cbcvebase.

Fortinet Fortios vulnerabilities

277 known vulnerabilities affecting fortinet/fortios.

Total CVEs
277
CISA KEV
19
actively exploited
Public exploits
24
Exploited in wild
25
Severity breakdown
CRITICAL25HIGH86MEDIUM156LOW10

Vulnerabilities

Page 11 of 14
CVE-2022-38378P4MEDIUMCVSS 6.0≥ 6.0.0, < 7.0.8≥ 7.2.0, < 7.2.1+5 more2023-02-16
CVE-2022-38378 [MEDIUM] CWE-269 CVE-2022-38378: An improper privilege management vulnerability [CWE-269] in Fortinet FortiOS version 7.2.0 and befor An improper privilege management vulnerability [CWE-269] in Fortinet FortiOS version 7.2.0 and before 7.0.7 and FortiProxy version 7.2.0 through 7.2.1 and before 7.0.7 allows an attacker that has access to the admin profile section (System subsection Administrator Users) to modify their own profile and upgrade their privileges to Read Write via CLI
nvd
CVE-2018-13367P4MEDIUMCVSS 5.3≤ 6.2.0v6.2.3+1 more2019-08-23
CVE-2018-13367 [MEDIUM] CWE-200 CVE-2018-13367: An information exposure vulnerability in FortiOS 6.2.3, 6.2.0 and below may allow an unauthenticated An information exposure vulnerability in FortiOS 6.2.3, 6.2.0 and below may allow an unauthenticated attacker to gain platform information such as version, models, via parsing a JavaScript file through admin webUI.
nvd
CVE-2024-36505P4MEDIUMCVSS 5.5≥ 6.4.13, ≤ 6.4.15≥ 7.0.12, < 7.0.15+5 more2024-08-13
CVE-2024-36505 [MEDIUM] CWE-284 CVE-2024-36505: An improper access control vulnerability [CWE-284] in FortiOS 7.4.0 through 7.4.3, 7.2.5 through 7.2 An improper access control vulnerability [CWE-284] in FortiOS 7.4.0 through 7.4.3, 7.2.5 through 7.2.7, 7.0.12 through 7.0.14 and 6.4.x may allow an attacker who has already successfully obtained write access to the underlying system (via another hypothetical exploit) to bypass the file integrity checking system.
nvd
CVE-2015-2323P4MEDIUMCVSS 6.4v5.0.0v5.0.1+14 more2015-08-11
CVE-2015-2323 [MEDIUM] CWE-310 CVE-2015-2323: FortiOS 5.0.x before 5.0.12 and 5.2.x before 5.2.4 supports anonymous, export, RC4, and possibly oth FortiOS 5.0.x before 5.0.12 and 5.2.x before 5.2.4 supports anonymous, export, RC4, and possibly other weak ciphers when using TLS to connect to FortiGuard servers, which allows man-in-the-middle attackers to spoof TLS content by modifying packets.
nvd
CVE-2025-25255P4MEDIUMCVSS 4.3≥ 7.6.0, < 7.6.4≥ 7.6.0, ≤ 7.6.32025-10-14
CVE-2025-25255 [MEDIUM] CWE-358 CVE-2025-25255: An Improperly Implemented Security Check for Standard vulnerability [CWE-358] vulnerability in Forti An Improperly Implemented Security Check for Standard vulnerability [CWE-358] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiProxy 7.6.0 through 7.6.3, FortiProxy 7.4.0 through 7.4.11, FortiProxy 7.2 all versions, FortiProxy 7.0.1 through 7.0.22 may allow an unauthenticated proxy user to bypass the domain fronting protection feature via
nvd
CVE-2021-43081P4MEDIUMCVSS 6.1≥ 6.0.0, ≤ 6.0.14≥ 6.2.0, ≤ 6.2.10+2 more2022-05-11
CVE-2021-43081 [MEDIUM] CWE-79 CVE-2021-43081: An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiOS ver An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiOS version 7.0.3 and below, 6.4.8 and below, 6.2.10 and below, 6.0.14 to 6.0.0. and in FortiProxy version 7.0.1 and below, 2.0.7 to 2.0.0 web filter override form may allow an unauthenticated attacker to perform an XSS attack via crafted HTTP GET requests.
nvd
CVE-2022-41330P4MEDIUMCVSS 6.1≥ 6.2.0, < 6.2.13≥ 6.4.0, < 6.4.12+6 more2023-04-11
