Fortinet Fortios vulnerabilities
277 known vulnerabilities affecting fortinet/fortios.
Total CVEs
277
CISA KEV
19
actively exploited
Public exploits
24
Exploited in wild
25
Severity breakdown
CRITICAL25HIGH86MEDIUM156LOW10
Vulnerabilities
Page 1 of 14
CVE-2022-42475P1CRITICALCVSS 9.8KEVPoCRansomware≥ 5.0.0, ≤ 5.0.14≥ 5.2.0, ≤ 5.2.15+15 more2023-01-02
CVE-2022-42475 [CRITICAL] CWE-197 CVE-2022-42475: A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 t
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0 through 6.4.10, 6.2.0 through 6.2.11, 6.0.15 and earlier and FortiProxy SSL-VPN 7.2.0 through 7.2.1, 7.0.7 and earlier may allow a remote unauthenticated attacker to execute arbitrary code or commands via specifically crafted req
nvd
CVE-2024-55591P1CRITICALCVSS 9.8KEVPoCRansomware≥ 7.0.0, < 7.0.17≥ 7.0.0, ≤ 7.0.162025-01-14
CVE-2024-55591 [CRITICAL] CWE-288 CVE-2024-55591: An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiO
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy version 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12 allows a remote attacker to gain super-admin privileges via crafted requests to Node.js websocket module.
nvd
CVE-2018-13379P1CRITICALCVSS 9.8KEVPoCRansomware≥ 5.4.6, < 5.4.13≥ 5.6.3, < 5.6.8+1 more2019-06-04
CVE-2018-13379 [CRITICAL] CWE-22 CVE-2018-13379: An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiO
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.3 to 5.6.7 and 5.4.6 to 5.4.12 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 to 1.1.6, 1.0.0 to 1.0.7 under SSL VPN web portal allows an unauthenticated attacker to download system files via special crafted HTTP resource requests.
nvd
CVE-2022-40684P1CRITICALCVSS 9.8KEVPoCRansomware≥ 7.0.0, < 7.0.7≥ 7.2.0, < 7.2.22022-10-18
CVE-2022-40684 [CRITICAL] CWE-287 CVE-2022-40684: An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6, FortiProxy version 7.2.0 and version 7.0.0 through 7.0.6 and FortiSwitchManager version 7.2.0 and 7.0.0 allows an unauthenticated atttacker to perform operations on the administrative interface via speciall
nvd
CVE-2024-21762P1CRITICALCVSS 9.8KEVPoCRansomware≥ 6.0.0, < 6.0.18≥ 6.2.0, < 6.2.16+10 more2024-02-09
CVE-2024-21762 [CRITICAL] CWE-787 CVE-2024-21762: A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 t
A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, 6.0.0 through 6.0.17, FortiProxy versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0.14, 2.0.0 through 2.0.13, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6, 1.0.0 through 1.0.7
nvd
CVE-2023-27997P1CRITICALCVSS 9.8KEVPoCRansomware≥ 6.0.0, ≤ 6.0.16≥ 6.2.0, ≤ 6.2.13+16 more2023-06-13
CVE-2023-27997 [CRITICAL] CWE-122 CVE-2023-27997: A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, version 6.4.12 and below, version 6.0.16 and below and FortiProxy version 7.2.3 and below, version 7.0.9 and below, version 2.0.12 and below, version 1.2 all versions, version 1.1 all versions SSL-VPN may allow a remote attacker to ex
nvd
CVE-2024-23113P1CRITICALCVSS 9.8KEVPoC≥ 7.0.0, ≤ 7.0.13≥ 7.2.0, ≤ 7.2.6+1 more2024-02-15
CVE-2024-23113 [CRITICAL] CWE-134 CVE-2024-23113: A use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0
A use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, FortiProxy versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0.14, FortiPAM versions 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiSwitchManager versions 7.2.0 through 7.2.3, 7.0.0 throu
nvd
CVE-2018-13382P1HIGHCVSS 7.5KEVPoCRansomware≥ 5.4.1, < 5.4.11≥ 5.6.0, < 5.6.9+1 more2019-06-04
CVE-2018-13382 [HIGH] CWE-863 CVE-2018-13382: An Improper Authorization vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.8 and 5.4.1
An Improper Authorization vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.8 and 5.4.1 to 5.4.10 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 to 1.1.6, 1.0.0 to 1.0.7 under SSL VPN web portal allows an unauthenticated attacker to modify the password of an SSL VPN web portal user via specially crafted HTTP requests
nvd
CVE-2026-24858P1CRITICALCVSS 9.8KEV≥ 7.0.0, ≤ 7.0.18≥ 7.2.0, ≤ 7.2.12+4 more2026-01-27
CVE-2026-24858 [CRITICAL] CWE-288 CVE-2026-24858: An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.5, FortiAnalyzer 7.4.0 through 7.4.9, FortiAnalyzer 7.2.0 through 7.2.11, FortiAnalyzer 7.0.0 through 7.0.15, FortiManager 7.6.0 through 7.6.5, FortiManager 7.4.0 through 7.4.9, FortiManager 7.2.0 through 7.
