cbcvebase.

Fortinet Fortios vulnerabilities

277 known vulnerabilities affecting fortinet/fortios.

Total CVEs
277
CISA KEV
19
actively exploited
Public exploits
24
Exploited in wild
25
Severity breakdown
CRITICAL25HIGH86MEDIUM156LOW10

Vulnerabilities

Page 4 of 14
CVE-2018-1352P3CRITICALCVSS 9.8v5.6.02019-02-08
CVE-2018-1352 [CRITICAL] CWE-134 CVE-2018-1352: A format string vulnerability in Fortinet FortiOS 5.6.0 allows attacker to execute unauthorized code A format string vulnerability in Fortinet FortiOS 5.6.0 allows attacker to execute unauthorized code or commands via the SSH username variable.
nvd
CVE-2023-41841P3HIGHCVSS 8.8≥ 7.0.0, ≤ 7.0.11≥ 7.2.0, ≤ 7.2.42023-10-10
CVE-2023-41841 [HIGH] CWE-285 CVE-2023-41841: An improper authorization vulnerability in Fortinet FortiOS 7.0.0 - 7.0.11 and 7.2.0 - 7.2.4 allows An improper authorization vulnerability in Fortinet FortiOS 7.0.0 - 7.0.11 and 7.2.0 - 7.2.4 allows an attacker belonging to the prof-admin profile to perform elevated actions.
nvd
CVE-2023-41677P3HIGHCVSS 8.8≥ 6.0.0, < 6.2.16≥ 6.4.0, < 6.4.15+9 more2024-04-09
CVE-2023-41677 [HIGH] CWE-522 CVE-2023-41677: A insufficiently protected credentials in Fortinet FortiProxy 7.4.0, 7.2.0 through 7.2.6, 7.0.0 thro A insufficiently protected credentials in Fortinet FortiProxy 7.4.0, 7.2.0 through 7.2.6, 7.0.0 through 7.0.12, 2.0.0 through 2.0.13, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6, 1.0.0 through 1.0.7, Fortinet FortiOS 7.4.0 through 7.4.1, 7.2.0 through 7.2.6, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, 6.0.0 through 6.0.17 allows at
nvd
CVE-2023-42790P3HIGHCVSS 8.1≥ 6.2.0, ≤ 6.2.15≥ 6.4.0, ≤ 6.4.14+3 more2024-03-12
CVE-2023-42790 [HIGH] CWE-121 CVE-2023-42790: A stack-based buffer overflow vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2.0 t A stack-based buffer overflow vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2.0 through 7.2.5, FortiOS 7.0.0 through 7.0.12, FortiOS 6.4.0 through 6.4.14, FortiOS 6.2.0 through 6.2.15, FortiProxy 7.4.0, FortiProxy 7.2.0 through 7.2.6, FortiProxy 7.0.0 through 7.0.12, FortiProxy 2.0.0 through 2.0.13, FortiSASE 23.2.b allows attacker
nvd
CVE-2025-22252P3HIGHCVSS 7.2≥ 7.4.4, < 7.4.7v7.6.0+1 more2025-05-28
CVE-2025-22252 [HIGH] CWE-306 CVE-2025-22252: A missing authentication for critical function in Fortinet FortiProxy versions 7.6.0 through 7.6.1, A missing authentication for critical function in Fortinet FortiProxy versions 7.6.0 through 7.6.1, FortiSwitchManager version 7.2.5, and FortiOS versions 7.4.4 through 7.4.6 and version 7.6.0 may allow an attacker with knowledge of an existing admin account to access the device as a valid admin via an authentication bypass.
nvd
CVE-2023-44250P3HIGHCVSS 8.8v7.2.5v7.4.0+2 more2024-01-10
CVE-2023-44250 [HIGH] CWE-269 CVE-2023-44250: An improper privilege management vulnerability [CWE-269] in a Fortinet FortiOS HA cluster version 7. An improper privilege management vulnerability [CWE-269] in a Fortinet FortiOS HA cluster version 7.4.0 through 7.4.1 and 7.2.5 and in a FortiProxy HA cluster version 7.4.0 through 7.4.1 allows an authenticated attacker to perform elevated actions via crafted HTTP or HTTPS requests.
nvd
CVE-2020-12819P3HIGHCVSS 7.5fixed in 5.6.13≥ 6.0.0, < 6.0.11+6 more2024-12-19
