7.4.2, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14 allows attacker to access to the configuration of the managed devices by sending specifically crafted packets
nvdfortinet
CVE-2024-50566HIGHCVSS 8.8≥ 7.2.1, < 7.2.9≥ 7.4.0, < 7.4.6+4 more2025-01-14
CVE-2024-50566 [HIGH] CWE-78 CVE-2024-50566: A improper neutralization of special elements used in an os command ('os command injection') vulnera A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiManager Cloud 7.6.0 through 7.6.1, FortiManager Cloud 7.4.0 through 7.4.4, FortiManager Cloud 7.2.2 through 7.2.7, FortiManager 7.6.0 through 7.6.1, FortiManager 7.4.0 through 7.4.5, FortiManager 7.2.1 through 7.2.8 may allow an a
nvdfortinet
CVE-2024-33502HIGHCVSS 7.2≥ 6.0.0, < 7.2.6≥ 7.4.0, < 7.4.3+6 more2025-01-14
CVE-2024-33502 [HIGH] CWE-22 CVE-2024-33502: An improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiM An improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiManager, FortiAnalyzer versions 7.4.0 through 7.4.2 and 7.2.0 through 7.2.5 and 7.0.0 through 7.0.12 and 6.4.0 through 6.4.14 and 6.2.0 through 6.2.12 and 6.0.0 through 6.0.12 allows attacker to execute unauthorized code or commands via crafted HTTP or HT
nvdfortinet
CVE-2024-32115MEDIUMCVSS 5.5≥ 7.0.0, < 7.2.6≥ 7.4.0, < 7.4.3+3 more2025-01-14
CVE-2024-32115 [MEDIUM] CWE-23 CVE-2024-32115: A relative path traversal vulnerability [CWE-23] in Fortinet FortiManager version 7.4.0 through 7.4 A relative path traversal vulnerability [CWE-23] in Fortinet FortiManager version 7.4.0 through 7.4.2 and before 7.2.5 allows a privileged attacker to delete files from the underlying filesystem via crafted HTTP or HTTPs requests.
nvdfortinet
CVE-2021-32589CRITICALCVSS 9.8≥ 5.0.0, < 5.6.11≥ 6.0.0, < 6.0.11+10 more2024-12-19
CVE-2021-32589 [CRITICAL] CWE-416 CVE-2021-32589: A Use After Free (CWE-416) vulnerability in FortiManager version 7.0.0, version 6.4.5 and below, ver A Use After Free (CWE-416) vulnerability in FortiManager version 7.0.0, version 6.4.5 and below, version 6.2.7 and below, version 6.0.10 and below, version 5.6.10 and below, version 5.4.7 and below, version 5.2.10 and below, version 5.0.12 and below and FortiAnalyzer version 7.0.0, version 6.4.5 and below, version 6.2.7 and below, version 6.0.10 a
nvdfortinet
CVE-2024-48889HIGHCVSS 7.2≥ 6.4.10, < 6.4.15≥ 7.0.5, < 7.0.13+7 more2024-12-18
CVE-2024-48889 [HIGH] CWE-78 CVE-2024-48889: An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulner An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] in FortiManager version 7.6.0, version 7.4.4 and below, version 7.2.7 and below, version 7.0.12 and below, version 6.4.14 and below and FortiManager Cloud version 7.4.4 and below, version 7.2.7 to 7.2.1, version 7.0.12 to 7.0.1 may allow
nvdfortinet
CVE-2024-26011CRITICALCVSS 9.8≥ 6.4.0, < 6.4.15≥ 7.0.0, < 7.0.12+6 more2024-11-12
