Fortinet Fortios vulnerabilities

268 known vulnerabilities affecting fortinet/fortios.

Total CVEs
268
CISA KEV
18
actively exploited
Public exploits
19
Exploited in wild
13
Severity breakdown
CRITICAL25HIGH84MEDIUM149LOW10

Vulnerabilities

Page 12 of 14
CVE-2017-17544HIGHCVSS 7.2≤ 5.4.0≥ 5.6.0, ≤ 5.6.10+2 more2019-04-09
CVE-2017-17544 [HIGH] CWE-269 CVE-2017-17544: A privilege escalation vulnerability in Fortinet FortiOS 6.0.0 to 6.0.6, 5.6.0 to 5.6.10, 5.4 and be A privilege escalation vulnerability in Fortinet FortiOS 6.0.0 to 6.0.6, 5.6.0 to 5.6.10, 5.4 and below allows admin users to elevate their profile to super_admin via restoring modified configurations.
cvelistv5nvd
CVE-2018-13366MEDIUMCVSS 5.3≤ 5.6.7v6.0.0+1 more2019-04-09
CVE-2018-13366 [MEDIUM] CWE-200 CVE-2018-13366: An information disclosure vulnerability in Fortinet FortiOS 6.0.1, 5.6.7 and below allows attacker t An information disclosure vulnerability in Fortinet FortiOS 6.0.1, 5.6.7 and below allows attacker to reveals serial number of FortiGate via hostname field defined in connection control setup packets of PPTP protocol.
nvd
CVE-2018-1352CRITICALCVSS 9.8v5.6.02019-02-08
CVE-2018-1352 [CRITICAL] CWE-134 CVE-2018-1352: A format string vulnerability in Fortinet FortiOS 5.6.0 allows attacker to execute unauthorized code A format string vulnerability in Fortinet FortiOS 5.6.0 allows attacker to execute unauthorized code or commands via the SSH username variable.
nvd
CVE-2018-13374MEDIUMCVSS 4.3KEVPoCfixed in 6.0.32019-01-22
CVE-2018-13374 [MEDIUM] CWE-732 CVE-2018-13374: A Improper Access Control in Fortinet FortiOS 6.0.2, 5.6.7 and before, FortiADC 6.1.0, 6.0.0 to 6.0. A Improper Access Control in Fortinet FortiOS 6.0.2, 5.6.7 and before, FortiADC 6.1.0, 6.0.0 to 6.0.1, 5.4.0 to 5.4.4 allows attacker to obtain the LDAP server login credentials configured in FortiGate via pointing a LDAP server connectivity test request to a rogue LDAP server instead of the configured one.
nvd
CVE-2018-13376HIGHCVSS 7.5≤ 5.2.12≥ 5.4.6, ≤ 5.4.7+1 more2018-11-27
CVE-2018-13376 [HIGH] CVE-2018-13376: An uninitialized memory buffer leak exists in Fortinet FortiOS 5.6.1 to 5.6.3, 5.4.6 to 5.4.7, 5.2 a An uninitialized memory buffer leak exists in Fortinet FortiOS 5.6.1 to 5.6.3, 5.4.6 to 5.4.7, 5.2 all versions under web proxy's disclaimer response web pages, potentially causing sensitive data to be displayed in the HTTP response.
nvd
CVE-2018-9194MEDIUMCVSS 5.9≥ 5.4.6, ≤ 5.4.9v6.0.0+1 more2018-09-05
CVE-2018-9194 [MEDIUM] CWE-203 CVE-2018-9194: A plaintext recovery of encrypted messages or a Man-in-the-middle (MiTM) attack on RSA PKCS #1 v1.5 A plaintext recovery of encrypted messages or a Man-in-the-middle (MiTM) attack on RSA PKCS #1 v1.5 encryption may be possible without knowledge of the server's private key. Fortinet FortiOS 5.4.6 to 5.4.9, 6.0.0 and 6.0.1 are vulnerable by such attack under VIP SSL feature when CPx being used.
