Fortinet Fortios vulnerabilities
277 known vulnerabilities affecting fortinet/fortios.
Total CVEs
277
CISA KEV
19
actively exploited
Public exploits
24
Exploited in wild
25
Severity breakdown
CRITICAL25HIGH86MEDIUM156LOW10
Vulnerabilities
Page 10 of 14
CVE-2020-12818P4MEDIUMCVSS 5.3fixed in 6.4.12020-09-24
CVE-2020-12818 [MEDIUM] CVE-2020-12818: An insufficient logging vulnerability in FortiGate before 6.4.1 may allow the traffic from an unauth
An insufficient logging vulnerability in FortiGate before 6.4.1 may allow the traffic from an unauthenticated attacker to Fortinet owned IP addresses to go unnoticed.
nvd
CVE-2021-41032P4MEDIUMCVSS 5.4≥ 6.2.0, < 6.4.9≥ 7.0.0, < 7.0.42022-05-04
CVE-2021-41032 [MEDIUM] CVE-2021-41032: An improper access control vulnerability [CWE-284] in FortiOS versions 6.4.8 and prior and 7.0.3 and
An improper access control vulnerability [CWE-284] in FortiOS versions 6.4.8 and prior and 7.0.3 and prior may allow an authenticated attacker with a restricted user profile to gather sensitive information and modify the SSL-VPN tunnel status of other VDOMs using specific CLI commands.
nvd
CVE-2022-42472P4MEDIUMCVSS 5.4≥ 6.0.1, ≤ 6.0.16≥ 6.2.0, ≤ 6.2.12+7 more2023-02-16
CVE-2022-42472 [MEDIUM] CWE-113 CVE-2022-42472: A improper neutralization of crlf sequences in http headers ('http response splitting') in Fortinet
A improper neutralization of crlf sequences in http headers ('http response splitting') in Fortinet FortiOS versions 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0 through 6.4.11, 6.2.0 through 6.2.12, 6.0.0 through 6.0.16, FortiProxy 7.2.0 through 7.2.1, 7.0.0 through 7.0.7, 2.0.0 through 2.0.10, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6 may allow
nvd
CVE-2026-59839P4MEDIUMCVSS 5.5≥ 6.4.0, < 7.4.10≥ 7.6.0, < 7.6.7+5 more2026-07-14
CVE-2026-59839 [MEDIUM] CWE-22 CVE-2026-59839: A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fo
A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiOS 7.6.0 through 7.6.6, FortiOS 7.4.0 through 7.4.9, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiPAM 1.8.0, FortiPAM 1.7.0 through 1.7.2, FortiPAM 1.6 all versions, FortiPAM 1.5 all versions, FortiPAM
nvd
CVE-2022-41329P4MEDIUMCVSS 5.3≥ 6.2.3, ≤ 6.2.13≥ 6.4.0, ≤ 6.4.11+2 more2023-03-07
CVE-2022-41329 [MEDIUM] CWE-200 CVE-2022-41329: An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in Fortinet Fo
An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in Fortinet FortiProxy version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.7, FortiOS version 7.2.0 through 7.2.3 and 7.0.0 through 7.0.9 allows an unauthenticated attackers to obtain sensitive logging informations on the device via crafted HTTP GET requests.
nvd
CVE-2017-14182P4MEDIUMCVSS 6.5v5.4.0v5.4.1+4 more2017-10-27
CVE-2017-14182 [MEDIUM] CWE-20 CVE-2017-14182: A Denial of Service (DoS) vulnerability in Fortinet FortiOS 5.4.0 to 5.4.5 allows an authenticated u
A Denial of Service (DoS) vulnerability in Fortinet FortiOS 5.4.0 to 5.4.5 allows an authenticated user to cause the web GUI to be temporarily unresponsive, via passing a specially crafted payload to the 'params' parameter of the JSON web API.
nvd
CVE-2021-42757P4MEDIUMCVSS 6.7≥ 5.0.0, ≤ 6.0.13≥ 6.2.0, ≤ 6.2.9+6 more2021-12-08
CVE-2021-42757 [MEDIUM] CWE-120 CVE-2021-42757: A buffer overflow [CWE-121] in the TFTP client library of FortiOS before 6.4.7 and FortiOS 7.0.0 thr
A buffer overflow [CWE-121] in the TFTP client library of FortiOS before 6.4.7 and FortiOS 7.0.0 through 7.0.2, may allow an authenticated local attacker to achieve arbitrary code execution via specially crafted command line arguments.