nvd
CVE-2025-59718P1CRITICALCVSS 9.8KEVRansomware≥ 7.0.0, < 7.0.18≥ 7.2.0, < 7.2.12+6 more2025-12-09
CVE-2025-59718 [CRITICAL] CWE-347 CVE-2025-59718: A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7
A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiProxy 7.6.0 through 7.6.3, FortiProxy 7.4.0 through 7.4.10, FortiProxy 7.2.0 through 7.2.14, FortiProxy 7.0.0 through 7.0.21, FortiSwitchManager 7.2.
nvd
CVE-2018-13374P1MEDIUMCVSS 4.3KEVPoCRansomwarefixed in 6.0.32019-01-22
CVE-2018-13374 [MEDIUM] CWE-732 CVE-2018-13374: A Improper Access Control in Fortinet FortiOS 6.0.2, 5.6.7 and before, FortiADC 6.1.0, 6.0.0 to 6.0.
A Improper Access Control in Fortinet FortiOS 6.0.2, 5.6.7 and before, FortiADC 6.1.0, 6.0.0 to 6.0.1, 5.4.0 to 5.4.4 allows attacker to obtain the LDAP server login credentials configured in FortiGate via pointing a LDAP server connectivity test request to a rogue LDAP server instead of the configured one.
nvd
CVE-2019-5591P1MEDIUMCVSS 6.5KEVPoCRansomware≤ 6.2.02020-08-14
CVE-2019-5591 [MEDIUM] CWE-306 CVE-2019-5591: A Default Configuration vulnerability in FortiOS may allow an unauthenticated attacker on the same s
A Default Configuration vulnerability in FortiOS may allow an unauthenticated attacker on the same subnet to intercept sensitive information by impersonating the LDAP server.
nvd
CVE-2019-6693P1MEDIUMCVSS 6.5KEVPoCRansomware≤ 5.6.10≥ 6.0.0, ≤ 6.0.6+1 more2019-11-21
CVE-2019-6693 [MEDIUM] CWE-798 CVE-2019-6693: Use of a hard-coded cryptographic key to cipher sensitive data in FortiOS configuration backup file
Use of a hard-coded cryptographic key to cipher sensitive data in FortiOS configuration backup file may allow an attacker with access to the backup file to decipher the sensitive data, via knowledge of the hard-coded key. The aforementioned sensitive data includes users' passwords (except the administrator's password), private keys' passphrases and Hig
nvd
CVE-2020-12812P1CRITICALCVSS 9.8KEVRansomwarefixed in 6.0.10≥ 6.2.0, < 6.2.4+1 more2020-07-24
CVE-2020-12812 [CRITICAL] CWE-178 CVE-2020-12812: An improper authentication vulnerability in SSL VPN in FortiOS 6.4.0, 6.2.0 to 6.2.3, 6.0.9 and belo
An improper authentication vulnerability in SSL VPN in FortiOS 6.4.0, 6.2.0 to 6.2.3, 6.0.9 and below may result in a user being able to log in successfully without being prompted for the second factor of authentication (FortiToken) if they changed the case of their username.
