Fortinet Fortimanager vulnerabilities
114 known vulnerabilities affecting fortinet/fortimanager.
Total CVEs
114
CISA KEV
2
actively exploited
Public exploits
1
Exploited in wild
2
Severity breakdown
CRITICAL14HIGH38MEDIUM56LOW6
Vulnerabilities
Page 5 of 6
CVE-2021-42757P4MEDIUMCVSS 6.7≥ 6.0.0, ≤ 6.4.7≥ 7.0.0, ≤ 7.0.2+2 more2021-12-08
CVE-2021-42757 [MEDIUM] CWE-120 CVE-2021-42757: A buffer overflow [CWE-121] in the TFTP client library of FortiOS before 6.4.7 and FortiOS 7.0.0 thr
A buffer overflow [CWE-121] in the TFTP client library of FortiOS before 6.4.7 and FortiOS 7.0.0 through 7.0.2, may allow an authenticated local attacker to achieve arbitrary code execution via specially crafted command line arguments.
nvd
CVE-2022-26118P4MEDIUMCVSS 6.7≥ 6.0.0, ≤ 6.0.11≥ 6.2.0, ≤ 6.2.9+2 more2022-07-18
CVE-2022-26118 [MEDIUM] CWE-269 CVE-2022-26118: A privilege chaining vulnerability [CWE-268] in FortiManager and FortiAnalyzer 6.0.x, 6.2.x, 6.4.0 t
A privilege chaining vulnerability [CWE-268] in FortiManager and FortiAnalyzer 6.0.x, 6.2.x, 6.4.0 through 6.4.7, 7.0.0 through 7.0.3 may allow a local and authenticated attacker with a restricted shell to escalate their privileges to root due to incorrect permissions of some folders and executable files on the system.
nvd
CVE-2024-32116P4MEDIUMCVSS 6.0≥ 6.2.0, < 7.2.6≥ 7.4.0, < 7.4.3+5 more2024-11-12
CVE-2024-32116 [MEDIUM] CWE-23 CVE-2024-32116: Multiple relative path traversal vulnerabilities [CWE-23] in Fortinet FortiManager version 7.4.0 thr
Multiple relative path traversal vulnerabilities [CWE-23] in Fortinet FortiManager version 7.4.0 through 7.4.2 and before 7.2.5, FortiAnalyzer version 7.4.0 through 7.4.2 and before 7.2.5 and FortiAnalyzer-BigData version 7.4.0 and before 7.2.7 allows a privileged attacker to delete files from the underlying filesystem via crafted CLI requests.
nvd
CVE-2024-36508P4MEDIUMCVSS 6.0≥ 6.4.0, < 7.2.6≥ 7.4.0, < 7.4.3+4 more2025-02-11
CVE-2024-36508 [MEDIUM] CWE-22 CVE-2024-36508: An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE
An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in Fortinet FortiManager version 7.4.0 through 7.4.2 and before 7.2.5 and Fortinet FortiAnalyzer version 7.4.0 through 7.4.2 and before 7.2.5 CLI allows an authenticated admin user with diagnose privileges to delete files on the system.
nvd
CVE-2018-1355P4MEDIUMCVSS 6.1≤ 5.6.5v6.0.02018-06-27
CVE-2018-1355 [MEDIUM] CWE-601 CVE-2018-1355: An open redirect vulnerability in Fortinet FortiManager 6.0.0, 5.6.5 and below versions, FortiAnalyz
An open redirect vulnerability in Fortinet FortiManager 6.0.0, 5.6.5 and below versions, FortiAnalyzer 6.0.0, 5.6.5 and below versions allows attacker to inject script code during converting a HTML table to a PDF document under the FortiView feature. An attacker may be able to social engineer an authenticated user into generating a PDF file containing
nvd
CVE-2018-13375P4MEDIUMCVSS 6.1≤ 5.6.0vFortiManager 5.6.0 and below2019-05-28
CVE-2018-13375 [MEDIUM] CWE-79 CVE-2018-13375: An Improper Neutralization of Script-Related HTML Tags in Fortinet FortiAnalyzer 5.6.0 and below and
An Improper Neutralization of Script-Related HTML Tags in Fortinet FortiAnalyzer 5.6.0 and below and FortiManager 5.6.0 and below allows an attacker to send DHCP request containing malicious scripts in the HOSTNAME parameter. The malicious script code is executed while viewing the logs in FortiAnalyzer and FortiManager (with FortiAnalyzer feature ena
nvd
CVE-2023-40719P4MEDIUMCVSS 5.5≥ 7.0.0, ≤ 7.0.10≥ 7.2.0, ≤ 7.2.3+1 more2023-11-14
CVE-2023-40719 [MEDIUM] CWE-798 CVE-2023-40719: A use of hard-coded credentials vulnerability in Fortinet FortiAnalyzer and FortiManager 7.0.0 - 7.0
A use of hard-coded credentials vulnerability in Fortinet FortiAnalyzer and FortiManager 7.0.0 - 7.0.8, 7.2.0 - 7.2.3 and 7.4.0 allows an attacker to access Fortinet private testing data via the use of static credentials.
