cbcvebase.

Fortinet Fortios vulnerabilities

277 known vulnerabilities affecting fortinet/fortios.

Total CVEs
277
CISA KEV
19
actively exploited
Public exploits
24
Exploited in wild
25
Severity breakdown
CRITICAL25HIGH86MEDIUM156LOW10

Vulnerabilities

Page 14 of 14
CVE-2021-43206P4MEDIUMCVSS 4.3≥ 5.6.0, < 6.0.14≥ 6.2.0, < 6.2.10+2 more2022-05-04
CVE-2021-43206 [MEDIUM] CWE-209 CVE-2021-43206: A server-generated error message containing sensitive information in Fortinet FortiOS 7.0.0 through A server-generated error message containing sensitive information in Fortinet FortiOS 7.0.0 through 7.0.3, 6.4.0 through 6.4.8, 6.2.x, 6.0.x and FortiProxy 7.0.0 through 7.0.1, 2.0.x allows malicious webservers to retrieve a web proxy's client username and IP via same origin HTTP requests triggering proxy-generated HTTP status codes pages.
nvd
CVE-2024-32122P4MEDIUMCVSS 4.4≥ 6.4.0, ≤ 6.4.16≥ 7.0.0, ≤ 7.0.17+2 more2025-04-08
CVE-2024-32122 [MEDIUM] CWE-257 CVE-2024-32122: A storing passwords in a recoverable format in Fortinet FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all A storing passwords in a recoverable format in Fortinet FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions allows attacker to information disclosure via modification of LDAP server IP to point to a malicious server.
nvd
CVE-2021-42755P4MEDIUMCVSS 4.3v5.4.0v5.4.1+64 more2022-07-18
CVE-2021-42755 [MEDIUM] CWE-190 CVE-2021-42755: An integer overflow / wraparound vulnerability [CWE-190] in FortiSwitch 7.0.2 and below, 6.4.9 and b An integer overflow / wraparound vulnerability [CWE-190] in FortiSwitch 7.0.2 and below, 6.4.9 and below, 6.2.x, 6.0.x; FortiRecorder 6.4.2 and below, 6.0.10 and below; FortiOS 7.0.2 and below, 6.4.8 and below, 6.2.10 and below, 6.0.x; FortiProxy 7.0.0, 2.0.6 and below, 1.2.x, 1.1.x, 1.0.x; FortiVoiceEnterprise 6.4.3 and below, 6.0.10 and below dhcp
nvd
CVE-2022-22305P4MEDIUMCVSS 4.2≥ 5.6.10, ≤ 5.6.14≥ 6.0.0, ≤ 6.0.17+1 more2023-09-01
CVE-2022-22305 [MEDIUM] CWE-297 CVE-2022-22305: An improper certificate validation vulnerability [CWE-295] in FortiManager 7.0.1 and below, 6.4.6 an An improper certificate validation vulnerability [CWE-295] in FortiManager 7.0.1 and below, 6.4.6 and below; FortiAnalyzer 7.0.2 and below, 6.4.7 and below; FortiOS 6.2.x and 6.0.x; FortiSandbox 4.0.x, 3.2.x and 3.1.x may allow a network adjacent and unauthenticated attacker to man-in-the-middle the communication between the listed products and some
nvd
CVE-2017-3128P4MEDIUMCVSS 4.8v5.0.0v5.0.1+24 more2017-05-23
CVE-2017-3128 [MEDIUM] CWE-79 CVE-2017-3128: A stored XSS (Cross-Site-Scripting) vulnerability in Fortinet FortiOS allows attackers to execute un A stored XSS (Cross-Site-Scripting) vulnerability in Fortinet FortiOS allows attackers to execute unauthorized code or commands via the policy global-label parameter.
nvd
CVE-2015-3626P4MEDIUMCVSS 4.3≤ 5.2.32015-08-11
