cbcvebase.

Fortinet Fortimanager vulnerabilities

114 known vulnerabilities affecting fortinet/fortimanager.

Total CVEs
114
CISA KEV
2
actively exploited
Public exploits
1
Exploited in wild
2
Severity breakdown
CRITICAL14HIGH38MEDIUM56LOW6

Vulnerabilities

Page 4 of 6
CVE-2023-41838P3HIGHCVSS 7.1≥ 6.2.0, ≤ 6.2.11≥ 6.4.0, ≤ 6.4.12+3 more2023-10-10
CVE-2023-41838 [HIGH] CWE-78 CVE-2023-41838: An improper neutralization of special elements used in an os command ('os command injection') in For An improper neutralization of special elements used in an os command ('os command injection') in FortiManager 7.4.0 and 7.2.0 through 7.2.3 may allow attacker to execute unauthorized code or commands via FortiManager cli.
nvd
CVE-2018-1354P3MEDIUMCVSS 6.5≤ 6.0.02018-06-27
CVE-2018-1354 [MEDIUM] CWE-732 CVE-2018-1354: An improper access control vulnerability in Fortinet FortiManager 6.0.0, 5.6.5 and below versions, F An improper access control vulnerability in Fortinet FortiManager 6.0.0, 5.6.5 and below versions, FortiAnalyzer 6.0.0, 5.6.5 and below versions allows a regular user edit the avatar picture of other users with arbitrary content.
nvd
CVE-2024-32123P3MEDIUMCVSS 6.7≥ 4.3.4, < 7.2.6≥ 7.4.0, < 7.4.4+11 more2025-03-11
CVE-2024-32123 [MEDIUM] CWE-78 CVE-2024-32123: Multiple improper neutralization of special elements used in an os command ('os command injection') Multiple improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiManager, FortiAnalyzer versions 7.4.0 through 7.4.2 7.2.0 through 7.2.5 and 7.0.0 through 7.0.12 and 6.4.0 through 6.4.14 and 6.2.0 through 6.2.12 and 6.0.0 through 6.0.12 and 5.6.0 through 5.6.11 and 5.4.0 through 5.4.7 and 5.2.0 throu
nvd
CVE-2023-42788P3MEDIUMCVSS 6.7≥ 6.2.0, ≤ 6.2.11≥ 6.4.0, ≤ 6.4.12+3 more2023-10-10
CVE-2023-42788 [MEDIUM] CWE-78 CVE-2023-42788: An improper neutralization of special elements used in an os command ('OS Command Injection') vulner An improper neutralization of special elements used in an os command ('OS Command Injection') vulnerability [CWE-78] in FortiManager & FortiAnalyzer version 7.4.0, version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.8, version 6.4.0 through 6.4.12 and version 6.2.0 through 6.2.11 may allow a local attacker with low privileges to execute unauthoriz
nvd
CVE-2023-44249P3MEDIUMCVSS 6.5≥ 6.2.0, ≤ 6.2.12≥ 6.4.0, ≤ 6.4.13+4 more2023-10-10
CVE-2023-44249 [MEDIUM] CWE-639 CVE-2023-44249: An authorization bypass through user-controlled key [CWE-639] vulnerability in Fortinet FortiManager An authorization bypass through user-controlled key [CWE-639] vulnerability in Fortinet FortiManager version 7.4.0 and before 7.2.3 and FortiAnalyzer version 7.4.0 and before 7.2.3 allows a remote attacker with low privileges to read sensitive information via crafted HTTP requests.
nvd
CVE-2024-40585P3MEDIUMCVSS 6.5≥ 6.2.0, < 7.0.9≥ 7.2.0, < 7.2.4+5 more2025-03-14
CVE-2024-40585 [MEDIUM] CWE-532 CVE-2024-40585: An insertion of sensitive information into log file vulnerabilities [CWE-532] in FortiManager versio An insertion of sensitive information into log file vulnerabilities [CWE-532] in FortiManager version 7.4.0, version 7.2.3 and below, version 7.0.8 and below, version 6.4.12 and below, version 6.2.11 and below and FortiAnalyzer version 7.4.0, version 7.2.3 and below, version 7.0.8 and below, version 6.4.12 and below, version 6.2.11 and below eventlo
nvd
CVE-2022-27490P3MEDIUMCVSS 6.5≥ 5.6.0, ≤ 5.6.11≥ 6.0.0, ≤ 6.0.42023-03-07