CVE-2024-26011 [CRITICAL] CWE-306 CVE-2024-26011: A missing authentication for critical function in Fortinet FortiManager version 7.4.0 through 7.4.2, A missing authentication for critical function in Fortinet FortiManager version 7.4.0 through 7.4.2, 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through 6.4.14, FortiPAM version 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiProxy version 7.4.0 through 7.4.2, 7.2.0 through 7.2.9, 7.0.0 through 7.0.17, 2.0.0 through 2.0.14, 1.2.0 throug
nvdfortinet
CVE-2024-33505HIGHCVSS 7.3≥ 6.0.0, < 7.2.7≥ 7.4.0, < 7.4.3+6 more2024-11-12
CVE-2024-33505 [HIGH] CWE-122 CVE-2024-33505: A heap-based buffer overflow in Fortinet FortiAnalyzer version 7.4.0 through 7.4.2, 7.2.0 through 7. A heap-based buffer overflow in Fortinet FortiAnalyzer version 7.4.0 through 7.4.2, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14, FortiManager version 7.4.0 through 7.4.2, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14 allows attacker to escalation of privilege via specially crafted http requests
nvdfortinet
CVE-2024-23666HIGHCVSS 8.8≥ 6.4.0, < 6.4.15≥ 7.0.0, < 7.0.13+6 more2024-11-12
CVE-2024-23666 [HIGH] CWE-602 CVE-2024-23666: A client-side enforcement of server-side security in Fortinet FortiAnalyzer-BigData at least versi A client-side enforcement of server-side security in Fortinet FortiAnalyzer-BigData at least version 7.4.0 and 7.2.0 through 7.2.6 and 7.0.1 through 7.0.6 and 6.4.5 through 6.4.7 and 6.2.5, FortiManager version 7.4.0 through 7.4.1 and 7.2.0 through 7.2.4 and 7.0.0 through 7.0.11 and 6.4.0 through 6.4.14, FortiAnalyzer version 7.4.0 through 7.4.1 and 7
nvdfortinet
CVE-2023-44255MEDIUMCVSS 4.1≥ 6.2.0, < 7.4.3≥ 7.4.0, ≤ 7.4.2+4 more2024-11-12
CVE-2023-44255 [MEDIUM] CWE-359 CVE-2023-44255: An exposure of sensitive information to an unauthorized actor [CWE-200] in Fortinet FortiManager bef An exposure of sensitive information to an unauthorized actor [CWE-200] in Fortinet FortiManager before 7.4.2, FortiAnalyzer before 7.4.2 and FortiAnalyzer-BigData before 7.2.5 may allow a privileged attacker with administrative read permissions to read event logs of another adom via crafted HTTP or HTTPs requests.
nvdfortinet
CVE-2024-32116MEDIUMCVSS 6.0≥ 6.2.0, < 7.2.6≥ 7.4.0, < 7.4.3+5 more2024-11-12
CVE-2024-32116 [MEDIUM] CWE-23 CVE-2024-32116: Multiple relative path traversal vulnerabilities [CWE-23] in Fortinet FortiManager version 7.4.0 thr Multiple relative path traversal vulnerabilities [CWE-23] in Fortinet FortiManager version 7.4.0 through 7.4.2 and before 7.2.5, FortiAnalyzer version 7.4.0 through 7.4.2 and before 7.2.5 and FortiAnalyzer-BigData version 7.4.0 and before 7.2.7 allows a privileged attacker to delete files from the underlying filesystem via crafted CLI requests.
nvdfortinet
CVE-2024-31496MEDIUMCVSS 6.7≥ 6.2.0, < 7.2.6≥ 7.4.0, < 7.4.3+5 more2024-11-12
CVE-2024-31496 [MEDIUM] CWE-121 CVE-2024-31496: A stack-based buffer overflow vulnerability [CWE-121] in Fortinet FortiManager version 7.4.0 through A stack-based buffer overflow vulnerability [CWE-121] in Fortinet FortiManager version 7.4.0 through 7.4.2 and before 7.2.5, FortiAnalyzer version 7.4.0 through 7.4.2 and before 7.2.5 and FortiAnalyzer-BigData 7.4.0 and before 7.2.7 allows a privileged attacker to execute unauthorized code or commands via crafted CLI requests.