CVE-2020-12819 [HIGH] CWE-122 CVE-2020-12819: A heap-based buffer overflow vulnerability in the processing of Link Control Protocol messages in Fo A heap-based buffer overflow vulnerability in the processing of Link Control Protocol messages in FortiGate versions 5.6.12, 6.0.10, 6.2.4 and 6.4.1 and earlier may allow a remote attacker with valid SSL VPN credentials to crash the SSL VPN daemon by sending a large LCP packet, when tunnel mode is enabled. Arbitrary code execution may be theoretically
nvd
CVE-2017-14186P4MEDIUMCVSS 5.4PoC≤ 5.0≤ 5.2.12+2 more2017-11-29
CVE-2017-14186 [MEDIUM] CWE-79 CVE-2017-14186: A Cross-site Scripting (XSS) vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.7, 5.4 a A Cross-site Scripting (XSS) vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.7, 5.4 and below versions under SSL VPN web portal allows a remote user to inject arbitrary web script or HTML in the context of the victim's browser via the login redir parameter. An URL Redirection attack may also be feasible by injecting an external URL via
nvd
CVE-2021-44171P3HIGHCVSS 8.0≥ 6.0.0, ≤ 6.0.14≥ 6.2.0, ≤ 6.2.10+2 more2022-10-10
CVE-2021-44171 [HIGH] CWE-78 CVE-2021-44171: A improper neutralization of special elements used in an os command ('os command injection') in Fort A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiOS version 6.0.0 through 6.0.14, FortiOS version 6.2.0 through 6.2.10, FortiOS version 6.4.0 through 6.4.8, FortiOS version 7.0.0 through 7.0.3 allows attacker to execute privileged commands on a linked FortiSwitch via diagnostic CLI commands.
nvd
CVE-2013-1414P4MEDIUMCVSS 5.1PoC≤ 4.3.12v4.3.10+2 more2013-07-08
CVE-2013-1414 [MEDIUM] CWE-352 CVE-2013-1414: Multiple cross-site request forgery (CSRF) vulnerabilities in Fortinet FortiOS on FortiGate firewall Multiple cross-site request forgery (CSRF) vulnerabilities in Fortinet FortiOS on FortiGate firewall devices before 4.3.13 and 5.x before 5.0.2 allow remote attackers to hijack the authentication of administrators for requests that modify (1) settings or (2) policies, or (3) restart the device via a rebootme action to system/maintenance/shutdown.
nvd
CVE-2024-50562P4MEDIUMCVSS 4.8PoC≥ 6.4.0, < 7.2.11≥ 7.4.0, < 7.4.8+6 more2025-06-10
CVE-2024-50562 [MEDIUM] CWE-613 CVE-2024-50562: An Insufficient Session Expiration vulnerability [CWE-613] in FortiOS SSL-VPN version 7.6.0, version An Insufficient Session Expiration vulnerability [CWE-613] in FortiOS SSL-VPN version 7.6.0, version 7.4.6 and below, version 7.2.10 and below, 7.0 all versions, 6.4 all versions may allow an attacker in possession of a cookie used to log in the SSL-VPN portal to log in again, although the session has expired or was logged out.
nvd
CVE-2015-1880P4MEDIUMCVSS 4.3PoCv5.2.0v5.2.1+1 more2015-05-12
CVE-2015-1880 [MEDIUM] CWE-79 CVE-2015-1880: Cross-site scripting (XSS) vulnerability in the sslvpn login page in Fortinet FortiOS 5.2.x before 5 Cross-site scripting (XSS) vulnerability in the sslvpn login page in Fortinet FortiOS 5.2.x before 5.2.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2023-46714P3HIGHCVSS 7.2≥ 7.2.1, ≤ 7.2.6v7.4.0+2 more2024-05-14
CVE-2023-46714 [HIGH] CWE-121 CVE-2023-46714: A stack-based buffer overflow [CWE-121] vulnerability in Fortinet FortiOS version 7.2.1 through 7.2. A stack-based buffer overflow [CWE-121] vulnerability in Fortinet FortiOS version 7.2.1 through 7.2.6 and version 7.4.0 through 7.4.1 allows a privileged attacker over the administrative interface to execute arbitrary code or commands via crafted HTTP or HTTPs requests.
nvd
CVE-2025-58413P3HIGHCVSS 7.5≥ 6.0.0, < 7.4.9≥ 7.6.0, < 7.6.4+7 more2025-11-18