CVE-2022-41330 [MEDIUM] CWE-79 CVE-2022-41330: An improper neutralization of input during web page generation vulnerability ('Cross-site Scripting' An improper neutralization of input during web page generation vulnerability ('Cross-site Scripting') [CWE-79] in Fortinet FortiOS version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.9, version 6.4.0 through 6.4.11 and before 6.2.12 and FortiProxy version 7.2.0 through 7.2.1 and before 7.0.7 allows an unauthenticated attacker to perform an XSS att
nvd
CVE-2020-29010P4MEDIUMCVSS 5.0≥ 6.0.0, < 6.0.11≥ 6.2.0, < 6.2.5+2 more2025-03-17
CVE-2020-29010 [MEDIUM] CWE-200 CVE-2020-29010: An exposure of sensitive information to an unauthorized actor vulnerability in FortiOS version 6.2.4 An exposure of sensitive information to an unauthorized actor vulnerability in FortiOS version 6.2.4 and below, version 6.0.10 and belowmay allow remote authenticated actors to read the SSL VPN events log entries of users in other VDOMs by executing "get vpn ssl monitor" from the CLI. The sensitive data includes usernames, user groups, and IP addres
nvd
CVE-2023-45586P4MEDIUMCVSS 5.0≥ 6.2.0, ≤ 6.2.16≥ 6.4.0, ≤ 6.4.15+7 more2024-05-14
CVE-2023-45586 [MEDIUM] CWE-345 CVE-2023-45586: An insufficient verification of data authenticity vulnerability [CWE-345] in Fortinet FortiOS SSL-VP An insufficient verification of data authenticity vulnerability [CWE-345] in Fortinet FortiOS SSL-VPN tunnel mode version 7.4.0 through 7.4.1, version 7.2.0 through 7.2.7 and before 7.0.12 & FortiProxy SSL-VPN tunnel mode version 7.4.0 through 7.4.1, version 7.2.0 through 7.2.7 and before 7.0.13 allows an authenticated VPN user to send (but not rece
nvd
CVE-2023-47537P4MEDIUMCVSS 4.8≥ 7.0.0, < 7.0.14≥ 7.2.0, ≤ 7.2.6+5 more2024-02-15
CVE-2023-47537 [MEDIUM] CWE-295 CVE-2023-47537: An improper certificate validation vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7. An improper certificate validation vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2.0 through 7.2.6, FortiOS 7.0.0 through 7.0.15, FortiOS 6.4 all versions allows a remote and unauthenticated attacker to perform a Man-in-the-Middle attack on the FortiLink communication channel between the FortiOS device and FortiSwitch.
nvd
CVE-2023-29175P4MEDIUMCVSS 4.8≥ 6.0.0, ≤ 6.0.17≥ 6.2.0, ≤ 6.2.15+4 more2023-06-13
CVE-2023-29175 [MEDIUM] CWE-295 CVE-2023-29175: An improper certificate validation vulnerability [CWE-295] in FortiOS 6.2 all versions, 6.4 all vers An improper certificate validation vulnerability [CWE-295] in FortiOS 6.2 all versions, 6.4 all versions, 7.0.0 through 7.0.10, 7.2.0 and FortiProxy 1.2 all versions, 2.0 all versions, 7.0.0 through 7.0.9, 7.2.0 through 7.2.3 may allow a remote and unauthenticated attacker to perform a Man-in-the-Middle attack on the communication channel between th
nvd
CVE-2017-7733P4MEDIUMCVSS 6.1v5.4.0v5.4.1+5 more2017-10-27
CVE-2017-7733 [MEDIUM] CWE-79 CVE-2017-7733: A Cross-Site-Scripting (XSS) vulnerability in Fortinet FortiOS 5.4.0 to 5.4.5 and 5.6.0 allows a rem A Cross-Site-Scripting (XSS) vulnerability in Fortinet FortiOS 5.4.0 to 5.4.5 and 5.6.0 allows a remote unauthenticated attacker to execute arbitrary javascript code via webUI "Login Disclaimer" redir parameter.
nvd
CVE-2017-7739P4MEDIUMCVSS 6.1v5.2.0v5.2.1+17 more2017-11-13