nvd
CVE-2021-44168P1HIGHCVSS 7.8KEVPoCfixed in 6.0.14≥ 6.2.0, < 6.2.10+2 more2022-01-04
CVE-2021-44168 [HIGH] CWE-494 CVE-2021-44168: A download of code without integrity check vulnerability in the "execute restore src-vis" command of
A download of code without integrity check vulnerability in the "execute restore src-vis" command of FortiOS before 7.0.3 may allow a local authenticated attacker to download arbitrary files on the device via specially crafted update packages.
nvd
CVE-2025-24472P1HIGHCVSS 8.1KEVRansomware≥ 7.0.0, < 7.0.17≥ 7.0.0, ≤ 7.0.162025-02-11
CVE-2025-24472 [HIGH] CWE-288 CVE-2025-24472: An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiO
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS 7.0.0 through 7.0.16 and FortiProxy 7.2.0 through 7.2.12, 7.0.0 through 7.0.19 may allow a remote unauthenticated attacker with prior knowledge of upstream and downstream devices serial numbers to gain super-admin privileges on the downstream device,
nvd
CVE-2018-13383P1MEDIUMCVSS 6.5KEVRansomware≥ 5.2.0, < 5.2.15≥ 5.4.0, < 5.4.13+2 more2019-05-29
CVE-2018-13383 [MEDIUM] CWE-787 CVE-2018-13383: A heap buffer overflow in Fortinet FortiOS 6.0.0 through 6.0.4, 5.6.0 through 5.6.10, 5.4.0 through
A heap buffer overflow in Fortinet FortiOS 6.0.0 through 6.0.4, 5.6.0 through 5.6.10, 5.4.0 through 5.4.12, 5.2.14 and earlier and FortiProxy 2.0.0, 1.2.8 and earlier in the SSL VPN web portal may cause the SSL VPN web service termination for logged in users due to a failure to properly handle javascript href data when proxying webpages.
nvd
CVE-2022-41328P1HIGHCVSS 7.1KEV≥ 6.0.0, ≤ 6.0.16≥ 6.2.0, < 6.2.14+7 more2023-03-07
CVE-2022-41328 [HIGH] CWE-22 CVE-2022-41328: A improper limitation of a pathname to a restricted directory vulnerability ('path traversal') [CWE-
A improper limitation of a pathname to a restricted directory vulnerability ('path traversal') [CWE-22] in Fortinet FortiOS version 7.2.0 through 7.2.3, 7.0.0 through 7.0.9 and before 6.4.11 allows a privileged attacker to read and write files on the underlying Linux system via crafted CLI commands.
nvd
CVE-2025-68686P1MEDIUMCVSS 5.9KEV≥ 6.4.0, < 7.4.7≥ 7.6.0, < 7.6.2+5 more2026-02-10
CVE-2025-68686 [MEDIUM] CWE-200 CVE-2025-68686: An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability
An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1, FortiOS 7.4.0 through 7.4.6, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persisten
nvd
CVE-2016-6909P1CRITICALCVSS 9.8ExploitedPoC≥ 4.1.0, < 4.1.11≥ 4.2.0, < 4.2.13+1 more2016-08-24
CVE-2016-6909 [CRITICAL] CWE-119 CVE-2016-6909: Buffer overflow in the Cookie parser in Fortinet FortiOS 4.x before 4.1.11, 4.2.x before 4.2.13, and
Buffer overflow in the Cookie parser in Fortinet FortiOS 4.x before 4.1.11, 4.2.x before 4.2.13, and 4.3.x before 4.3.9 and FortiSwitch before 3.4.3 allows remote attackers to execute arbitrary code via a crafted HTTP request, aka EGREGIOUSBLUNDER.
nvd
1 / 14Next →