CVE-2022-27490 [MEDIUM] CWE-200 CVE-2022-27490: A exposure of sensitive information to an unauthorized actor in Fortinet FortiManager version 6.0.0 A exposure of sensitive information to an unauthorized actor in Fortinet FortiManager version 6.0.0 through 6.0.4, FortiAnalyzer version 6.0.0 through 6.0.4, FortiPortal version 6.0.0 through 6.0.9, 5.3.0 through 5.3.8, 5.2.x, 5.1.0, 5.0.x, 4.2.x, 4.1.x, FortiSwitch version 7.0.0 through 7.0.4, 6.4.0 through 6.4.10, 6.2.x, 6.0.x allows an attacker wh
nvd
CVE-2025-68482P3MEDIUMCVSS 5.9≥ 6.4.0, < 7.4.9≥ 7.6.0, < 7.6.5+5 more2026-03-10
CVE-2025-68482 [MEDIUM] CWE-295 CVE-2025-68482: A improper certificate validation vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, Forti A improper certificate validation vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0 through 7.4.8, FortiAnalyzer 7.2 all versions, FortiAnalyzer 7.0 all versions, FortiAnalyzer 6.4 all versions, FortiManager 7.6.0 through 7.6.4, FortiManager 7.4.0 through 7.4.8, FortiManager 7.2 all versions, FortiManager 7.0 all versi
nvd
CVE-2023-47542P4MEDIUMCVSS 6.7≥ 7.0.0, < 7.0.11≥ 7.2.0, < 7.2.5+4 more2024-04-09
CVE-2023-47542 [MEDIUM] CWE-1336 CVE-2023-47542: A improper neutralization of special elements used in a template engine [CWE-1336] in FortiManager v A improper neutralization of special elements used in a template engine [CWE-1336] in FortiManager versions 7.4.1 and below, versions 7.2.4 and below, and 7.0.10 and below allows attacker to execute unauthorized code or commands via specially crafted templates.
nvd
CVE-2024-31496P4MEDIUMCVSS 6.7≥ 6.2.0, < 7.2.6≥ 7.4.0, < 7.4.3+5 more2024-11-12
CVE-2024-31496 [MEDIUM] CWE-121 CVE-2024-31496: A stack-based buffer overflow vulnerability [CWE-121] in Fortinet FortiManager version 7.4.0 through A stack-based buffer overflow vulnerability [CWE-121] in Fortinet FortiManager version 7.4.0 through 7.4.2 and before 7.2.5, FortiAnalyzer version 7.4.0 through 7.4.2 and before 7.2.5 and FortiAnalyzer-BigData 7.4.0 and before 7.2.7 allows a privileged attacker to execute unauthorized code or commands via crafted CLI requests.
nvd
CVE-2024-33501P4MEDIUMCVSS 6.7≥ 6.0.10, ≤ 6.0.12≥ 6.2.8, < 7.2.6+6 more2025-03-11
CVE-2024-33501 [MEDIUM] CWE-89 CVE-2024-33501: Two improper neutralization of special elements used in an SQL Command ('SQL Injection') vulnerabili Two improper neutralization of special elements used in an SQL Command ('SQL Injection') vulnerability [CWE-89] in Fortinet FortiAnalyzer version 7.4.0 through 7.4.2 and before 7.2.5, FortiManager version 7.4.0 through 7.4.2 and before 7.2.5 and FortiAnalyzer-BigData version 7.4.0 and before 7.2.7 allows a privileged attacker to execute unauthorized
nvd
CVE-2023-41842P4MEDIUMCVSS 6.7≥ 6.2.0, < 7.0.10≥ 7.2.0, < 7.2.4+6 more2024-03-12
CVE-2023-41842 [MEDIUM] CWE-134 CVE-2023-41842: A use of externally-controlled format string vulnerability [CWE-134] vulnerability in Fortinet allo A use of externally-controlled format string vulnerability [CWE-134] vulnerability in Fortinet allows a privileged attacker to execute unauthorized code or commands via specially crafted command arguments.
nvd
CVE-2024-32117P4MEDIUMCVSS 4.9≥ 6.2.0, < 7.2.6≥ 7.4.0, < 7.4.3+5 more2024-11-12
CVE-2024-32117 [MEDIUM] CWE-22 CVE-2024-32117: An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in Fortinet FortiManager version 7.4.0 through 7.4.2 and below 7.2.5, FortiAnalyzer version 7.4.0 through 7.4.2 and below 7.2.5 & FortiAnalyzer-BigData version 7.4.0 and below 7.2.7 allows a privileged attacker to read arbitrary files from the und
nvd
CVE-2022-23439P4MEDIUMCVSS 6.1≥ 7.4.0, ≤ 7.4.3≥ 7.2.0, ≤ 7.2.11+3 more2025-01-22
