Fortinet Fortimanager vulnerabilities
114 known vulnerabilities affecting fortinet/fortimanager.
Total CVEs
114
CISA KEV
2
actively exploited
Public exploits
1
Exploited in wild
2
Severity breakdown
CRITICAL14HIGH38MEDIUM56LOW6
Vulnerabilities
Page 3 of 6
CVE-2019-6695P3CRITICALCVSS 9.8≤ 6.0.6v6.2.02019-08-23
CVE-2019-6695 [CRITICAL] CWE-345 CVE-2019-6695: Lack of root file system integrity checking in Fortinet FortiManager VM application images of 6.2.0,
Lack of root file system integrity checking in Fortinet FortiManager VM application images of 6.2.0, 6.0.6 and below may allow an attacker to implant third-party programs by recreating the image through specific methods.
nvd
CVE-2020-9289P3HIGHCVSS 7.5≤ 6.2.32020-06-16
CVE-2020-9289 [HIGH] CWE-798 CVE-2020-9289: Use of a hard-coded cryptographic key to encrypt password data in CLI configuration in FortiManager
Use of a hard-coded cryptographic key to encrypt password data in CLI configuration in FortiManager 6.2.3 and below, FortiAnalyzer 6.2.3 and below may allow an attacker with access to the CLI configuration or the CLI backup file to decrypt the sensitive data, via knowledge of the hard-coded key.
nvd
CVE-2024-45331P3HIGHCVSS 7.8≥ 6.4.0, < 7.2.6≥ 7.4.0, < 7.4.4+4 more2025-01-16
CVE-2024-45331 [HIGH] CWE-266 CVE-2024-45331: A incorrect privilege assignment vulnerability in Fortinet FortiAnalyzer 7.4.0 through 7.4.3, FortiA
A incorrect privilege assignment vulnerability in Fortinet FortiAnalyzer 7.4.0 through 7.4.3, FortiAnalyzer 7.2.0 through 7.2.5, FortiAnalyzer 7.0 all versions, FortiAnalyzer 6.4 all versions, FortiAnalyzer Cloud 7.4.1 through 7.4.2, FortiAnalyzer Cloud 7.2.1 through 7.2.6, FortiAnalyzer Cloud 7.0 all versions, FortiAnalyzer Cloud 6.4 all versions, Fo
nvd
CVE-2024-21757P3HIGHCVSS 7.8≥ 7.0.0, < 7.0.11≥ 7.2.0, < 7.2.5+4 more2024-08-13
CVE-2024-21757 [HIGH] CWE-620 CVE-2024-21757: A unverified password change in Fortinet FortiManager versions 7.0.0 through 7.0.10, versions 7.2.0
A unverified password change in Fortinet FortiManager versions 7.0.0 through 7.0.10, versions 7.2.0 through 7.2.4, and versions 7.4.0 through 7.4.1, as well as Fortinet FortiAnalyzer versions 7.0.0 through 7.0.10, versions 7.2.0 through 7.2.4, and versions 7.4.0 through 7.4.1, allows an attacker to modify admin passwords via the device configuration ba
nvd
CVE-2024-33505P3HIGHCVSS 7.3≥ 6.0.0, < 7.2.7≥ 7.4.0, < 7.4.3+6 more2024-11-12
CVE-2024-33505 [HIGH] CWE-122 CVE-2024-33505: A heap-based buffer overflow in Fortinet FortiAnalyzer version 7.4.0 through 7.4.2, 7.2.0 through 7.
