cbcvebase.

Fortinet Fortios vulnerabilities

277 known vulnerabilities affecting fortinet/fortios.

Total CVEs
277
CISA KEV
19
actively exploited
Public exploits
24
Exploited in wild
25
Severity breakdown
CRITICAL25HIGH86MEDIUM156LOW10

Vulnerabilities

Page 2 of 14
CVE-2022-41335P1HIGHCVSS 8.1Exploited≥ 6.2.0, ≤ 6.2.12≥ 6.4.0, ≤ 6.4.10+5 more2023-02-16
CVE-2022-41335 [HIGH] CWE-23 CVE-2022-41335: A relative path traversal vulnerability [CWE-23] in Fortinet FortiOS version 7.2.0 through 7.2.2, 7. A relative path traversal vulnerability [CWE-23] in Fortinet FortiOS version 7.2.0 through 7.2.2, 7.0.0 through 7.0.8 and before 6.4.10, FortiProxy version 7.2.0 through 7.2.1, 7.0.0 through 7.0.7 and before 2.0.10, FortiSwitchManager 7.2.0 and before 7.0.0 allows an authenticated attacker to read and write files on the underlying Linux system via craf
nvd
CVE-2025-24477P1MEDIUMCVSS 6.7Exploited≥ 7.2.4, < 7.2.12≥ 7.4.0, < 7.4.8+4 more2025-07-15
CVE-2025-24477 [MEDIUM] CWE-122 CVE-2025-24477: A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.2, FortiOS 7.4.0 th A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.2, FortiOS 7.4.0 through 7.4.7, FortiOS 7.2.4 through 7.2.12 allows an attacker to escalate its privileges via a specially crafted CLI command
nvd
CVE-2025-62631P1MEDIUMCVSS 5.6Exploited≥ 6.4.0, < 7.4.1v7.4.0+3 more2025-12-09
CVE-2025-62631 [MEDIUM] CWE-613 CVE-2025-62631: An insufficient session expiration vulnerability [CWE-613] vulnerability in Fortinet FortiOS 7.4.0, An insufficient session expiration vulnerability [CWE-613] vulnerability in Fortinet FortiOS 7.4.0, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions allows attacker to maintain access to network resources via an active SSLVPN session not terminated after a user's password change under particular conditions outside of the a
nvd
CVE-2024-21754P2MEDIUMCVSS 4.4Exploited≥ 6.4.0, ≤ 6.4.15≥ 7.0.0, ≤ 7.0.15+4 more2024-06-11
CVE-2024-21754 [MEDIUM] CWE-916 CVE-2024-21754: A use of password hash with insufficient computational effort vulnerability [CWE-916] affecting Fort A use of password hash with insufficient computational effort vulnerability [CWE-916] affecting FortiOS version 7.4.3 and below, 7.2 all versions, 7.0 all versions, 6.4 all versions and FortiProxy version 7.4.2 and below, 7.2 all versions, 7.0 all versions, 2.0 all versions may allow a privileged attacker with super-admin profile and CLI access to d
nvd
CVE-2016-1909P1CRITICALCVSS 9.8PoC≤ 4.3.16v5.0+8 more2016-01-15
CVE-2016-1909 [CRITICAL] CWE-264 CVE-2016-1909: Fortinet FortiAnalyzer before 5.0.12 and 5.2.x before 5.2.5; FortiSwitch 3.3.x before 3.3.3; FortiCa Fortinet FortiAnalyzer before 5.0.12 and 5.2.x before 5.2.5; FortiSwitch 3.3.x before 3.3.3; FortiCache 3.0.x before 3.0.8; and FortiOS 4.1.x before 4.1.11, 4.2.x before 4.2.16, 4.3.x before 4.3.17 and 5.0.x before 5.0.8 have a hardcoded passphrase for the Fortimanager_Access account, which allows remote attackers to obtain administrative access via
nvd
CVE-2026-25815P2LOWCVSS 3.2Exploited≤ 7.6.62026-02-05
CVE-2026-25815 [LOW] CWE-1394 CVE-2026-25815: Fortinet FortiOS through 7.6.6 allows attackers to decrypt LDAP credentials stored in device configu Fortinet FortiOS through 7.6.6 allows attackers to decrypt LDAP credentials stored in device configuration files, as exploited in the wild from 2025-12-16 through 2026 (by default, the encryption key is the same across all customers' installations). NOTE: the Supplier's position is that the instance of CWE-1394 is not a vulnerability because customers
nvd
