Fortinet Fortimanager vulnerabilities

113 known vulnerabilities affecting fortinet/fortimanager.

Total CVEs
113
CISA KEV
2
actively exploited
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL14HIGH38MEDIUM55LOW6

Vulnerabilities

Page 4 of 6
CVE-2023-44253MEDIUMCVSS 5.0≥ 6.2.0, ≤ 6.2.12≥ 6.4.0, ≤ 6.4.14+5 more2024-02-15
CVE-2023-44253 [MEDIUM] CWE-200 CVE-2023-44253: An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in Fortinet Fo An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in Fortinet FortiManager version 7.4.0 through 7.4.1 and before 7.2.5, FortiAnalyzer version 7.4.0 through 7.4.1 and before 7.2.5 and FortiAnalyzer-BigData before 7.2.5 allows an adom administrator to enumerate other adoms and device names via crafted HTTP or HTTPS
cvelistv5nvd
CVE-2023-40719MEDIUMCVSS 5.5≥ 7.0.0, ≤ 7.0.10≥ 7.2.0, ≤ 7.2.3+1 more2023-11-14
CVE-2023-40719 [MEDIUM] CWE-798 CVE-2023-40719: A use of hard-coded credentials vulnerability in Fortinet FortiAnalyzer and FortiManager 7.0.0 - 7.0 A use of hard-coded credentials vulnerability in Fortinet FortiAnalyzer and FortiManager 7.0.0 - 7.0.8, 7.2.0 - 7.2.3 and 7.4.0 allows an attacker to access Fortinet private testing data via the use of static credentials.
cvelistv5nvd
CVE-2023-44256MEDIUMCVSS 6.5≥ 7.0.0, ≤ 7.0.8≥ 7.2.0, ≤ 7.2.3+1 more2023-10-20
CVE-2023-44256 [MEDIUM] CWE-22 CVE-2023-44256: A server-side request forgery vulnerability [CWE-918] in Fortinet FortiAnalyzer version 7.4.0, versi A server-side request forgery vulnerability [CWE-918] in Fortinet FortiAnalyzer version 7.4.0, version 7.2.0 through 7.2.3 and before 7.0.8 and FortiManager version 7.4.0, version 7.2.0 through 7.2.3 and before 7.0.8 allows a remote attacker with low privileges to view sensitive data from internal servers or perform a local port scan via a crafted HT
cvelistv5nvd
CVE-2023-41679CRITICALCVSS 9.6≥ 6.0.0, ≤ 6.0.12≥ 6.2.0, ≤ 6.2.12+6 more2023-10-10
CVE-2023-41679 [CRITICAL] CWE-284 CVE-2023-41679: An improper access control vulnerability [CWE-284] in FortiManager management interface 7.2.0 throug An improper access control vulnerability [CWE-284] in FortiManager management interface 7.2.0 through 7.2.2, 7.0.0 through 7.0.7, 6.4.0 through 6.4.11, 6.2 all versions, 6.0 all versions may allow a remote and authenticated attacker with at least "device management" permission on his profile and belonging to a specific ADOM to add and delete CLI s
cvelistv5nvd
CVE-2023-41838HIGHCVSS 7.1≥ 6.2.0, ≤ 6.2.11≥ 6.4.0, ≤ 6.4.12+3 more2023-10-10
CVE-2023-41838 [HIGH] CWE-78 CVE-2023-41838: An improper neutralization of special elements used in an os command ('os command injection') in For An improper neutralization of special elements used in an os command ('os command injection') in FortiManager 7.4.0 and 7.2.0 through 7.2.3 may allow attacker to execute unauthorized code or commands via FortiManager cli.
cvelistv5nvd
CVE-2023-25607HIGHCVSS 7.8≥ 6.0.0, ≤ 6.0.12≥ 6.2.0, ≤ 6.2.12+6 more2023-10-10
CVE-2023-25607 [HIGH] CWE-78 CVE-2023-25607: An improper neutralization of special elements used in an OS Command ('OS Command Injection') vulner An improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78 ] in FortiManager 7.2.0 through 7.2.2, 7.0.0 through 7.0.7, 6.4.0 through 6.4.11, 6.2 all versions, 6.0 all versions, FortiAnalyzer 7.2.0 through 7.2.2, 7.0.0 through 7.0.7, 6.4.0 through 6.4.11, 6.2 all versions, 6.0 all versions and For
cvelistv5nvd
CVE-2023-42788MEDIUMCVSS 6.7≥ 6.2.0, ≤ 6.2.11≥ 6.4.0, ≤ 6.4.12+3 more2023-10-10
CVE-2023-42788 [MEDIUM] CWE-78 CVE-2023-42788: An improper neutralization of special elements used in an os command ('OS Command Injection') vulner An improper neutralization of special elements used in an os command ('OS Command Injection') vulnerability [CWE-78] in FortiManager & FortiAnalyzer version 7.4.0, version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.8, version 6.4.0 through 6.4.12 and version 6.2.0 through 6.2.11 may allow a local attacker with low privileges to execute unauthoriz
cvelistv5nvd
CVE-2023-44249MEDIUMCVSS 6.5≥ 6.2.0, ≤ 6.2.12≥ 6.4.0, ≤ 6.4.13+4 more2023-10-10
CVE-2023-44249 [MEDIUM] CWE-639 CVE-2023-44249: An authorization bypass through user-controlled key [CWE-639] vulnerability in Fortinet FortiManager An authorization bypass through user-controlled key [CWE-639] vulnerability in Fortinet FortiManager version 7.4.0 and before 7.2.3 and FortiAnalyzer version 7.4.0 and before 7.2.3 allows a remote attacker with low privileges to read sensitive information via crafted HTTP requests.
