Fortinet Fortios vulnerabilities
39 known vulnerabilities affecting fortinet/fortinet_fortios.
Total CVEs
39
CISA KEV
2
actively exploited
Public exploits
2
Exploited in wild
2
Severity breakdown
CRITICAL1HIGH14MEDIUM22LOW2
Vulnerabilities
Page 2 of 2
CVE-2020-12818P4MEDIUMCVSS 5.3vFortiOS before 6.4.12020-09-24
CVE-2020-12818 [MEDIUM] CVE-2020-12818: An insufficient logging vulnerability in FortiGate before 6.4.1 may allow the traffic from an unauth
An insufficient logging vulnerability in FortiGate before 6.4.1 may allow the traffic from an unauthenticated attacker to Fortinet owned IP addresses to go unnoticed.
nvd
CVE-2021-41032P4MEDIUMCVSS 5.4vFortiOS 7.0.3, 7.0.2, 7.0.1, 7.0.0, 6.4.8, 6.4.7, 6.4.6, 6.4.5, 6.4.4, 6.4.3, 6.4.2, 6.4.1, 6.4.0, 6.2.10, 6.2.9, 6.2.8, 6.2.7, 6.2.6, 6.2.5, 6.2.4, 6.2.3, 6.2.2, 6.2.1, 6.2.02022-05-04
CVE-2021-41032 [MEDIUM] CVE-2021-41032: An improper access control vulnerability [CWE-284] in FortiOS versions 6.4.8 and prior and 7.0.3 and
An improper access control vulnerability [CWE-284] in FortiOS versions 6.4.8 and prior and 7.0.3 and prior may allow an authenticated attacker with a restricted user profile to gather sensitive information and modify the SSL-VPN tunnel status of other VDOMs using specific CLI commands.
nvd
CVE-2017-14182P4MEDIUMCVSS 6.5vFortiOS 5.4.5, 5.4.4, 5.4.3, 5.4.2, 5.4.1, 5.4.02017-10-27
CVE-2017-14182 [MEDIUM] CWE-20 CVE-2017-14182: A Denial of Service (DoS) vulnerability in Fortinet FortiOS 5.4.0 to 5.4.5 allows an authenticated u
A Denial of Service (DoS) vulnerability in Fortinet FortiOS 5.4.0 to 5.4.5 allows an authenticated user to cause the web GUI to be temporarily unresponsive, via passing a specially crafted payload to the 'params' parameter of the JSON web API.
nvd
CVE-2019-6696P4MEDIUMCVSS 6.1v6.2.1v6.2.0+1 more2020-03-15
CVE-2019-6696 [MEDIUM] CWE-20 CVE-2019-6696: An improper input validation vulnerability in FortiOS 6.2.1, 6.2.0, 6.0.8 and below until 5.4.0 unde
An improper input validation vulnerability in FortiOS 6.2.1, 6.2.0, 6.0.8 and below until 5.4.0 under admin webUI may allow an attacker to perform an URL redirect attack via a specifically crafted request to the admin initial password change webpage.
nvd
CVE-2018-13384P4MEDIUMCVSS 6.1vFortiOS all versions below 6.0.52019-06-04
CVE-2018-13384 [MEDIUM] CWE-601 CVE-2018-13384: A Host Header Redirection vulnerability in Fortinet FortiOS all versions below 6.0.5 under SSL VPN w
A Host Header Redirection vulnerability in Fortinet FortiOS all versions below 6.0.5 under SSL VPN web portal allows a remote attacker to potentially poison HTTP cache and subsequently redirect SSL VPN web portal users to arbitrary web domains.
nvd
CVE-2017-7733P4MEDIUMCVSS 6.1vFortiOS 5.6.0, 5.4.5, 5.4.4, 5.4.3, 5.4.2, 5.4.1, 5.4.02017-10-27
CVE-2017-7733 [MEDIUM] CWE-79 CVE-2017-7733: A Cross-Site-Scripting (XSS) vulnerability in Fortinet FortiOS 5.4.0 to 5.4.5 and 5.6.0 allows a rem
A Cross-Site-Scripting (XSS) vulnerability in Fortinet FortiOS 5.4.0 to 5.4.5 and 5.6.0 allows a remote unauthenticated attacker to execute arbitrary javascript code via webUI "Login Disclaimer" redir parameter.
nvd
CVE-2022-23438P4MEDIUMCVSS 6.1vFortiOS 7.0.5, 7.0.4, 7.0.3, 7.0.2, 7.0.1, 7.0.0, 6.4.9, 6.4.8, 6.4.7, 6.4.6, 6.4.5, 6.4.4, 6.4.3, 6.4.2, 6.4.1, 6.4.02022-07-18
CVE-2022-23438 [MEDIUM] CWE-79 CVE-2022-23438: An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vul
An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in FortiOS version 7.0.5 and prior and 6.4.9 and prior may allow an unauthenticated remote attacker to perform a reflected cross site scripting (XSS) attack in the captive portal authentication replacement page.
