Fortinet Fortios vulnerabilities
268 known vulnerabilities affecting fortinet/fortios.
Total CVEs
268
CISA KEV
18
actively exploited
Public exploits
19
Exploited in wild
13
Severity breakdown
CRITICAL25HIGH84MEDIUM149LOW10
Vulnerabilities
Page 14 of 14
CVE-2014-0351MEDIUMCVSS 5.4≤ 4.3.15v4.3.10+9 more2014-09-10
CVE-2014-0351 [MEDIUM] CWE-310 CVE-2014-0351: The FortiManager protocol service in Fortinet FortiOS before 4.3.16 and 5.x before 5.0.8 on FortiGat
The FortiManager protocol service in Fortinet FortiOS before 4.3.16 and 5.x before 5.0.8 on FortiGate devices does not prevent use of anonymous ciphersuites, which makes it easier for man-in-the-middle attackers to obtain sensitive information or interfere with communications by modifying the client-server data stream.
nvd
CVE-2014-2216HIGHCVSS 7.5≤ 4.3.15v4.3.10+9 more2014-08-25
CVE-2014-2216 [HIGH] CVE-2014-2216: The FortiManager protocol service in Fortinet FortiOS before 4.3.16 and 5.0.0 before 5.0.8 on FortiG
The FortiManager protocol service in Fortinet FortiOS before 4.3.16 and 5.0.0 before 5.0.8 on FortiGate devices allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted request.
nvd
CVE-2013-7182MEDIUMCVSS 4.3v5.0.52014-02-04
CVE-2013-7182 [MEDIUM] CWE-79 CVE-2013-7182: Cross-site scripting (XSS) vulnerability in firewall/schedule/recurrdlg in Fortinet FortiOS 5.0.5 al
Cross-site scripting (XSS) vulnerability in firewall/schedule/recurrdlg in Fortinet FortiOS 5.0.5 allows remote attackers to inject arbitrary web script or HTML via the mkey parameter.
nvd
CVE-2013-1414MEDIUMCVSS 5.1PoC≤ 4.3.12v4.3.10+2 more2013-07-08
CVE-2013-1414 [MEDIUM] CWE-352 CVE-2013-1414: Multiple cross-site request forgery (CSRF) vulnerabilities in Fortinet FortiOS on FortiGate firewall
Multiple cross-site request forgery (CSRF) vulnerabilities in Fortinet FortiOS on FortiGate firewall devices before 4.3.13 and 5.x before 5.0.2 allow remote attackers to hijack the authentication of administrators for requests that modify (1) settings or (2) policies, or (3) restart the device via a rebootme action to system/maintenance/shutdown.
nvd
CVE-2013-4604MEDIUMCVSS 6.5≤ 5.0.2v5.0.12013-06-25
CVE-2013-4604 [MEDIUM] CWE-264 CVE-2013-4604: Fortinet FortiOS before 5.0.3 on FortiGate devices does not properly restrict Guest capabilities, wh
Fortinet FortiOS before 5.0.3 on FortiGate devices does not properly restrict Guest capabilities, which allows remote authenticated users to read, modify, or delete the records of arbitrary users by leveraging the Guest role.
nvd
CVE-2006-3222MEDIUMCVSS 5.0v2.5_0mr4v2.8_mr10+7 more2006-06-24
CVE-2006-3222 [MEDIUM] CVE-2006-3222: The FTP proxy module in Fortinet FortiOS (FortiGate) before 2.80 MR12 and 3.0 MR2 allows remote atta
The FTP proxy module in Fortinet FortiOS (FortiGate) before 2.80 MR12 and 3.0 MR2 allows remote attackers to bypass anti-virus scanning via the Enhanced Passive (EPSV) FTP mode.
nvd
CVE-2005-3057CRITICALCVSS 10.0≤ 2.8_mr10≤ 3_beta2005-12-31
CVE-2005-3057 [CRITICAL] CVE-2005-3057: The FTP component in FortiGate 2.8 running FortiOS 2.8MR10 and v3beta, and other versions before 3.0
The FTP component in FortiGate 2.8 running FortiOS 2.8MR10 and v3beta, and other versions before 3.0 MR1, allows remote attackers to bypass the Fortinet FTP anti-virus engine by sending a STOR command and uploading a file before the FTP server response has been sent, as demonstrated using LFTP.
nvd
CVE-2005-3058HIGHCVSS 7.5PoC≤ 2.8_mr10≤ 3_beta2005-12-31
CVE-2005-3058 [HIGH] CWE-264 CVE-2005-3058: Interpretation conflict in Fortinet FortiGate 2.8, running FortiOS 2.8MR10 and v3beta, allows remote
Interpretation conflict in Fortinet FortiGate 2.8, running FortiOS 2.8MR10 and v3beta, allows remote attackers to bypass the URL blocker via an (1) HTTP request terminated with a line feed (LF) and not carriage return line feed (CRLF) or (2) HTTP request with no Host field, which is still processed by most web servers without violating RFC2616.
nvd
← Previous14 / 14