nvd
CVE-2019-6696P4MEDIUMCVSS 6.1≥ 5.4.0, ≤ 6.0.8v6.2.0+1 more2020-03-15
CVE-2019-6696 [MEDIUM] CWE-20 CVE-2019-6696: An improper input validation vulnerability in FortiOS 6.2.1, 6.2.0, 6.0.8 and below until 5.4.0 unde
An improper input validation vulnerability in FortiOS 6.2.1, 6.2.0, 6.0.8 and below until 5.4.0 under admin webUI may allow an attacker to perform an URL redirect attack via a specifically crafted request to the admin initial password change webpage.
nvd
CVE-2019-16151P4MEDIUMCVSS 6.1≥ 6.2.0, < 6.2.10≥ 6.4.0, < 6.4.2+2 more2025-03-21
CVE-2019-16151 [MEDIUM] CWE-79 CVE-2019-16151: An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiOS 6.4
An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiOS 6.4.1 and below, 6.2.9 and below may allow a remote unauthenticated attacker to either redirect users to malicious websites via a crafted "Host" header or to execute JavaScript code in the victim's browser context.
This happens when the FortiGate has web
nvd
CVE-2019-6697P4MEDIUMCVSS 6.1≥ 6.0.0, < 6.0.7≥ 6.2.0, < 6.2.2+1 more2025-03-17
CVE-2019-6697 [MEDIUM] CWE-79 CVE-2019-6697: An Improper Neutralization of Input vulnerability affecting FortiGate version 6.2.0 through 6.2.1, 6
An Improper Neutralization of Input vulnerability affecting FortiGate version 6.2.0 through 6.2.1, 6.0.0 through 6.0.6 in the hostname parameter of a DHCP packet under DHCP monitor page may allow an unauthenticated attacker in the same network as the FortiGate to perform a Stored Cross Site Scripting attack (XSS) by sending a crafted DHCP packet.
nvd
CVE-2026-23573P4MEDIUMCVSS 6.1≥ 7.2.0, < 7.6.7≥ 7.6.0, ≤ 7.6.6+4 more2026-07-14
CVE-2026-23573 [MEDIUM] CWE-79 CVE-2026-23573: An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerabilit
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.6, FortiOS 7.4 all versions, FortiOS 7.2 all versions, FortiPAM 1.8.0, FortiPAM 1.7 all versions, FortiPAM 1.6 all versions, FortiPAM 1.5 all versions, FortiPAM 1.4 all versions, FortiPAM 1
nvd
CVE-2023-22641P4MEDIUMCVSS 5.4≥ 6.0.0, < 6.4.13≥ 7.0.0, < 7.0.11+6 more2023-04-11
CVE-2023-22641 [MEDIUM] CWE-601 CVE-2023-22641: A url redirection to untrusted site ('open redirect') in Fortinet FortiOS version 7.2.0 through 7.2.
A url redirection to untrusted site ('open redirect') in Fortinet FortiOS version 7.2.0 through 7.2.3, FortiOS version 7.0.0 through 7.0.9, FortiOS versions 6.4.0 through 6.4.12, FortiOS all versions 6.2, FortiOS all versions 6.0, FortiProxy version 7.2.0 through 7.2.2, FortiProxy version 7.0.0 through 7.0.8, FortiProxy all versions 2.0, FortiProxy
nvd
CVE-2016-7542P4MEDIUMCVSS 4.9v5.2.0v5.2.1+11 more2017-03-30
CVE-2016-7542 [MEDIUM] CWE-200 CVE-2016-7542: A read-only administrator on Fortinet devices with FortiOS 5.2.x before 5.2.10 GA and 5.4.x before 5
A read-only administrator on Fortinet devices with FortiOS 5.2.x before 5.2.10 GA and 5.4.x before 5.4.2 GA may have access to read-write administrators password hashes (not including super-admins) stored on the appliance via the webui REST API, and may therefore be able to crack them.
nvd
CVE-2018-13384P4MEDIUMCVSS 6.1fixed in 6.0.52019-06-04
CVE-2018-13384 [MEDIUM] CWE-601 CVE-2018-13384: A Host Header Redirection vulnerability in Fortinet FortiOS all versions below 6.0.5 under SSL VPN w
A Host Header Redirection vulnerability in Fortinet FortiOS all versions below 6.0.5 under SSL VPN web portal allows a remote attacker to potentially poison HTTP cache and subsequently redirect SSL VPN web portal users to arbitrary web domains.