A heap-based buffer overflow in Fortinet FortiAnalyzer version 7.4.0 through 7.4.2, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14, FortiManager version 7.4.0 through 7.4.2, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14 allows attacker to escalation of privilege via specially crafted http requests
nvd
CVE-2024-33503P3HIGHCVSS 7.8≥ 6.4.0, < 7.2.6≥ 7.4.0, < 7.4.4+4 more2025-01-14
CVE-2024-33503 [HIGH] CWE-266 CVE-2024-33503: A improper privilege management vulnerability in Fortinet FortiManager Cloud 7.4.1 through 7.4.3, Fo
A improper privilege management vulnerability in Fortinet FortiManager Cloud 7.4.1 through 7.4.3, FortiManager Cloud 7.2.1 through 7.2.5, FortiManager Cloud 7.0 all versions, FortiManager 7.4.0 through 7.4.3, FortiManager 7.2.0 through 7.2.5, FortiManager 7.0 all versions, FortiManager 6.4 all versions allows attacker to escalation of privilege via sp
nvd
CVE-2023-25606P3MEDIUMCVSS 6.5≥ 6.4.0, < 6.4.12≥ 7.0.0, ≤ 7.0.5+3 more2023-07-11
CVE-2023-25606 [MEDIUM] CWE-22 CVE-2023-25606: An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE
An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-23] in FortiAnalyzer and FortiManager management interface 7.2.0 through 7.2.1, 7.0.0 through 7.0.5, 6.4 all versions may allow a remote and authenticated attacker to retrieve arbitrary files from the underlying filesystem via specially crafted web re
nvd
CVE-2024-52964P3MEDIUMCVSS 6.5≥ 6.2.0, < 7.0.14≥ 7.2.0, < 7.2.10+8 more2025-08-12
CVE-2024-52964 [MEDIUM] CWE-22 CVE-2024-52964: An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE
An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in Fortinet FortiManager version 7.6.0 through 7.6.1, 7.4.0 through 7.4.5, 7.2.0 through 7.2.9 and below 7.0.13 & FortiManager Cloud version 7.6.0 through 7.6.1, 7.4.0 through 7.4.5 and before 7.2.9 allows an authenticated remote attacker to overw
nvd
CVE-2018-1360P3HIGHCVSS 8.1≥ 5.2.0, ≤ 5.2.7v5.4.0+1 more2019-04-25
CVE-2018-1360 [HIGH] CWE-319 CVE-2018-1360: A cleartext transmission of sensitive information vulnerability in Fortinet FortiManager 5.2.0 throu
A cleartext transmission of sensitive information vulnerability in Fortinet FortiManager 5.2.0 through 5.2.7, 5.4.0 and 5.4.1 may allow an unauthenticated attacker in a man in the middle position to retrieve the admin password via intercepting REST API JSON responses.
nvd
CVE-2025-68649P3MEDIUMCVSS 6.5≥ 7.0.0, < 7.4.8≥ 7.6.0, < 7.6.5+4 more2026-04-14
CVE-2025-68649 [MEDIUM] CWE-22 CVE-2025-68649: An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in F
An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0 through 7.4.7, FortiAnalyzer 7.2 all versions, FortiAnalyzer 7.0 all versions, FortiAnalyzer Cloud 7.6.0 through 7.6.4, FortiAnalyzer Cloud 7.4.0 through 7.4.7, FortiAnalyzer Cloud 7.2 all
nvd
CVE-2023-44256P3MEDIUMCVSS 6.5≥ 7.0.0, ≤ 7.0.8≥ 7.2.0, ≤ 7.2.3+1 more2023-10-20
CVE-2023-44256 [MEDIUM] CWE-22 CVE-2023-44256: A server-side request forgery vulnerability [CWE-918] in Fortinet FortiAnalyzer version 7.4.0, versi
A server-side request forgery vulnerability [CWE-918] in Fortinet FortiAnalyzer version 7.4.0, version 7.2.0 through 7.2.3 and before 7.0.8 and FortiManager version 7.4.0, version 7.2.0 through 7.2.3 and before 7.0.8 allows a remote attacker with low privileges to view sensitive data from internal servers or perform a local port scan via a crafted HT
nvd
CVE-2023-44254P3MEDIUMCVSS 6.5≥ 6.2.0, < 7.2.5v7.4.0+4 more2024-09-10
CVE-2023-44254 [MEDIUM] CWE-639 CVE-2023-44254: An authorization bypass through user-controlled key [CWE-639] vulnerability in FortiAnalyzer version
An authorization bypass through user-controlled key [CWE-639] vulnerability in FortiAnalyzer version 7.4.1 and before 7.2.5 and FortiManager version 7.4.1 and before 7.2.5 may allow a remote attacker with low privileges to read sensitive data via a crafted HTTP request.
nvd
CVE-2019-17654P3HIGHCVSS 8.8≤ 6.0.6v6.2.0+1 more2020-03-15
CVE-2019-17654 [HIGH] CWE-345 CVE-2019-17654: An Insufficient Verification of Data Authenticity vulnerability in FortiManager 6.2.1, 6.2.0, 6.0.6
An Insufficient Verification of Data Authenticity vulnerability in FortiManager 6.2.1, 6.2.0, 6.0.6 and below may allow an unauthenticated attacker to perform a Cross-Site WebSocket Hijacking (CSWSH) attack.
