Fortinet Fortios vulnerabilities

268 known vulnerabilities affecting fortinet/fortios.

Total CVEs
268
CISA KEV
18
actively exploited
Public exploits
19
Exploited in wild
13
Severity breakdown
CRITICAL25HIGH84MEDIUM149LOW10

Vulnerabilities

Page 13 of 14
CVE-2017-3132MEDIUMCVSS 6.1PoC≤ 5.6.02017-09-12
CVE-2017-3132 [MEDIUM] CWE-79 CVE-2017-3132: A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.6.0 and earlier allows attackers A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.6.0 and earlier allows attackers to Execute unauthorized code or commands via the action input during the activation of a FortiToken.
nvd
CVE-2017-3131MEDIUMCVSS 5.4PoCv5.4.0v5.4.1+4 more2017-09-12
CVE-2017-3131 [MEDIUM] CWE-79 CVE-2017-3131: A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.4.0 through 5.4.4 and 5.6.0 allo A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.4.0 through 5.4.4 and 5.6.0 allows attackers to execute unauthorized code or commands via the filter input in "Applications" under FortiView.
nvd
CVE-2017-3130HIGHCVSS 7.5v5.0.0v5.0.1+30 more2017-08-10
CVE-2017-3130 [HIGH] CWE-200 CVE-2017-3130: An information disclosure vulnerability in Fortinet FortiOS 5.6.0, 5.4.4 and below versions allows a An information disclosure vulnerability in Fortinet FortiOS 5.6.0, 5.4.4 and below versions allows attacker to get FortiOS version info by inspecting FortiOS IKE VendorID packets.
nvd
CVE-2017-3127MEDIUMCVSS 6.1v5.2.0v5.2.1+9 more2017-06-01
CVE-2017-3127 [MEDIUM] CWE-79 CVE-2017-3127: A Cross-Site Scripting vulnerability in Fortinet FortiGate 5.2.0 through 5.2.10 allows attacker to e A Cross-Site Scripting vulnerability in Fortinet FortiGate 5.2.0 through 5.2.10 allows attacker to execute unauthorized code or commands via the srcintf parameter during Firewall Policy Creation.
nvd
CVE-2017-3128MEDIUMCVSS 4.8v5.0.0v5.0.1+24 more2017-05-23
CVE-2017-3128 [MEDIUM] CWE-79 CVE-2017-3128: A stored XSS (Cross-Site-Scripting) vulnerability in Fortinet FortiOS allows attackers to execute un A stored XSS (Cross-Site-Scripting) vulnerability in Fortinet FortiOS allows attackers to execute unauthorized code or commands via the policy global-label parameter.
nvd
CVE-2016-7542MEDIUMCVSS 4.9v5.2.0v5.2.1+11 more2017-03-30
CVE-2016-7542 [MEDIUM] CWE-200 CVE-2016-7542: A read-only administrator on Fortinet devices with FortiOS 5.2.x before 5.2.10 GA and 5.4.x before 5 A read-only administrator on Fortinet devices with FortiOS 5.2.x before 5.2.10 GA and 5.4.x before 5.4.2 GA may have access to read-write administrators password hashes (not including super-admins) stored on the appliance via the webui REST API, and may therefore be able to crack them.
cvelistv5nvd
CVE-2016-7541MEDIUMCVSS 5.9v5.0.0v5.0.1+25 more2017-03-30
CVE-2016-7541 [MEDIUM] CWE-254 CVE-2016-7541: Long lived sessions in Fortinet FortiGate devices with FortiOS 5.x before 5.4.0 could violate a secu Long lived sessions in Fortinet FortiGate devices with FortiOS 5.x before 5.4.0 could violate a security policy during IPS signature updates when the FortiGate's IPSengine is configured in flow mode. All FortiGate versions with IPS configured in proxy mode (the default mode) are not affected.
cvelistv5nvd
CVE-2016-8492MEDIUMCVSS 5.9≤ 4.3.18v4.3.0+7 more2017-02-08
CVE-2016-8492 [MEDIUM] CWE-200 CVE-2016-8492: The implementation of an ANSI X9.31 RNG in Fortinet FortiGate allows attackers to gain unauthorized The implementation of an ANSI X9.31 RNG in Fortinet FortiGate allows attackers to gain unauthorized read access to data handled by the device via IPSec/TLS decryption.
nvd
CVE-2016-6909CRITICALCVSS 9.8PoC≥ 4.1.0, < 4.1.11≥ 4.2.0, < 4.2.13+1 more2016-08-24
CVE-2016-6909 [CRITICAL] CWE-119 CVE-2016-6909: Buffer overflow in the Cookie parser in Fortinet FortiOS 4.x before 4.1.11, 4.2.x before 4.2.13, and Buffer overflow in the Cookie parser in Fortinet FortiOS 4.x before 4.1.11, 4.2.x before 4.2.13, and 4.3.x before 4.3.9 and FortiSwitch before 3.4.3 allows remote attackers to execute arbitrary code via a crafted HTTP request, aka EGREGIOUSBLUNDER.
nvd
CVE-2016-3978MEDIUMCVSS 6.1PoCv5.0.0v5.0.1+15 more2016-04-08
CVE-2016-3978 [MEDIUM] CWE-79 CVE-2016-3978: The Web User Interface (WebUI) in FortiOS 5.0.x before 5.0.13, 5.2.x before 5.2.3, and 5.4.x before The Web User Interface (WebUI) in FortiOS 5.0.x before 5.0.13, 5.2.x before 5.2.3, and 5.4.x before 5.4.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks or cross-site scripting (XSS) attacks via the "redirect" parameter to "login."
nvd