CVE-2025-58413 [HIGH] CWE-121 CVE-2025-58413: A stack-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 t A stack-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiOS 6.2 all versions, FortiOS 6.0 all versions, FortiSASE 25.3.b allows attacker to execute unauthorized code or commands via specially crafted packets
nvd
CVE-2023-45584P3HIGHCVSS 7.2≥ 6.4.0, < 7.0.13≥ 7.2.0, < 7.2.6+4 more2025-08-12
CVE-2023-45584 [HIGH] CWE-415 CVE-2023-45584: A double free vulnerability [CWE-415] vulnerability in Fortinet FortiOS 7.4.0, FortiOS 7.2.0 through A double free vulnerability [CWE-415] vulnerability in Fortinet FortiOS 7.4.0, FortiOS 7.2.0 through 7.2.5, FortiOS 7.0.0 through 7.0.12, FortiOS 6.4 all versions, FortiPAM 1.1 all versions, FortiPAM 1.0 all versions, FortiProxy 7.4.0 through 7.4.1, FortiProxy 7.2.0 through 7.2.7, FortiProxy 7.0.0 through 7.0.13 allows a privileged attacker to execute
nvd
CVE-2024-50571P3HIGHCVSS 7.2≥ 6.2.0, < 6.4.16≥ 7.0.0, < 7.0.17+8 more2025-10-14
CVE-2024-50571 [HIGH] CWE-122 CVE-2024-50571: A heap-based buffer overflow vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.2, FortiAnaly A heap-based buffer overflow vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.2, FortiAnalyzer 7.4.0 through 7.4.5, FortiAnalyzer 7.2.0 through 7.2.9, FortiAnalyzer 7.0.0 through 7.0.13, FortiAnalyzer 6.4 all versions, FortiAnalyzer 6.2 all versions, FortiAnalyzer 6.0 all versions, FortiAnalyzer Cloud 7.4.1 through 7.4.5, FortiAnalyzer Cloud
nvd
CVE-2018-13371P3HIGHCVSS 8.8≤ 5.4.10≥ 5.6.0, ≤ 5.6.7+1 more2020-04-02
CVE-2018-13371 [HIGH] CWE-20 CVE-2018-13371: An external control of system vulnerability in FortiOS may allow an authenticated, regular user to c An external control of system vulnerability in FortiOS may allow an authenticated, regular user to change the routing settings of the device via connecting to the ZebOS component.
nvd
CVE-2025-64157P3HIGHCVSS 7.2≥ 7.0.0, < 7.4.10≥ 7.6.0, < 7.6.5+4 more2026-02-10
CVE-2025-64157 [HIGH] CWE-134 CVE-2025-64157: A use of externally-controlled format string vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, A use of externally-controlled format string vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, FortiOS 7.4.0 through 7.4.9, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0 all versions allows an authenticated admin to execute unauthorized code or commands via specifically crafted configuration.
nvd
CVE-2024-26013P3HIGHCVSS 7.5≥ 6.4.0, < 7.0.16≥ 7.2.0, < 7.2.9+6 more2025-04-08
CVE-2024-26013 [HIGH] CWE-923 CVE-2024-26013: A improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in For A improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in Fortinet FortiOS version 7.4.0 through 7.4.4, 7.2.0 through 7.2.8, 7.0.0 through 7.0.15, 6.4.0 through 6.4.15 and before 6.2.16, Fortinet FortiProxy version 7.4.0 through 7.4.2, 7.2.0 through 7.2.9 and before 7.0.15, Fortinet FortiManager version 7.4.0 thr
nvd
CVE-2024-52965P3HIGHCVSS 7.2≥ 7.0.1, < 7.0.17≥ 7.2.0, < 7.2.11+7 more2025-07-08
CVE-2024-52965 [HIGH] CWE-304 CVE-2024-52965: A missing critical step in authentication vulnerability [CWE-304] in Fortinet FortiOS version 7.6.0 A missing critical step in authentication vulnerability [CWE-304] in Fortinet FortiOS version 7.6.0 through 7.6.1, 7.4.0 through 7.4.5, 7.2.0 through 7.2.10, and before 7.0.16 & FortiProxy version 7.6.0 through 7.6.1, 7.4.0 through 7.4.8, 7.2.0 through 7.2.13 and before 7.0.20 allows an API-user using api-key + PKI user certificate authentication to lo
nvd
Fortinet Fortios vulnerabilities | cvebase