nvd
CVE-2018-9192MEDIUMCVSS 5.9≥ 5.4.6, ≤ 5.4.9v6.0.0+1 more2018-09-05
CVE-2018-9192 [MEDIUM] CWE-203 CVE-2018-9192: A plaintext recovery of encrypted messages or a Man-in-the-middle (MiTM) attack on RSA PKCS #1 v1.5 A plaintext recovery of encrypted messages or a Man-in-the-middle (MiTM) attack on RSA PKCS #1 v1.5 encryption may be possible without knowledge of the server's private key. Fortinet FortiOS 5.4.6 to 5.4.9, 6.0.0 and 6.0.1 are vulnerable by such attack under SSL Deep Inspection feature when CPx being used.
nvd
CVE-2018-9185HIGHCVSS 8.1≤ 6.0.02018-07-05
CVE-2018-9185 [HIGH] CWE-200 CVE-2018-9185: An information disclosure vulnerability in Fortinet FortiOS 6.0.0 and below versions reveals user's An information disclosure vulnerability in Fortinet FortiOS 6.0.0 and below versions reveals user's web portal login credentials in a Javascript file sent to client-side when pages bookmarked in web portal use the Single Sign-On feature.
nvd
CVE-2017-14185MEDIUMCVSS 5.3≥ 5.2.0, ≤ 5.2.13≥ 5.4.0, ≤ 5.4.8+1 more2018-05-25
CVE-2017-14185 [MEDIUM] CWE-200 CVE-2017-14185: An Information Disclosure vulnerability in Fortinet FortiOS 5.6.0 to 5.6.2, 5.4.0 to 5.4.8 and 5.2 a An Information Disclosure vulnerability in Fortinet FortiOS 5.6.0 to 5.6.2, 5.4.0 to 5.4.8 and 5.2 all versions allows SSL VPN web portal users to access internal FortiOS configuration information (eg:addresses) via specifically crafted URLs inside the SSL-VPN web portal.
nvd
CVE-2017-14187MEDIUMCVSS 6.2≤ 5.2.0≥ 5.4.0, ≤ 5.4.8+1 more2018-05-24
CVE-2017-14187 [MEDIUM] CWE-269 CVE-2017-14187: A local privilege escalation and local code execution vulnerability in Fortinet FortiOS 5.6.0 to 5.6 A local privilege escalation and local code execution vulnerability in Fortinet FortiOS 5.6.0 to 5.6.2, 5.4.0 to 5.4.8, and 5.2 and below versions allows attacker to execute unauthorized binary program contained on an USB drive plugged into a FortiGate via linking the aforementioned binary program to a command that is allowed to be run by the fnsysc
nvd
CVE-2012-0941MEDIUMCVSS 6.1≥ 4.3.0, < 4.3.62018-02-08
CVE-2012-0941 [MEDIUM] CWE-79 CVE-2012-0941: Multiple cross-site scripting (XSS) vulnerabilities in Fortinet FortiGate UTM WAF appliances with Fo Multiple cross-site scripting (XSS) vulnerabilities in Fortinet FortiGate UTM WAF appliances with FortiOS 4.3.x before 4.3.6 allow remote attackers to inject arbitrary web script or HTML via vectors involving the (1) Endpoint Monitor, (2) Dialup List, or (3) Log&Report Display modules, or the fields_sorted_opt parameter to (4) user/auth/list or (5) end
nvd
CVE-2017-14190MEDIUMCVSS 6.1≤ 5.2.0≥ 5.4.0, ≤ 5.4.7+1 more2018-01-29
CVE-2017-14190 [MEDIUM] CWE-79 CVE-2017-14190: A Cross-site Scripting vulnerability in Fortinet FortiOS 5.6.0 to 5.6.2, 5.4.0 to 5.4.7, 5.2 and ear A Cross-site Scripting vulnerability in Fortinet FortiOS 5.6.0 to 5.6.2, 5.4.0 to 5.4.7, 5.2 and earlier, allows attacker to inject arbitrary web script or HTML via maliciously crafted "Host" header in user HTTP requests.