nvd
CVE-2019-5586P4MEDIUMCVSS 6.1vFortiOS 5.2.0 to 6.0.42019-06-04
CVE-2019-5586 [MEDIUM] CWE-79 CVE-2019-5586: A reflected Cross-Site-Scripting (XSS) vulnerability in Fortinet FortiOS 5.2.0 to 5.6.10, 6.0.0 to 6
A reflected Cross-Site-Scripting (XSS) vulnerability in Fortinet FortiOS 5.2.0 to 5.6.10, 6.0.0 to 6.0.4 under SSL VPN web portal may allow an attacker to execute unauthorized malicious script code via the "param" parameter of the error process HTTP requests.
nvd
CVE-2020-15937P4MEDIUMCVSS 6.1vFortiOS 6.4.1, 6.2.52021-03-03
CVE-2020-15937 [MEDIUM] CWE-79 CVE-2020-15937: An improper neutralization of input vulnerability in FortiGate version 6.2.x below 6.2.5 and 6.4.x b
An improper neutralization of input vulnerability in FortiGate version 6.2.x below 6.2.5 and 6.4.x below 6.4.1 may allow a remote attacker to perform a stored cross site scripting attack (XSS) via the IPS and WAF logs dashboard.
nvd
CVE-2018-13365P4MEDIUMCVSS 5.3v6.0.1v5.6.5 and below2019-05-29
CVE-2018-13365 [MEDIUM] CWE-200 CVE-2018-13365: An Information Exposure vulnerability in Fortinet FortiOS 6.0.1, 5.6.5 and below, allow attackers to
An Information Exposure vulnerability in Fortinet FortiOS 6.0.1, 5.6.5 and below, allow attackers to learn private IP as well as the hostname of FortiGate via Application Control Block page.
nvd
CVE-2022-22306P4MEDIUMCVSS 5.3vFortiOS 6.0.0 through 6.0.14, 6.2.0 through 6.2.10, 6.4.0 through 6.4.8, 7.0.02022-05-24
CVE-2022-22306 [MEDIUM] CWE-295 CVE-2022-22306: An improper certificate validation vulnerability [CWE-295] in FortiOS 6.0.0 through 6.0.14, 6.2.0 th
An improper certificate validation vulnerability [CWE-295] in FortiOS 6.0.0 through 6.0.14, 6.2.0 through 6.2.10, 6.4.0 through 6.4.8, 7.0.0 may allow a network adjacent and unauthenticated attacker to man-in-the-middle the communication between the FortiGate and some peers such as private SDNs and external cloud platforms.
nvd
CVE-2019-5588P4MEDIUMCVSS 6.1vFortiOS 6.0.0 to 6.0.42019-06-04
CVE-2019-5588 [MEDIUM] CWE-79 CVE-2019-5588: A reflected Cross-Site-Scripting (XSS) vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4 under SSL VP
A reflected Cross-Site-Scripting (XSS) vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4 under SSL VPN web portal may allow an attacker to execute unauthorized malicious script code via the "err" parameter of the error process HTTP requests.
nvd
CVE-2018-13366P4MEDIUMCVSS 5.3v6.0.1v5.6.7 and below2019-04-09
CVE-2018-13366 [MEDIUM] CWE-200 CVE-2018-13366: An information disclosure vulnerability in Fortinet FortiOS 6.0.1, 5.6.7 and below allows attacker t
An information disclosure vulnerability in Fortinet FortiOS 6.0.1, 5.6.7 and below allows attacker to reveals serial number of FortiGate via hostname field defined in connection control setup packets of PPTP protocol.