CVE-2015-3626 [MEDIUM] CWE-79 CVE-2015-3626: Cross-site scripting (XSS) vulnerability in the DHCP Monitor page in the Web User Interface (WebUI) Cross-site scripting (XSS) vulnerability in the DHCP Monitor page in the Web User Interface (WebUI) in Fortinet FortiOS before 5.2.4 on FortiGate devices allows remote attackers to inject arbitrary web script or HTML via a crafted hostname.
nvd
CVE-2015-1571P4MEDIUMCVSS 4.3v5.0.72015-02-10
CVE-2015-1571 [MEDIUM] CWE-310 CVE-2015-1571: The CAPWAP DTLS protocol implementation in Fortinet FortiOS 5.0 Patch 7 build 4457 uses the same cer The CAPWAP DTLS protocol implementation in Fortinet FortiOS 5.0 Patch 7 build 4457 uses the same certificate and private key across different customers' installations, which makes it easier for man-in-the-middle attackers to spoof SSL servers by leveraging the Fortinet_Factory certificate and private key. NOTE: FG-IR-15-002 says "The Fortinet_Factory
nvd
CVE-2022-41327P4MEDIUMCVSS 4.4≥ 7.0.0, ≤ 7.0.8≥ 7.2.0, ≤ 7.2.42023-06-13
CVE-2022-41327 [MEDIUM] CWE-319 CVE-2022-41327: A cleartext transmission of sensitive information vulnerability [CWE-319] in Fortinet FortiOS versio A cleartext transmission of sensitive information vulnerability [CWE-319] in Fortinet FortiOS version 7.2.0 through 7.2.4, 7.0.0 through 7.0.8, FortiProxy version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.8 allows an authenticated attacker with readonly superadmin privileges to intercept traffic in order to obtain other adminstrators cookies via dia
nvd
CVE-2025-47295P4LOWCVSS 3.7≥ 6.4.0, < 7.0.15≥ 7.2.0, < 7.2.8+5 more2025-05-28
CVE-2025-47295 [LOW] CWE-126 CVE-2025-47295: A buffer over-read in Fortinet FortiOS versions 7.4.0 through 7.4.3, versions 7.2.0 through 7.2.7, a A buffer over-read in Fortinet FortiOS versions 7.4.0 through 7.4.3, versions 7.2.0 through 7.2.7, and versions 7.0.0 through 7.0.14 may allow a remote unauthenticated attacker to crash the FGFM daemon via a specially crafted request, under rare conditions that are outside of the attacker's control.
nvd
CVE-2024-46665P4LOWCVSS 3.7≥ 7.4.0, < 7.4.5v7.6.0+1 more2025-01-14
CVE-2024-46665 [LOW] CWE-201 CVE-2024-46665: An insertion of sensitive information into sent data vulnerability [CWE-201] in FortiOS 7.6.0, 7.4.0 An insertion of sensitive information into sent data vulnerability [CWE-201] in FortiOS 7.6.0, 7.4.0 through 7.4.4 may allow an attacker in a man-in-the-middle position to retrieve the RADIUS accounting server shared secret via intercepting accounting-requests.
nvd
CVE-2022-42474P4LOWCVSS 2.7≥ 6.2.0, ≤ 6.2.15≥ 6.4.0, ≤ 6.4.12+2 more2023-06-13
CVE-2022-42474 [LOW] CWE-23 CVE-2022-42474: A relative path traversal vulnerability [CWE-23] in Fortinet FortiOS version 7.2.0 through 7.2.3, ve A relative path traversal vulnerability [CWE-23] in Fortinet FortiOS version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.9 and before 6.4.12, FortiProxy version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.7, FortiSwitchManager version 7.2.0 through 7.2.1 and before 7.0.1 allows an privileged attacker to delete arbitrary directories from the filesystem
nvd
CVE-2015-1451P4LOWCVSS 3.5v5.0.72015-02-02