CVE-2017-7739 [MEDIUM] CWE-79 CVE-2017-7739: A reflected Cross-site Scripting (XSS) vulnerability in web proxy disclaimer response web pages in F A reflected Cross-site Scripting (XSS) vulnerability in web proxy disclaimer response web pages in Fortinet FortiOS 5.6.0, 5.4.0 to 5.4.5, 5.2.0 to 5.2.11 allows an unauthenticated attacker to inject arbitrary web script or HTML in the context of the victim's browser via sending a maliciously crafted URL to the victim.
nvd
CVE-2022-23438P4MEDIUMCVSS 6.1≤ 6.4.9≥ 7.0.0, ≤ 7.0.52022-07-18
CVE-2022-23438 [MEDIUM] CWE-79 CVE-2022-23438: An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vul An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in FortiOS version 7.0.5 and prior and 6.4.9 and prior may allow an unauthenticated remote attacker to perform a reflected cross site scripting (XSS) attack in the captive portal authentication replacement page.
nvd
CVE-2023-29183P4MEDIUMCVSS 5.4≥ 6.2.0, < 6.2.15≥ 6.4.0, < 6.4.13+6 more2023-09-13
CVE-2023-29183 [MEDIUM] CWE-79 CVE-2023-29183: An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerabilit An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiProxy 7.2.0 through 7.2.4, 7.0.0 through 7.0.10 and FortiOS 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through 6.4.12, 6.2.0 through 6.2.14 GUI may allow an authenticated attacker to trigger malicious JavaScript code execution
nvd
CVE-2017-14185P4MEDIUMCVSS 5.3≥ 5.2.0, ≤ 5.2.13≥ 5.4.0, ≤ 5.4.8+1 more2018-05-25
CVE-2017-14185 [MEDIUM] CWE-200 CVE-2017-14185: An Information Disclosure vulnerability in Fortinet FortiOS 5.6.0 to 5.6.2, 5.4.0 to 5.4.8 and 5.2 a An Information Disclosure vulnerability in Fortinet FortiOS 5.6.0 to 5.6.2, 5.4.0 to 5.4.8 and 5.2 all versions allows SSL VPN web portal users to access internal FortiOS configuration information (eg:addresses) via specifically crafted URLs inside the SSL-VPN web portal.
nvd
CVE-2006-3222P4MEDIUMCVSS 5.0v2.5_0mr4v2.8_mr10+7 more2006-06-24
CVE-2006-3222 [MEDIUM] CVE-2006-3222: The FTP proxy module in Fortinet FortiOS (FortiGate) before 2.80 MR12 and 3.0 MR2 allows remote atta The FTP proxy module in Fortinet FortiOS (FortiGate) before 2.80 MR12 and 3.0 MR2 allows remote attackers to bypass anti-virus scanning via the Enhanced Passive (EPSV) FTP mode.
nvd
CVE-2022-40680P4MEDIUMCVSS 5.4≥ 6.0.7, ≤ 6.0.15≥ 6.2.2, ≤ 6.2.12+2 more2022-12-06
CVE-2022-40680 [MEDIUM] CWE-79 CVE-2022-40680: A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet F A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiOS 6.0.7 - 6.0.15, 6.2.2 - 6.2.12, 6.4.0 - 6.4.9 and 7.0.0 - 7.0.3 allows a privileged attacker to execute unauthorized code or commands via storing malicious payloads in replacement messages.
nvd
CVE-2023-36555P4MEDIUMCVSS 5.4≥ 7.2.0, ≤ 7.2.42023-10-10
CVE-2023-36555 [MEDIUM] CWE-80 CVE-2023-36555: An improper neutralization of script-related html tags in a web page (basic xss) in Fortinet FortiOS An improper neutralization of script-related html tags in a web page (basic xss) in Fortinet FortiOS 7.2.0 - 7.2.4 allows an attacker to execute unauthorized code or commands via the SAML and Security Fabric components.
nvd
CVE-2025-58903P4MEDIUMCVSS 4.9≥ 6.4.0, < 7.4.9≥ 7.6.0, < 7.6.4+5 more2025-10-14
CVE-2025-58903 [MEDIUM] CWE-252 CVE-2025-58903: An Unchecked Return Value vulnerability [CWE-252] in Fortinet FortiOS version 7.6.0 through 7.6.3 an An Unchecked Return Value vulnerability [CWE-252] in Fortinet FortiOS version 7.6.0 through 7.6.3 and before 7.4.8 API allows an authenticated user to cause a Null Pointer Dereference, crashing the http daemon via a specialy crafted request.
nvd
Fortinet Fortios vulnerabilities | cvebase