nvd
CVE-2021-43080P4MEDIUMCVSS 5.4vFortiOS 7.2.0, 7.0.5, 7.0.4, 7.0.3, 7.0.2, 7.0.1, 7.0.0, 6.4.9, 6.4.8, 6.4.7, 6.4.6, 6.4.5, 6.4.4, 6.4.3, 6.4.2, 6.4.1, 6.4.02022-09-06
CVE-2021-43080 [MEDIUM] CWE-79 CVE-2021-43080: An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiOS ver
An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiOS version 7.2.0, version 6.4.0 through 6.4.9, version 7.0.0 through 7.0.5 may allow an authenticated attacker to perform a stored cross site scripting (XSS) attack through the URI parameter via the Threat Feed IP address section of the Security Fabric Exter
nvd
CVE-2022-23442P4MEDIUMCVSS 4.3vFortiOS 7.0.5, 7.0.4, 7.0.3, 7.0.2, 7.0.1, 7.0.0, 6.4.8, 6.4.7, 6.4.6, 6.4.5, 6.4.4, 6.4.3, 6.4.2, 6.4.1, 6.4.0, 6.2.11, 6.2.10, 6.2.9, 6.2.8, 6.2.7, 6.2.6, 6.2.5, 6.2.4, 6.2.3, 6.2.2, 6.2.1, 6.2.02022-08-03
CVE-2022-23442 [MEDIUM] CVE-2022-23442: An improper access control vulnerability [CWE-284] in FortiOS versions 6.2.0 through 6.2.11, 6.4.0 t
An improper access control vulnerability [CWE-284] in FortiOS versions 6.2.0 through 6.2.11, 6.4.0 through 6.4.8 and 7.0.0 through 7.0.5 may allow an authenticated attacker with a restricted user profile to gather the checksum information about the other VDOMs via CLI commands.
nvd
CVE-2020-15936P4MEDIUMCVSS 4.5vFortiOS 6.4.3, 6.4.2, 6.4.1, 6.4.0, 6.2.5, 6.2.4, 6.2.3, 6.2.2, 6.2.1, 6.2.0, 6.0.11, 6.0.10, 6.0.9, 6.0.8, 6.0.7, 6.0.6, 6.0.5, 6.0.4, 6.0.3, 6.0.2, 6.0.1, 6.0.0, 5.6.13, 5.6.12, 5.6.11, 5.6.10, 5.6.9, 5.6.8, 5.6.7, 5.6.6, 5.6.5, 5.6.4, 5.6.3, 5.6.2, 5.6.1, 5.6.02022-03-01
CVE-2020-15936 [MEDIUM] CWE-20 CVE-2020-15936: A improper input validation in Fortinet FortiGate version 6.4.3 and below, version 6.2.5 and below,
A improper input validation in Fortinet FortiGate version 6.4.3 and below, version 6.2.5 and below, version 6.0.11 and below, version 5.6.13 and below allows attacker to disclose sensitive information via SNI Client Hello TLS packets.
nvd
CVE-2017-3128P4MEDIUMCVSS 4.8v5.0.0-5.0.14, 5.2.0-5.2.102017-05-23
CVE-2017-3128 [MEDIUM] CWE-79 CVE-2017-3128: A stored XSS (Cross-Site-Scripting) vulnerability in Fortinet FortiOS allows attackers to execute un
A stored XSS (Cross-Site-Scripting) vulnerability in Fortinet FortiOS allows attackers to execute unauthorized code or commands via the policy global-label parameter.
nvd
CVE-2021-32600P4LOWCVSS 3.8vFortiOS 7.0.0, 6.4.0 through 6.4.6, 6.2.0 through 6.2.9, 6.0.x, 5.6.x2021-11-17
CVE-2021-32600 [LOW] CWE-200 CVE-2021-32600: An exposure of sensitive information to an unauthorized actor vulnerability in FortiOS CLI 7.0.0, 6.
An exposure of sensitive information to an unauthorized actor vulnerability in FortiOS CLI 7.0.0, 6.4.0 through 6.4.6, 6.2.0 through 6.2.9, 6.0.x and 5.6.x may allow a local and authenticated user assigned to a specific VDOM to retrieve other VDOMs information such as the admin account list and the network interface list.
nvd
CVE-2022-29053P4LOWCVSS 3.3vFortiOS 7.2.0, 7.0.5, 7.0.4, 7.0.3, 7.0.2, 7.0.1, 7.0.0, 6.4.9, 6.4.8, 6.4.7, 6.4.6, 6.4.5, 6.4.4, 6.4.3, 6.4.2, 6.4.1, 6.4.0, 6.2.10, 6.2.9, 6.2.8, 6.2.7, 6.2.6, 6.2.5, 6.2.4, 6.2.3, 6.2.2, 6.2.1, 6.2.0, 6.0.14, 6.0.13, 6.0.12, 6.0.11, 6.0.10, 6.0.9, 6.0.8, 6.0.7, 6.0.6, 6.0.5, 6.0.4, 6.0.3, 6.0.2, 6.0.1, 6.0.02022-09-06
CVE-2022-29053 [LOW] CVE-2022-29053: A missing cryptographic steps vulnerability [CWE-325] in the functions that encrypt the keytab files
A missing cryptographic steps vulnerability [CWE-325] in the functions that encrypt the keytab files in FortiOS version 7.2.0, 7.0.0 through 7.0.5 and below 7.0.0 may allow an attacker in possession of the encrypted file to decipher it.
nvd
← Previous2 / 2