nvd
CVE-2019-17657P3HIGHCVSS 7.5fixed in 6.2.3vbelow 6.2.32020-04-07
CVE-2019-17657 [HIGH] CWE-400 CVE-2019-17657: An Uncontrolled Resource Consumption vulnerability in Fortinet FortiSwitch below 3.6.11, 6.0.6 and 6
An Uncontrolled Resource Consumption vulnerability in Fortinet FortiSwitch below 3.6.11, 6.0.6 and 6.2.2, FortiAnalyzer below 6.2.3, FortiManager below 6.2.3 and FortiAP-S/W2 below 6.2.2 may allow an attacker to cause admin webUI denial of service (DoS) via handling special crafted HTTP requests/responses in pieces slowly, as demonstrated by Slow HTTP
nvd
CVE-2022-45857P3HIGHCVSS 7.5≥ 6.2.0, < 6.2.9≥ 6.4.0, < 6.4.8+4 more2023-01-05
CVE-2022-45857 [HIGH] CWE-286 CVE-2022-45857: An incorrect user management vulnerability [CWE-286] in the FortiManager version 6.4.6 and below VDO
An incorrect user management vulnerability [CWE-286] in the FortiManager version 6.4.6 and below VDOM creation component may allow an attacker to access a FortiGate without a password via newly created VDOMs after the super_admin account is deleted.
nvd
CVE-2023-42787P3MEDIUMCVSS 6.5≥ 6.2.0, ≤ 6.2.12≥ 6.4.0, ≤ 6.4.13+3 more2023-10-10
CVE-2023-42787 [MEDIUM] CWE-602 CVE-2023-42787: A client-side enforcement of server-side security [CWE-602] vulnerability in Fortinet FortiManager v
A client-side enforcement of server-side security [CWE-602] vulnerability in Fortinet FortiManager version 7.4.0 and before 7.2.3 and FortiAnalyzer version 7.4.0 and before 7.2.3 may allow a remote attacker with low privileges to access a privileged web console via client side code execution.
nvd
CVE-2024-32118P3MEDIUMCVSS 6.7≥ 6.2.0, < 7.2.6≥ 7.4.0, < 7.4.3+5 more2024-11-12
CVE-2024-32118 [MEDIUM] CWE-78 CVE-2024-32118: Multiple improper neutralization of special elements used in an OS command ('OS Command Injection')
Multiple improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] in Fortinet FortiManager version 7.4.0 through 7.4.2 and before 7.2.5, Fortinet FortiAnalyzer version 7.4.0 through 7.4.2 and before 7.2.5 and Fortinet FortiAnalyzer-BigData before 7.4.0 allows an authenticated privileged attack
nvd
CVE-2021-32603P3MEDIUMCVSS 6.5≥ 5.6.0, < 6.2.8≥ 6.4.0, < 6.4.6+1 more2021-08-05
CVE-2021-32603 [MEDIUM] CWE-918 CVE-2021-32603: A server-side request forgery (SSRF) (CWE-918) vulnerability in FortiManager and FortiAnalyser GUI 7
A server-side request forgery (SSRF) (CWE-918) vulnerability in FortiManager and FortiAnalyser GUI 7.0.0, 6.4.5 and below, 6.2.7 and below, 6.0.11 and below, 5.6.11 and below may allow a remote and authenticated attacker to access unauthorized files and services on the system via specifically crafted web requests.
nvd
CVE-2023-25609P3MEDIUMCVSS 6.5≥ 6.4.8, ≤ 6.4.11≥ 7.0.0, ≤ 7.0.6+3 more2023-06-13
CVE-2023-25609 [MEDIUM] CWE-918 CVE-2023-25609: A server-side request forgery (SSRF) vulnerability [CWE-918] in FortiManager and FortiAnalyzer GUI 7
A server-side request forgery (SSRF) vulnerability [CWE-918] in FortiManager and FortiAnalyzer GUI 7.2.0 through 7.2.1, 7.0.0 through 7.0.6, 6.4.8 through 6.4.11 may allow a remote and authenticated attacker to access unauthorized files and services on the system via specially crafted web requests.
nvd
CVE-2016-8495P3HIGHCVSS 7.4v5.0.6 to 5.2.7v5.4.0 to 5.4.12017-02-13
CVE-2016-8495 [HIGH] CWE-200 CVE-2016-8495: An improper certificate validation vulnerability in Fortinet FortiManager 5.0.6 through 5.2.7 and 5.
An improper certificate validation vulnerability in Fortinet FortiManager 5.0.6 through 5.2.7 and 5.4.0 through 5.4.1 allows remote attacker to spoof a trusted entity by using a man-in-the-middle (MITM) attack via the Fortisandbox devices probing feature.
nvd