CVE-2022-23439 [MEDIUM] CWE-610 CVE-2022-23439: A externally controlled reference to a resource in another sphere vulnerability in Fortinet allows A externally controlled reference to a resource in another sphere vulnerability in Fortinet allows attacker to poison web caches via crafted HTTP requests, where the `Host` header points to an arbitrary webserver
nvd
CVE-2022-26121P4MEDIUMCVSS 5.3≤ 5.6.11≤ 6.0.11+3 more2022-10-10
CVE-2022-26121 [MEDIUM] CWE-668 CVE-2022-26121: An exposure of resource to wrong sphere vulnerability [CWE-668] in FortiAnalyzer and FortiManager GU An exposure of resource to wrong sphere vulnerability [CWE-668] in FortiAnalyzer and FortiManager GUI 7.0.0 through 7.0.3, 6.4.0 through 6.4.8, 6.2.0 through 6.2.9, 6.0.0 through 6.0.11, 5.6.0 through 5.6.11 may allow an unauthenticated and remote attacker to access report template images via referencing the name in the URL path.
nvd
CVE-2021-43072P4MEDIUMCVSS 6.7≥ 5.6.0, < 6.4.8≥ 7.0.0, < 7.0.3+5 more2023-07-18
CVE-2021-43072 [MEDIUM] CWE-120 CVE-2021-43072: A buffer copy without checking size of input ('classic buffer overflow') in Fortinet FortiAnalyzer v A buffer copy without checking size of input ('classic buffer overflow') in Fortinet FortiAnalyzer version 7.0.2 and below, version 6.4.7 and below, version 6.2.9 and below, version 6.0.11 and below, version 5.6.11 and below, FortiManager version 7.0.2 and below, version 6.4.7 and below, version 6.2.9 and below, version 6.0.11 and below, version 5.6
nvd
CVE-2025-67604P4MEDIUMCVSS 5.3≥ 7.2.0, ≤ 7.2.12≥ 7.4.0, < 7.4.9+5 more2026-05-12
CVE-2025-67604 [MEDIUM] CWE-676 CVE-2025-67604: A use of potentially dangerous function vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, A use of potentially dangerous function vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0 through 7.4.8, FortiAnalyzer 7.2 all versions, FortiAnalyzer 7.0 all versions, FortiAnalyzer 6.4 all versions, FortiManager 7.6.0 through 7.6.4, FortiManager 7.4.0 through 7.4.8, FortiManager 7.2 all versions, FortiManager 7.0 all
nvd
CVE-2021-24016P4MEDIUMCVSS 6.3fixed in 6.2.8≥ 6.4.0, < 6.4.42021-09-30
CVE-2021-24016 [MEDIUM] CWE-1236 CVE-2021-24016: An improper neutralization of formula elements in a csv file in Fortinet FortiManager version 6.4.3 An improper neutralization of formula elements in a csv file in Fortinet FortiManager version 6.4.3 and below, 6.2.7 and below allows attacker to execute arbitrary commands via crafted IPv4 field in policy name, when exported as excel file and opened unsafely on the victim host.
nvd
CVE-2024-32115P4MEDIUMCVSS 5.5≥ 7.0.0, < 7.2.6≥ 7.4.0, < 7.4.3+3 more2025-01-14
CVE-2024-32115 [MEDIUM] CWE-23 CVE-2024-32115: A relative path traversal vulnerability [CWE-23] in Fortinet FortiManager version 7.4.0 through 7.4 A relative path traversal vulnerability [CWE-23] in Fortinet FortiManager version 7.4.0 through 7.4.2 and before 7.2.5 allows a privileged attacker to delete files from the underlying filesystem via crafted HTTP or HTTPs requests.
nvd
CVE-2024-52962P4MEDIUMCVSS 5.3≥ 7.0.0, < 7.0.14≥ 7.2.0, < 7.2.9+6 more2025-04-08
CVE-2024-52962 [MEDIUM] CWE-117 CVE-2024-52962: An Improper Output Neutralization for Logs vulnerability [CWE-117] in FortiAnalyzer version 7.6.1 an An Improper Output Neutralization for Logs vulnerability [CWE-117] in FortiAnalyzer version 7.6.1 and below, version 7.4.5 and below, version 7.2.8 and below, version 7.0.13 and below and FortiManager version 7.6.1 and below, version 7.4.5 and below, version 7.2.8 and below, version 7.0.12 and below may allow an unauthenticated remote attacker to po
nvd