CVE-2015-1451 [LOW] CWE-79 CVE-2015-1451: Multiple cross-site scripting (XSS) vulnerabilities in Fortinet FortiOS 5.0 Patch 7 build 4457 allow Multiple cross-site scripting (XSS) vulnerabilities in Fortinet FortiOS 5.0 Patch 7 build 4457 allow remote authenticated users to inject arbitrary web script or HTML via the (1) WTP Name or (2) WTP Active Software Version field in a CAPWAP Join request.
nvd
CVE-2021-32600P4LOWCVSS 3.8≥ 5.6.0, ≤ 5.6.9≥ 6.0.0, ≤ 6.0.13+3 more2021-11-17
CVE-2021-32600 [LOW] CWE-200 CVE-2021-32600: An exposure of sensitive information to an unauthorized actor vulnerability in FortiOS CLI 7.0.0, 6. An exposure of sensitive information to an unauthorized actor vulnerability in FortiOS CLI 7.0.0, 6.4.0 through 6.4.6, 6.2.0 through 6.2.9, 6.0.x and 5.6.x may allow a local and authenticated user assigned to a specific VDOM to retrieve other VDOMs information such as the admin account list and the network interface list.
nvd
CVE-2022-29053P4LOWCVSS 3.3≥ 6.0.0, ≤ 6.0.14≥ 6.2.0, ≤ 6.2.11+3 more2022-09-06
CVE-2022-29053 [LOW] CVE-2022-29053: A missing cryptographic steps vulnerability [CWE-325] in the functions that encrypt the keytab files A missing cryptographic steps vulnerability [CWE-325] in the functions that encrypt the keytab files in FortiOS version 7.2.0, 7.0.0 through 7.0.5 and below 7.0.0 may allow an attacker in possession of the encrypted file to decipher it.
nvd
CVE-2022-29054P4LOWCVSS 3.3≥ 6.0.0, ≤ 6.0.16≥ 6.2.0, ≤ 6.2.12+4 more2023-02-16
CVE-2022-29054 [LOW] CWE-329 CVE-2022-29054: A missing cryptographic steps vulnerability [CWE-325] in the functions that encrypt the DHCP and DNS A missing cryptographic steps vulnerability [CWE-325] in the functions that encrypt the DHCP and DNS keys in Fortinet FortiOS version 7.2.0, 7.0.0 through 7.0.5, 6.4.0 through 6.4.9, 6.2.x and 6.0.x may allow an attacker in possession of the encrypted key to decipher it.
nvd
CVE-2022-22302P4LOWCVSS 3.3≥ 6.0.0, ≤ 6.0.13≥ 6.2.0, ≤ 6.2.9+3 more2023-07-11
CVE-2022-22302 [LOW] CWE-312 CVE-2022-22302: A clear text storage of sensitive information (CWE-312) vulnerability in both FortiGate version 6.4. A clear text storage of sensitive information (CWE-312) vulnerability in both FortiGate version 6.4.0 through 6.4.1, 6.2.0 through 6.2.9 and 6.0.0 through 6.0.13 and FortiAuthenticator version 5.5.0 and all versions of 6.1 and 6.0 may allow a local unauthorized party to retrieve the Fortinet private keys used to establish secure communication with both
nvd
CVE-2023-29184P4LOWCVSS 2.3≥ 6.2.0, ≤ 7.2.11≥ 7.2.0, ≤ 7.2.11+2 more2025-06-10
CVE-2023-29184 [LOW] CWE-459 CVE-2023-29184: An incomplete cleanup vulnerability [CWE-459] in FortiOS 7.2 all versions and before & FortiProxy v An incomplete cleanup vulnerability [CWE-459] in FortiOS 7.2 all versions and before & FortiProxy version 7.2.0 through 7.2.2 and before 7.0.8 allows a VDOM privileged attacker to add SSH key files on the system silently via crafted CLI requests.
nvd
Fortinet Fortios vulnerabilities | cvebase