nvd
CVE-2017-7738HIGHCVSS 7.2≤ 5.2≥ 5.4.0, ≤ 5.4.5+1 more2017-12-13
CVE-2017-7738 [HIGH] CWE-200 CVE-2017-7738: An Information Disclosure vulnerability in Fortinet FortiOS 5.6.0 to 5.6.2, 5.4.0 to 5.4.5, 5.2 and An Information Disclosure vulnerability in Fortinet FortiOS 5.6.0 to 5.6.2, 5.4.0 to 5.4.5, 5.2 and below versions allow an admin user with super_admin privileges to view the current SSL VPN web portal session info which may contains user credentials through the fnsysctl CLI command.
nvd
CVE-2017-14186MEDIUMCVSS 5.4PoC≤ 5.0≤ 5.2.12+2 more2017-11-29
CVE-2017-14186 [MEDIUM] CWE-79 CVE-2017-14186: A Cross-site Scripting (XSS) vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.7, 5.4 a A Cross-site Scripting (XSS) vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.7, 5.4 and below versions under SSL VPN web portal allows a remote user to inject arbitrary web script or HTML in the context of the victim's browser via the login redir parameter. An URL Redirection attack may also be feasible by injecting an external URL via
nvd
CVE-2017-7739MEDIUMCVSS 6.1v5.2.0v5.2.1+17 more2017-11-13
CVE-2017-7739 [MEDIUM] CWE-79 CVE-2017-7739: A reflected Cross-site Scripting (XSS) vulnerability in web proxy disclaimer response web pages in F A reflected Cross-site Scripting (XSS) vulnerability in web proxy disclaimer response web pages in Fortinet FortiOS 5.6.0, 5.4.0 to 5.4.5, 5.2.0 to 5.2.11 allows an unauthenticated attacker to inject arbitrary web script or HTML in the context of the victim's browser via sending a maliciously crafted URL to the victim.
nvd
CVE-2017-7733MEDIUMCVSS 6.1v5.4.0v5.4.1+5 more2017-10-27
CVE-2017-7733 [MEDIUM] CWE-79 CVE-2017-7733: A Cross-Site-Scripting (XSS) vulnerability in Fortinet FortiOS 5.4.0 to 5.4.5 and 5.6.0 allows a rem A Cross-Site-Scripting (XSS) vulnerability in Fortinet FortiOS 5.4.0 to 5.4.5 and 5.6.0 allows a remote unauthenticated attacker to execute arbitrary javascript code via webUI "Login Disclaimer" redir parameter.
nvd
CVE-2017-14182MEDIUMCVSS 6.5v5.4.0v5.4.1+4 more2017-10-27
CVE-2017-14182 [MEDIUM] CWE-20 CVE-2017-14182: A Denial of Service (DoS) vulnerability in Fortinet FortiOS 5.4.0 to 5.4.5 allows an authenticated u A Denial of Service (DoS) vulnerability in Fortinet FortiOS 5.4.0 to 5.4.5 allows an authenticated user to cause the web GUI to be temporarily unresponsive, via passing a specially crafted payload to the 'params' parameter of the JSON web API.
nvd
CVE-2017-7735MEDIUMCVSS 5.4v5.2.0v5.2.1+15 more2017-09-12
CVE-2017-7735 [MEDIUM] CWE-79 CVE-2017-7735: A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.2.0 through 5.2.11 and 5.4.0 thr A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.2.0 through 5.2.11 and 5.4.0 through 5.4.4 allows attackers to execute unauthorized code or commands via the "Groups" input while creating or editing User Groups.
nvd
CVE-2017-3133MEDIUMCVSS 6.1PoC≤ 5.6.02017-09-12
CVE-2017-3133 [MEDIUM] CWE-79 CVE-2017-3133: A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.6.0 and earlier allows attackers A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.6.0 and earlier allows attackers to execute unauthorized code or commands via the Replacement Message HTML for SSL-VPN.
nvd
CVE-2017-7734MEDIUMCVSS 5.4v5.4.0v5.4.1+3 more2017-09-12
CVE-2017-7734 [MEDIUM] CWE-79 CVE-2017-7734: A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.4.0 through 5.4.4 allows attacke A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.4.0 through 5.4.4 allows attackers to execute unauthorized code or commands via 'Comments' while saving Config Revisions.
nvd