CVE-2018-13380P3MEDIUMCVSS 6.1PoC≤ 5.2≥ 5.4.0, ≤ 5.4.12+2 more2019-06-04
CVE-2018-13380 [MEDIUM] CWE-79 CVE-2018-13380: A Cross-site Scripting (XSS) vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.7, 5.4.0 A Cross-site Scripting (XSS) vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.7, 5.4.0 to 5.4.12, 5.2 and below and Fortinet FortiProxy 2.0.0, 1.2.8 and below under SSL VPN web portal allows attacker to execute unauthorized malicious script code via the error or message handling parameters.
nvd
CVE-2023-25610P2CRITICALCVSS 9.8≥ 5.0.0, < 6.2.13≥ 6.4.0, < 6.4.12+11 more2025-03-24
CVE-2023-25610 [CRITICAL] CWE-124 CVE-2023-25610: A buffer underwrite ('buffer underflow') vulnerability in the administrative interface of Fortinet F A buffer underwrite ('buffer underflow') vulnerability in the administrative interface of Fortinet FortiOS version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.6, version 6.4.0 through 6.4.11 and version 6.2.12 and below, FortiProxy version 7.2.0 through 7.2.2, version 7.0.0 through 7.0.8, version 2.0.12 and below and FortiOS-6K7K version 7.0.5,
nvd
CVE-2024-48884P2CRITICALCVSS 9.1≥ 6.4.0, < 6.4.16≥ 7.0.0, < 7.0.16+7 more2025-01-14
CVE-2024-48884 [CRITICAL] CWE-22 CVE-2024-48884: A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fo A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiManager 7.6.0 through 7.6.1, FortiManager 7.4.1 through 7.4.3, FortiManager Cloud 7.4.1 through 7.4.3, FortiOS 7.6.0, FortiOS 7.4.0 through 7.4.4, FortiOS 7.2.0 through 7.2.9, FortiOS 7.0.0 through 7.0.15, FortiOS 6.4.0 through 6.4.15, Fo
nvd
CVE-2023-33308P2CRITICALCVSS 9.8≥ 7.0.0, ≤ 7.0.10≥ 7.2.0, ≤ 7.2.32023-07-26
CVE-2023-33308 [CRITICAL] CWE-121 CVE-2023-33308: A stack-based overflow vulnerability [CWE-124] in Fortinet FortiOS version 7.0.0 through 7.0.10 and A stack-based overflow vulnerability [CWE-124] in Fortinet FortiOS version 7.0.0 through 7.0.10 and 7.2.0 through 7.2.3 and FortiProxy version 7.0.0 through 7.0.9 and 7.2.0 through 7.2.2 allows a remote unauthenticated attacker to execute arbitrary code or command via crafted packets reaching proxy policies or firewall policies with proxy mode alon
nvd
CVE-2023-42789P2CRITICALCVSS 9.8≥ 6.2.0, ≤ 6.2.15≥ 6.4.0, ≤ 6.4.14+5 more2024-03-12
CVE-2023-42789 [CRITICAL] CWE-787 CVE-2023-42789: A out-of-bounds write vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2.0 through 7 A out-of-bounds write vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2.0 through 7.2.5, FortiOS 7.0.0 through 7.0.12, FortiOS 6.4.0 through 6.4.14, FortiOS 6.2.0 through 6.2.15, FortiProxy 7.4.0, FortiProxy 7.2.0 through 7.2.6, FortiProxy 7.0.0 through 7.0.12, FortiProxy 2.0.0 through 2.0.13, FortiSASE 23.2.b allows attacker to e
nvd
CVE-2022-35843P2CRITICALCVSS 9.8≥ 6.0.0, ≤ 6.0.15≥ 6.2.0, ≤ 6.2.12+6 more2022-12-06
CVE-2022-35843 [CRITICAL] CWE-284 CVE-2022-35843: An authentication bypass by assumed-immutable data vulnerability [CWE-302] in the FortiOS SSH login An authentication bypass by assumed-immutable data vulnerability [CWE-302] in the FortiOS SSH login component 7.2.0, 7.0.0 through 7.0.7, 6.4.0 through 6.4.9, 6.2 all versions, 6.0 all versions and FortiProxy SSH login component 7.0.0 through 7.0.5, 2.0.0 through 2.0.10, 1.2.0 all versions may allow a remote and unauthenticated attacker to login in
nvd
CVE-2017-3133P3MEDIUMCVSS 6.1PoC≤ 5.6.02017-09-12
CVE-2017-3133 [MEDIUM] CWE-79 CVE-2017-3133: A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.6.0 and earlier allows attackers A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.6.0 and earlier allows attackers to execute unauthorized code or commands via the Replacement Message HTML for SSL-VPN.