nvd
CVE-2023-44253P4MEDIUMCVSS 5.0≥ 6.2.0, ≤ 6.2.12≥ 6.4.0, ≤ 6.4.14+5 more2024-02-15
CVE-2023-44253 [MEDIUM] CWE-200 CVE-2023-44253: An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in Fortinet Fo
An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in Fortinet FortiManager version 7.4.0 through 7.4.1 and before 7.2.5, FortiAnalyzer version 7.4.0 through 7.4.1 and before 7.2.5 and FortiAnalyzer-BigData before 7.2.5 allows an adom administrator to enumerate other adoms and device names via crafted HTTP or HTTPS
nvd
CVE-2021-24017P4MEDIUMCVSS 4.3fixed in 6.2.7≥ 6.4.0, < 6.4.42021-09-30
CVE-2021-24017 [MEDIUM] CWE-287 CVE-2021-24017: An improper authentication in Fortinet FortiManager version 6.4.3 and below, 6.2.6 and below allows
An improper authentication in Fortinet FortiManager version 6.4.3 and below, 6.2.6 and below allows attacker to assign arbitrary Policy and Object modules via crafted requests to the request handler.
nvd
CVE-2022-39950P4MEDIUMCVSS 5.4≥ 6.0.0, ≤ 6.2.9≥ 6.4.0, ≤ 6.4.8+1 more2022-11-02
CVE-2022-39950 [MEDIUM] CVE-2022-39950: An improper neutralization of input during web page generation vulnerability [CWE-79] exists in Fort
An improper neutralization of input during web page generation vulnerability [CWE-79] exists in FortiManager and FortiAnalyzer 6.0.0 all versions, 6.2.0 all versions, 6.4.0 through 6.4.8, and 7.0.0 through 7.0.4. Report templates may allow a low privilege level attacker to perform an XSS attack via posting a crafted CKeditor "protected" comment as described
nvd
CVE-2021-32597P4MEDIUMCVSS 5.4fixed in 6.2.8≥ 6.4.0, < 6.4.6+1 more2021-08-06
CVE-2021-32597 [MEDIUM] CWE-79 CVE-2021-32597: Multiple improper neutralization of input during web page generation (CWE-79) in FortiManager and Fo
Multiple improper neutralization of input during web page generation (CWE-79) in FortiManager and FortiAnalyzer versions 7.0.0, 6.4.5 and below, 6.2.7 and below user interface, may allow a remote authenticated attacker to perform a Stored Cross Site Scripting attack (XSS) by injecting malicious payload in GET parameters.
nvd
CVE-2022-22303P4MEDIUMCVSS 5.5≥ 6.2.0, ≤ 6.2.9≥ 6.4.0, ≤ 6.4.7+1 more2022-03-02
CVE-2022-22303 [MEDIUM] CWE-200 CVE-2022-22303: An exposure of sensitive system information to an unauthorized control sphere vulnerability [CWE-497
An exposure of sensitive system information to an unauthorized control sphere vulnerability [CWE-497] in FortiManager versions prior to 7.0.2, 6.4.7 and 6.2.9 may allow a low privileged authenticated user to gain access to the FortiGate users credentials via the config conflict file.
nvd
CVE-2024-47569P4MEDIUMCVSS 4.3≥ 7.4.1, < 7.4.4≥ 7.6.0, < 7.6.2+1 more2025-10-14
CVE-2024-47569 [MEDIUM] CWE-201 CVE-2024-47569: A insertion of sensitive information into sent data vulnerability in Fortinet FortiMail 7.4.0 throug
A insertion of sensitive information into sent data vulnerability in Fortinet FortiMail 7.4.0 through 7.4.2, FortiMail 7.2.0 through 7.2.6, FortiMail 7.0 all versions, FortiManager 7.6.0 through 7.6.1, FortiManager 7.4.1 through 7.4.3, FortiManager Cloud 7.4.1 through 7.4.3, FortiNDR 7.6.0 through 7.6.1, FortiNDR 7.4.0 through 7.4.8, FortiNDR 7.2 al
nvd
CVE-2020-12811P4MEDIUMCVSS 6.1≥ 6.2.0, ≤ 6.2.62020-09-24
CVE-2020-12811 [MEDIUM] CWE-79 CVE-2020-12811: An improper neutralization of script-related HTML tags in a web page in FortiManager 6.2.0, 6.2.1, 6
An improper neutralization of script-related HTML tags in a web page in FortiManager 6.2.0, 6.2.1, 6.2.2, and 6.2.3and FortiAnalyzer 6.2.0, 6.2.1, 6.2.2, and 6.2.3 may allow an attacker to execute a cross site scripting (XSS) via the Identify Provider name field.