nvdfortinet
CVE-2024-32118MEDIUMCVSS 6.7≥ 6.2.0, < 7.2.6≥ 7.4.0, < 7.4.3+5 more2024-11-12
CVE-2024-32118 [MEDIUM] CWE-78 CVE-2024-32118: Multiple improper neutralization of special elements used in an OS command ('OS Command Injection') Multiple improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] in Fortinet FortiManager version 7.4.0 through 7.4.2 and before 7.2.5, Fortinet FortiAnalyzer version 7.4.0 through 7.4.2 and before 7.2.5 and Fortinet FortiAnalyzer-BigData before 7.4.0 allows an authenticated privileged attack
nvdfortinet
CVE-2024-32117MEDIUMCVSS 4.9≥ 6.2.0, < 7.2.6≥ 7.4.0, < 7.4.3+5 more2024-11-12
CVE-2024-32117 [MEDIUM] CWE-22 CVE-2024-32117: An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in Fortinet FortiManager version 7.4.0 through 7.4.2 and below 7.2.5, FortiAnalyzer version 7.4.0 through 7.4.2 and below 7.2.5 & FortiAnalyzer-BigData version 7.4.0 and below 7.2.7 allows a privileged attacker to read arbitrary files from the und
nvdfortinet
CVE-2024-35274LOWCVSS 2.3≥ 6.2.0, < 7.4.3≥ 7.4.0, ≤ 7.4.2+4 more2024-11-12
CVE-2024-35274 [LOW] CWE-23 CVE-2024-35274: An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in Fortinet FortiAnalyzer versions below 7.4.2, Fortinet FortiManager versions below 7.4.2 and Fortinet FortiAnalyzer-BigData version 7.4.0 and below 7.2.7 allows a privileged attacker with read write administrative privileges to create non-arbitrary
nvdfortinet
CVE-2024-47575CRITICALCVSS 9.8KEVPoC≥ 6.2.0, < 6.2.13≥ 6.4.0, < 6.4.15+9 more2024-10-23
CVE-2024-47575 [CRITICAL] CWE-306 CVE-2024-47575: A missing authentication for critical function in FortiManager 7.6.0, FortiManager 7.4.0 through 7.4 A missing authentication for critical function in FortiManager 7.6.0, FortiManager 7.4.0 through 7.4.4, FortiManager 7.2.0 through 7.2.7, FortiManager 7.0.0 through 7.0.12, FortiManager 6.4.0 through 6.4.14, FortiManager 6.2.0 through 6.2.12, Fortinet FortiManager Cloud 7.4.1 through 7.4.4, FortiManager Cloud 7.2.1 through 7.2.7, FortiManager Clou
nvdfortinet
CVE-2024-33506MEDIUMCVSS 4.3≥ 7.0.0, < 7.2.6≥ 7.4.0, < 7.4.3+3 more2024-10-08
CVE-2024-33506 [MEDIUM] CWE-200 CVE-2024-33506: An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiManage An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiManager 7.4.2 and below, 7.2.5 and below, 7.0.12 and below allows a remote authenticated attacker assigned to an Administrative Domain (ADOM) to access device summary of unauthorized ADOMs via crafted HTTP requests.
nvdfortinet
CVE-2023-44254MEDIUMCVSS 6.5≥ 6.2.0, < 7.2.5v7.4.0+4 more2024-09-10
CVE-2023-44254 [MEDIUM] CWE-639 CVE-2023-44254: An authorization bypass through user-controlled key [CWE-639] vulnerability in FortiAnalyzer version An authorization bypass through user-controlled key [CWE-639] vulnerability in FortiAnalyzer version 7.4.1 and before 7.2.5 and FortiManager version 7.4.1 and before 7.2.5 may allow a remote attacker with low privileges to read sensitive data via a crafted HTTP request.
nvdfortinet