nvd
CVE-2017-3132P3MEDIUMCVSS 6.1PoC≤ 5.6.02017-09-12
CVE-2017-3132 [MEDIUM] CWE-79 CVE-2017-3132: A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.6.0 and earlier allows attackers A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.6.0 and earlier allows attackers to Execute unauthorized code or commands via the action input during the activation of a FortiToken.
nvd
CVE-2024-26011P2CRITICALCVSS 9.8≥ 6.0.0, < 7.0.15≥ 7.2.0, < 7.2.8+7 more2024-11-12
CVE-2024-26011 [CRITICAL] CWE-306 CVE-2024-26011: A missing authentication for critical function in Fortinet FortiManager version 7.4.0 through 7.4.2, A missing authentication for critical function in Fortinet FortiManager version 7.4.0 through 7.4.2, 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through 6.4.14, FortiPAM version 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiProxy version 7.4.0 through 7.4.2, 7.2.0 through 7.2.9, 7.0.0 through 7.0.17, 2.0.0 through 2.0.14, 1.2.0 throug
nvd
CVE-2021-26109P2CRITICALCVSS 9.8≥ 6.0.0, ≤ 6.0.12≥ 6.2.0, ≤ 6.2.9+2 more2021-12-08
CVE-2021-26109 [CRITICAL] CWE-190 CVE-2021-26109: An integer overflow or wraparound vulnerability in the memory allocator of SSLVPN in FortiOS before An integer overflow or wraparound vulnerability in the memory allocator of SSLVPN in FortiOS before 7.0.1 may allow an unauthenticated attacker to corrupt control data on the heap via specifically crafted requests to SSLVPN, resulting in potentially arbitrary code execution.
nvd
CVE-2023-46717P2HIGHCVSS 8.8≥ 7.0.0, < 7.0.13≥ 7.2.0, < 7.2.7+4 more2024-03-12
CVE-2023-46717 [HIGH] CWE-287 CVE-2023-46717: An improper authentication vulnerability [CWE-287] in FortiOS versions 7.4.1 and below, versions 7.2 An improper authentication vulnerability [CWE-287] in FortiOS versions 7.4.1 and below, versions 7.2.6 and below, and versions 7.0.12 and below when configured with FortiAuthenticator in HA may allow a readonly user to gain read-write access via successive login attempts.
nvd
CVE-2026-22153P2HIGHCVSS 8.1≥ 7.6.0, < 7.6.5≥ 7.6.0, ≤ 7.6.42026-02-10
CVE-2026-22153 [HIGH] CWE-305 CVE-2026-22153: An Authentication Bypass by Primary Weakness vulnerability [CWE-305] vulnerability in Fortinet Forti An Authentication Bypass by Primary Weakness vulnerability [CWE-305] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4 may allow an unauthenticated attacker to bypass LDAP authentication of Agentless VPN or FSSO policy, when the remote LDAP server is configured in a specific way.
nvd
CVE-2024-48886P2CRITICALCVSS 9.8≥ 6.4.0, < 7.0.16≥ 7.2.0, < 7.2.9+5 more2025-01-14
CVE-2024-48886 [CRITICAL] CWE-1390 CVE-2024-48886: A weak authentication in Fortinet FortiOS versions 7.4.0 through 7.4.4, 7.2.0 through 7.2.8, 7.0.0 t A weak authentication in Fortinet FortiOS versions 7.4.0 through 7.4.4, 7.2.0 through 7.2.8, 7.0.0 through 7.0.15, 6.4.0 through 6.4.15, FortiProxy versions 7.4.0 through 7.4.4, 7.2.0 through 7.2.10, 7.0.0 through 7.0.17, 2.0.0 through 2.0.14, FortiManager versions 7.6.0 through 7.6.1, 7.4.1 through 7.4.3, FortiManager Cloud versions 7.4.1 throug
nvd
CVE-2025-53844P3HIGHCVSS 8.8≥ 7.2.0, < 7.2.12≥ 7.4.0, < 7.4.9+8 more2026-05-12
CVE-2025-53844 [HIGH] CWE-787 CVE-2025-53844: A out-of-bounds write vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7 A out-of-bounds write vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11 allows attacker to execute unauthorized code or commands via specially crafted packets.
nvd
Fortinet Fortios vulnerabilities | cvebase