nvd
CVE-2021-32598P4MEDIUMCVSS 4.3≥ 5.6.0, < 7.0.12021-08-05
CVE-2021-32598 [MEDIUM] CWE-444 CVE-2021-32598: An improper neutralization of CRLF sequences in HTTP headers ('HTTP Response Splitting') vulnerabili
An improper neutralization of CRLF sequences in HTTP headers ('HTTP Response Splitting') vulnerability In FortiManager and FortiAnalyzer GUI 7.0.0, 6.4.6 and below, 6.2.8 and below, 6.0.11 and below, 5.6.11 and below may allow an authenticated and remote attacker to perform an HTTP request splitting attack which gives attackers control of the remain
nvd
CVE-2021-32587P4MEDIUMCVSS 4.3≥ 5.6.0, < 6.4.6≥ 7.0.0, < 7.0.12021-08-06
CVE-2021-32587 [MEDIUM] CVE-2021-32587: An improper access control vulnerability in FortiManager and FortiAnalyzer GUI interface 7.0.0, 6.4.
An improper access control vulnerability in FortiManager and FortiAnalyzer GUI interface 7.0.0, 6.4.5 and below, 6.2.8 and below, 6.0.11 and below, 5.6.11 and below may allow a remote and authenticated attacker with restricted user profile to retrieve the list of administrative users of other ADOMs and their related configuration.
nvd
CVE-2023-36638P4MEDIUMCVSS 4.3≥ 6.4.0, < 6.4.12≥ 7.0.0, < 7.0.8+6 more2023-09-13
CVE-2023-36638 [MEDIUM] CWE-284 CVE-2023-36638: An improper privilege management vulnerability [CWE-269] in FortiManager 7.2.0 through 7.2.2, 7.0.0
An improper privilege management vulnerability [CWE-269] in FortiManager 7.2.0 through 7.2.2, 7.0.0 through 7.0.7, 6.4.0 through 6.4.11, 6.2 all versions, 6.0 all versions and FortiAnalyzer 7.2.0 through 7.2.2, 7.0.0 through 7.0.7, 6.4.0 through 6.4.11, 6.2 all versions, 6.0 all versions API may allow a remote and authenticated API admin user to acce
nvd
CVE-2015-3612P4MEDIUMCVSS 5.4≥ 5.0.0, ≤ 5.0.10≥ 5.2.0, ≤ 5.2.12020-02-04
CVE-2015-3612 [MEDIUM] CWE-79 CVE-2015-3612: A Cross-site Scripting (XSS) vulnerability exists in FortiManager 5.2.1 and earlier and 5.0.10 and e
A Cross-site Scripting (XSS) vulnerability exists in FortiManager 5.2.1 and earlier and 5.0.10 and earlier via an unspecified parameter in the FortiWeb auto update service page.
nvd
CVE-2024-33506P4MEDIUMCVSS 4.3≥ 7.0.0, < 7.2.6≥ 7.4.0, < 7.4.3+3 more2024-10-08
CVE-2024-33506 [MEDIUM] CWE-200 CVE-2024-33506: An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiManage
An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiManager 7.4.2 and below, 7.2.5 and below, 7.0.12 and below allows a remote authenticated attacker assigned to an Administrative Domain (ADOM) to access device summary of unauthorized ADOMs via crafted HTTP requests.
nvd
CVE-2024-54020P4MEDIUMCVSS 4.3≥ 7.0.0, < 7.0.8≥ 7.2.0, < 7.2.2+2 more2025-05-28
CVE-2024-54020 [MEDIUM] CWE-862 CVE-2024-54020: A missing authorization in Fortinet FortiManager versions 7.2.0 through 7.2.1, and versions 7.0.0 th
A missing authorization in Fortinet FortiManager versions 7.2.0 through 7.2.1, and versions 7.0.0 through 7.0.7 may allow an authenticated attacker to overwrite global threat feeds via crafted update requests.
nvd