nvd
CVE-2021-26092P4MEDIUMCVSS 6.1≥ 5.2.10, ≤ 5.2.15≥ 5.4.0, ≤ 5.4.13+4 more2022-02-24
CVE-2021-26092 [MEDIUM] CWE-79 CVE-2021-26092: Failure to sanitize input in the SSL VPN web portal of FortiOS 5.2.10 through 5.2.15, 5.4.0 through
Failure to sanitize input in the SSL VPN web portal of FortiOS 5.2.10 through 5.2.15, 5.4.0 through 5.4.13, 5.6.0 through 5.6.14, 6.0.0 through 6.0.12, 6.2.0 through 6.2.7, 6.4.0 through 6.4.4; and FortiProxy 1.2.0 through 1.2.9, 2.0.0 through 2.0.1 may allow a remote unauthenticated attacker to perform a reflected Cross-site Scripting (XSS) attack by
nvd
CVE-2022-41334P4MEDIUMCVSS 6.1≥ 7.0.0, ≤ 7.0.7≥ 7.2.0, ≤ 7.2.32023-02-16
CVE-2022-41334 [MEDIUM] CWE-79 CVE-2022-41334: An improper neutralization of input during web page generation [CWE-79] vulnerability in FortiOS ver
An improper neutralization of input during web page generation [CWE-79] vulnerability in FortiOS versions 7.0.0 to 7.0.7 and 7.2.0 to 7.2.3 may allow a remote, unauthenticated attacker to launch a cross site scripting (XSS) attack via the "redir" parameter of the URL seen when the "Sign in with FortiCloud" button is clicked.
nvd
CVE-2018-9194P4MEDIUMCVSS 5.9≥ 5.4.6, ≤ 5.4.9v6.0.0+1 more2018-09-05
CVE-2018-9194 [MEDIUM] CWE-203 CVE-2018-9194: A plaintext recovery of encrypted messages or a Man-in-the-middle (MiTM) attack on RSA PKCS #1 v1.5
A plaintext recovery of encrypted messages or a Man-in-the-middle (MiTM) attack on RSA PKCS #1 v1.5 encryption may be possible without knowledge of the server's private key. Fortinet FortiOS 5.4.6 to 5.4.9, 6.0.0 and 6.0.1 are vulnerable by such attack under VIP SSL feature when CPx being used.
nvd
CVE-2018-9192P4MEDIUMCVSS 5.9≥ 5.4.6, ≤ 5.4.9v6.0.0+1 more2018-09-05
CVE-2018-9192 [MEDIUM] CWE-203 CVE-2018-9192: A plaintext recovery of encrypted messages or a Man-in-the-middle (MiTM) attack on RSA PKCS #1 v1.5
A plaintext recovery of encrypted messages or a Man-in-the-middle (MiTM) attack on RSA PKCS #1 v1.5 encryption may be possible without knowledge of the server's private key. Fortinet FortiOS 5.4.6 to 5.4.9, 6.0.0 and 6.0.1 are vulnerable by such attack under SSL Deep Inspection feature when CPx being used.
nvd
CVE-2024-26006P4MEDIUMCVSS 6.1≥ 6.4.0, < 7.0.14≥ 7.2.0, < 7.2.8+5 more2025-03-14
CVE-2024-26006 [MEDIUM] CWE-79 CVE-2024-26006: An improper neutralization of input during web page Generation vulnerability [CWE-79] in FortiOS ver
An improper neutralization of input during web page Generation vulnerability [CWE-79] in FortiOS version 7.4.3 and below, version 7.2.7 and below, version 7.0.13 and below and FortiProxy version 7.4.3 and below, version 7.2.9 and below, version 7.0.16 and below web SSL VPN UI may allow a remote unauthenticated attacker to perform a Cross-Site Scripti
nvd
CVE-2016-7541P4MEDIUMCVSS 5.9v5.0.0v5.0.1+25 more2017-03-30
CVE-2016-7541 [MEDIUM] CWE-254 CVE-2016-7541: Long lived sessions in Fortinet FortiGate devices with FortiOS 5.x before 5.4.0 could violate a secu
Long lived sessions in Fortinet FortiGate devices with FortiOS 5.x before 5.4.0 could violate a security policy during IPS signature updates when the FortiGate's IPSengine is configured in flow mode. All FortiGate versions with IPS configured in proxy mode (the default mode) are not affected.
nvd