cvelistv5nvd
CVE-2023-42787MEDIUMCVSS 6.5≥ 6.2.0, ≤ 6.2.12≥ 6.4.0, ≤ 6.4.13+3 more2023-10-10
CVE-2023-42787 [MEDIUM] CWE-602 CVE-2023-42787: A client-side enforcement of server-side security [CWE-602] vulnerability in Fortinet FortiManager v A client-side enforcement of server-side security [CWE-602] vulnerability in Fortinet FortiManager version 7.4.0 and before 7.2.3 and FortiAnalyzer version 7.4.0 and before 7.2.3 may allow a remote attacker with low privileges to access a privileged web console via client side code execution.
cvelistv5nvd
CVE-2023-36638MEDIUMCVSS 4.3≥ 6.4.0, < 6.4.12≥ 7.0.0, < 7.0.8+6 more2023-09-13
CVE-2023-36638 [MEDIUM] CWE-284 CVE-2023-36638: An improper privilege management vulnerability [CWE-269] in FortiManager 7.2.0 through 7.2.2, 7.0.0 An improper privilege management vulnerability [CWE-269] in FortiManager 7.2.0 through 7.2.2, 7.0.0 through 7.0.7, 6.4.0 through 6.4.11, 6.2 all versions, 6.0 all versions and FortiAnalyzer 7.2.0 through 7.2.2, 7.0.0 through 7.0.7, 6.4.0 through 6.4.11, 6.2 all versions, 6.0 all versions API may allow a remote and authenticated API admin user to acce
cvelistv5nvd
CVE-2022-22305MEDIUMCVSS 4.2≥ 6.0.0, ≤ 6.0.12≥ 6.2.0, ≤ 6.2.11+4 more2023-09-01
CVE-2022-22305 [MEDIUM] CWE-297 CVE-2022-22305: An improper certificate validation vulnerability [CWE-295] in FortiManager 7.0.1 and below, 6.4.6 an An improper certificate validation vulnerability [CWE-295] in FortiManager 7.0.1 and below, 6.4.6 and below; FortiAnalyzer 7.0.2 and below, 6.4.7 and below; FortiOS 6.2.x and 6.0.x; FortiSandbox 4.0.x, 3.2.x and 3.1.x may allow a network adjacent and unauthenticated attacker to man-in-the-middle the communication between the listed products and some
cvelistv5nvd
CVE-2021-43072MEDIUMCVSS 6.7≥ 5.6.0, < 6.4.8≥ 7.0.0, < 7.0.3+5 more2023-07-18
CVE-2021-43072 [MEDIUM] CWE-120 CVE-2021-43072: A buffer copy without checking size of input ('classic buffer overflow') in Fortinet FortiAnalyzer v A buffer copy without checking size of input ('classic buffer overflow') in Fortinet FortiAnalyzer version 7.0.2 and below, version 6.4.7 and below, version 6.2.9 and below, version 6.0.11 and below, version 5.6.11 and below, FortiManager version 7.0.2 and below, version 6.4.7 and below, version 6.2.9 and below, version 6.0.11 and below, version 5.6
cvelistv5nvd
CVE-2023-25606MEDIUMCVSS 6.5≥ 6.4.0, < 6.4.12≥ 7.0.0, ≤ 7.0.5+3 more2023-07-11
CVE-2023-25606 [MEDIUM] CWE-22 CVE-2023-25606: An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-23] in FortiAnalyzer and FortiManager management interface 7.2.0 through 7.2.1, 7.0.0 through 7.0.5, 6.4 all versions may allow a remote and authenticated attacker to retrieve arbitrary files from the underlying filesystem via specially crafted web re
cvelistv5nvd
CVE-2023-25609MEDIUMCVSS 6.5≥ 6.4.8, ≤ 6.4.11≥ 7.0.0, ≤ 7.0.6+3 more2023-06-13
CVE-2023-25609 [MEDIUM] CWE-918 CVE-2023-25609: A server-side request forgery (SSRF) vulnerability [CWE-918] in FortiManager and FortiAnalyzer GUI 7 A server-side request forgery (SSRF) vulnerability [CWE-918] in FortiManager and FortiAnalyzer GUI 7.2.0 through 7.2.1, 7.0.0 through 7.0.6, 6.4.8 through 6.4.11 may allow a remote and authenticated attacker to access unauthorized files and services on the system via specially crafted web requests.