CVE-2016-1909CRITICALCVSS 9.8PoC≤ 4.3.16v5.0+8 more2016-01-15
CVE-2016-1909 [CRITICAL] CWE-264 CVE-2016-1909: Fortinet FortiAnalyzer before 5.0.12 and 5.2.x before 5.2.5; FortiSwitch 3.3.x before 3.3.3; FortiCa Fortinet FortiAnalyzer before 5.0.12 and 5.2.x before 5.2.5; FortiSwitch 3.3.x before 3.3.3; FortiCache 3.0.x before 3.0.8; and FortiOS 4.1.x before 4.1.11, 4.2.x before 4.2.16, 4.3.x before 4.3.17 and 5.0.x before 5.0.8 have a hardcoded passphrase for the Fortimanager_Access account, which allows remote attackers to obtain administrative access via
nvd
CVE-2015-7361CRITICALCVSS 9.3v5.2.32015-10-15
CVE-2015-7361 [CRITICAL] CWE-287 CVE-2015-7361: FortiOS 5.2.3, when configured to use High Availability (HA) and the dedicated management interface FortiOS 5.2.3, when configured to use High Availability (HA) and the dedicated management interface is enabled, does not require authentication for access to the ZebOS shell on the HA dedicated management interface, which allows remote attackers to obtain shell access via unspecified vectors.
nvd
CVE-2015-5965MEDIUMCVSS 5.0≤ 4.3.122015-08-11
CVE-2015-5965 [MEDIUM] CWE-20 CVE-2015-5965: The SSL-VPN feature in Fortinet FortiOS before 4.3.13 only checks the first byte of the TLS MAC in f The SSL-VPN feature in Fortinet FortiOS before 4.3.13 only checks the first byte of the TLS MAC in finished messages, which makes it easier for remote attackers to spoof encrypted content via a crafted MAC field.
nvd
CVE-2015-2323MEDIUMCVSS 6.4v5.0.0v5.0.1+14 more2015-08-11
CVE-2015-2323 [MEDIUM] CWE-310 CVE-2015-2323: FortiOS 5.0.x before 5.0.12 and 5.2.x before 5.2.4 supports anonymous, export, RC4, and possibly oth FortiOS 5.0.x before 5.0.12 and 5.2.x before 5.2.4 supports anonymous, export, RC4, and possibly other weak ciphers when using TLS to connect to FortiGuard servers, which allows man-in-the-middle attackers to spoof TLS content by modifying packets.
nvd
CVE-2015-3626MEDIUMCVSS 4.3≤ 5.2.32015-08-11
CVE-2015-3626 [MEDIUM] CWE-79 CVE-2015-3626: Cross-site scripting (XSS) vulnerability in the DHCP Monitor page in the Web User Interface (WebUI) Cross-site scripting (XSS) vulnerability in the DHCP Monitor page in the Web User Interface (WebUI) in Fortinet FortiOS before 5.2.4 on FortiGate devices allows remote attackers to inject arbitrary web script or HTML via a crafted hostname.
nvd
CVE-2014-8616MEDIUMCVSS 4.3v5.2.0v5.2.1+1 more2015-05-12
CVE-2014-8616 [MEDIUM] CWE-79 CVE-2014-8616: Multiple cross-site scripting (XSS) vulnerabilities in Fortinet FortiOS 5.2.x before 5.2.3 allow rem Multiple cross-site scripting (XSS) vulnerabilities in Fortinet FortiOS 5.2.x before 5.2.3 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors to the (1) user group or (2) vpn template menus.
nvd
CVE-2015-1880MEDIUMCVSS 4.3PoCv5.2.0v5.2.1+1 more2015-05-12
CVE-2015-1880 [MEDIUM] CWE-79 CVE-2015-1880: Cross-site scripting (XSS) vulnerability in the sslvpn login page in Fortinet FortiOS 5.2.x before 5 Cross-site scripting (XSS) vulnerability in the sslvpn login page in Fortinet FortiOS 5.2.x before 5.2.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2015-1571MEDIUMCVSS 4.3v5.0.72015-02-10
CVE-2015-1571 [MEDIUM] CWE-310 CVE-2015-1571: The CAPWAP DTLS protocol implementation in Fortinet FortiOS 5.0 Patch 7 build 4457 uses the same cer The CAPWAP DTLS protocol implementation in Fortinet FortiOS 5.0 Patch 7 build 4457 uses the same certificate and private key across different customers' installations, which makes it easier for man-in-the-middle attackers to spoof SSL servers by leveraging the Fortinet_Factory certificate and private key. NOTE: FG-IR-15-002 says "The Fortinet_Factory
nvd
CVE-2015-1452HIGHCVSS 7.8v5.0.72015-02-02
CVE-2015-1452 [HIGH] CWE-17 CVE-2015-1452: The Control and Provisioning of Wireless Access Points (CAPWAP) daemon in Fortinet FortiOS 5.0 Patch The Control and Provisioning of Wireless Access Points (CAPWAP) daemon in Fortinet FortiOS 5.0 Patch 7 build 4457 allows remote attackers to cause a denial of service (locked CAPWAP Access Controller) via a large number of ClientHello DTLS messages.
nvd
CVE-2015-1451LOWCVSS 3.5v5.0.72015-02-02
CVE-2015-1451 [LOW] CWE-79 CVE-2015-1451: Multiple cross-site scripting (XSS) vulnerabilities in Fortinet FortiOS 5.0 Patch 7 build 4457 allow Multiple cross-site scripting (XSS) vulnerabilities in Fortinet FortiOS 5.0 Patch 7 build 4457 allow remote authenticated users to inject arbitrary web script or HTML via the (1) WTP Name or (2) WTP Active Software Version field in a CAPWAP Join request.
nvd