cvelistv5nvd
CVE-2023-22642HIGHCVSS 8.1≥ 6.4.8, < 6.4.11≥ 7.0.0, < 7.0.6+5 more2023-04-11
CVE-2023-22642 [HIGH] CWE-295 CVE-2023-22642: An improper certificate validation vulnerability [CWE-295] in FortiAnalyzer and FortiManager 7.2.0 t An improper certificate validation vulnerability [CWE-295] in FortiAnalyzer and FortiManager 7.2.0 through 7.2.1, 7.0.0 through 7.0.5, 6.4.8 through 6.4.10 may allow a remote and unauthenticated attacker to perform a Man-in-the-Middle attack on the communication channel between the device and the remote FortiGuard server hosting outbreakalert ressourc
cvelistv5nvd
CVE-2022-27490MEDIUMCVSS 6.5≥ 5.6.0, ≤ 5.6.11≥ 6.0.0, ≤ 6.0.42023-03-07
CVE-2022-27490 [MEDIUM] CWE-200 CVE-2022-27490: A exposure of sensitive information to an unauthorized actor in Fortinet FortiManager version 6.0.0 A exposure of sensitive information to an unauthorized actor in Fortinet FortiManager version 6.0.0 through 6.0.4, FortiAnalyzer version 6.0.0 through 6.0.4, FortiPortal version 6.0.0 through 6.0.9, 5.3.0 through 5.3.8, 5.2.x, 5.1.0, 5.0.x, 4.2.x, 4.1.x, FortiSwitch version 7.0.0 through 7.0.4, 6.4.0 through 6.4.10, 6.2.x, 6.0.x allows an attacker wh
cvelistv5nvd
CVE-2022-45857HIGHCVSS 7.5≥ 6.2.0, < 6.2.9≥ 6.4.0, < 6.4.8+4 more2023-01-05
CVE-2022-45857 [HIGH] CWE-286 CVE-2022-45857: An incorrect user management vulnerability [CWE-286] in the FortiManager version 6.4.6 and below VDO An incorrect user management vulnerability [CWE-286] in the FortiManager version 6.4.6 and below VDOM creation component may allow an attacker to access a FortiGate without a password via newly created VDOMs after the super_admin account is deleted.
cvelistv5nvd
CVE-2022-38377LOWCVSS 2.7≥ 6.0.0, ≤ 6.0.11≥ 6.2.0, ≤ 6.2.9+3 more2022-11-25
CVE-2022-38377 [LOW] CWE-284 CVE-2022-38377: An improper access control vulnerability [CWE-284] in FortiManager 7.2.0, 7.0.0 through 7.0.3, 6.4.0 An improper access control vulnerability [CWE-284] in FortiManager 7.2.0, 7.0.0 through 7.0.3, 6.4.0 through 6.4.7, 6.2.0 through 6.2.9, 6.0.0 through 6.0.11 and FortiAnalyzer 7.2.0, 7.0.0 through 7.0.3, 6.4.0 through 6.4.8, 6.2.0 through 6.2.10, 6.0.0 through 6.0.12 may allow a remote and authenticated admin user assigned to a specific ADOM to access
cvelistv5nvd
CVE-2022-39950MEDIUMCVSS 5.4≥ 6.0.0, ≤ 6.2.9≥ 6.4.0, ≤ 6.4.8+1 more2022-11-02
CVE-2022-39950 [MEDIUM] CVE-2022-39950: An improper neutralization of input during web page generation vulnerability [CWE-79] exists in Fort An improper neutralization of input during web page generation vulnerability [CWE-79] exists in FortiManager and FortiAnalyzer 6.0.0 all versions, 6.2.0 all versions, 6.4.0 through 6.4.8, and 7.0.0 through 7.0.4. Report templates may allow a low privilege level attacker to perform an XSS attack via posting a crafted CKeditor "protected" comment as described
nvd
CVE-2022-26121MEDIUMCVSS 5.3≤ 5.6.11≤ 6.0.11+3 more2022-10-10
CVE-2022-26121 [MEDIUM] CWE-668 CVE-2022-26121: An exposure of resource to wrong sphere vulnerability [CWE-668] in FortiAnalyzer and FortiManager GU An exposure of resource to wrong sphere vulnerability [CWE-668] in FortiAnalyzer and FortiManager GUI 7.0.0 through 7.0.3, 6.4.0 through 6.4.8, 6.2.0 through 6.2.9, 6.0.0 through 6.0.11, 5.6.0 through 5.6.11 may allow an unauthenticated and remote attacker to access report template images via referencing the name in the URL path.
nvd