Fortinet Fortios vulnerabilities
282 known vulnerabilities affecting fortinet/fortios.
Total CVEs
282
CISA KEV
20
actively exploited
Public exploits
25
Exploited in wild
27
Severity breakdown
CRITICAL25HIGH88MEDIUM158LOW11
Vulnerabilities
Page 6 of 15
CVE-2025-22258P3HIGHCVSS 7.2≥ 7.0.2, < 7.0.17≥ 7.2.0, < 7.2.11+6 more2025-10-14
CVE-2025-22258 [HIGH] CWE-122 CVE-2025-22258: A heap-based buffer overflow in Fortinet FortiSRA 1.5.0, 1.4.0 through 1.4.2, FortiPAM 1.5.0, 1.4.0
A heap-based buffer overflow in Fortinet FortiSRA 1.5.0, 1.4.0 through 1.4.2, FortiPAM 1.5.0, 1.4.0 through 1.4.2, 1.3.0 through 1.3.1, 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiProxy 7.6.0 through 7.6.1, 7.4.0 through 7.4.7, FortiOS 7.6.0 through 7.6.2, 7.4.0 through 7.4.6, 7.2.0 through 7.2.10, 7.0.2 through 7.0.16, FortiSwitchManager 7.2
nvd
CVE-2014-2216P3HIGHCVSS 7.5≤ 4.3.15v4.3.10+9 more2014-08-25
CVE-2014-2216 [HIGH] CVE-2014-2216: The FortiManager protocol service in Fortinet FortiOS before 4.3.16 and 5.0.0 before 5.0.8 on FortiG
The FortiManager protocol service in Fortinet FortiOS before 4.3.16 and 5.0.0 before 5.0.8 on FortiGate devices allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted request.
nvd
CVE-2019-15705P3HIGHCVSS 7.5≤ 6.0.6≥ 6.2.0, ≤ 6.2.12019-11-27
CVE-2019-15705 [HIGH] CWE-20 CVE-2019-15705: An Improper Input Validation vulnerability in the SSL VPN portal of FortiOS versions 6.2.1 and below
An Improper Input Validation vulnerability in the SSL VPN portal of FortiOS versions 6.2.1 and below, and 6.0.6 and below may allow an unauthenticated remote attacker to crash the SSL VPN service by sending a crafted POST request.
nvd
CVE-2024-26007P3HIGHCVSS 7.5v7.4.12024-05-14
CVE-2024-26007 [HIGH] CWE-703 CVE-2024-26007: An improper check or handling of exceptional conditions vulnerability [CWE-703] in Fortinet FortiOS
An improper check or handling of exceptional conditions vulnerability [CWE-703] in Fortinet FortiOS version 7.4.1 allows an unauthenticated attacker to provoke a denial of service on the administrative interface via crafted HTTP requests.
nvd
CVE-2023-37935P3HIGHCVSS 7.5≥ 7.0.0, ≤ 7.0.12≥ 7.2.0, ≤ 7.2.5+1 more2023-10-10
CVE-2023-37935 [HIGH] CWE-598 CVE-2023-37935: A use of GET request method with sensitive query strings vulnerability in Fortinet FortiOS 7.0.0 - 7
A use of GET request method with sensitive query strings vulnerability in Fortinet FortiOS 7.0.0 - 7.0.12, 7.2.0 - 7.2.5 and 7.4.0 allows an attacker to view plaintext passwords of remote services such as RDP or VNC, if the attacker is able to read the GET requests to those services.
nvd
CVE-2025-25253P3HIGHCVSS 7.5≥ 7.0.0, < 7.4.9≥ 7.6.0, < 7.6.3+4 more2025-10-14
CVE-2025-25253 [HIGH] CWE-297 CVE-2025-25253: An Improper Validation of Certificate with Host Mismatch vulnerability [CWE-297] in FortiProxy versi
An Improper Validation of Certificate with Host Mismatch vulnerability [CWE-297] in FortiProxy version 7.6.1 and below, version 7.4.8 and below, 7.2 all versions, 7.0 all versions and FortiOS version 7.6.2 and below, version 7.4.8 and below, 7.2 all versions, 7.0 all versions ZTNA proxy may allow an unauthenticated attacker in a man-in-the middle posi
nvd
CVE-2021-26103P3HIGHCVSS 8.8≥ 5.6.0, ≤ 5.6.14≥ 6.0.0, ≤ 6.0.13+3 more2021-12-08
CVE-2021-26103 [HIGH] CWE-345 CVE-2021-26103: An insufficient verification of data authenticity vulnerability (CWE-345) in the user interface of F
An insufficient verification of data authenticity vulnerability (CWE-345) in the user interface of FortiProxy verison 2.0.3 and below, 1.2.11 and below and FortiGate verison 7.0.0, 6.4.6 and below, 6.2.9 and below of SSL VPN portal may allow a remote, unauthenticated attacker to conduct a cross-site request forgery (CSRF) attack . Only SSL VPN in web
nvd
CVE-2022-30307P3HIGHCVSS 8.1≥ 6.4.0, < 6.4.10≥ 7.0.1, < 7.0.8+1 more2022-11-02
CVE-2022-30307 [HIGH] CVE-2022-30307: A key management error vulnerability [CWE-320] affecting the RSA SSH host key in FortiOS 7.2.0 and b
A key management error vulnerability [CWE-320] affecting the RSA SSH host key in FortiOS 7.2.0 and below, 7.0.6 and below, 6.4.9 and below may allow an unauthenticated attacker to perform a man in the middle attack.
nvd
CVE-2022-29055P3HIGHCVSS 7.5≥ 6.2.0, < 6.2.11≥ 6.4.0, < 6.4.10+2 more2022-10-18
CVE-2022-29055 [HIGH] CWE-824 CVE-2022-29055: A access of uninitialized pointer in Fortinet FortiOS version 7.2.0, 7.0.0 through 7.0.5, 6.4.0 thro
A access of uninitialized pointer in Fortinet FortiOS version 7.2.0, 7.0.0 through 7.0.5, 6.4.0 through 6.4.8, 6.2.0 through 6.2.10, 6.0.x, FortiProxy version 7.0.0 through 7.0.4, 2.0.0 through 2.0.9, 1.2.x allows a remote unauthenticated or authenticated attacker to crash the sslvpn daemon via an HTTP GET request.
nvd
CVE-2023-22639P3HIGHCVSS 7.8≥ 6.0.0, ≤ 6.0.17≥ 6.2.0, ≤ 6.2.15+3 more2023-06-13
CVE-2023-22639 [HIGH] CWE-787 CVE-2023-22639: A out-of-bounds write in Fortinet FortiOS version 7.2.0 through 7.2.3, FortiOS version 7.0.0 through
A out-of-bounds write in Fortinet FortiOS version 7.2.0 through 7.2.3, FortiOS version 7.0.0 through 7.0.10, FortiOS version 6.4.0 through 6.4.12, FortiOS all versions 6.2, FortiOS all versions 6.0, FortiProxy version 7.2.0 through 7.2.2, FortiProxy version 7.0.0 through 7.0.8, FortiProxy all versions 2.0, FortiProxy all versions 1.2, FortiProxy all v
nvd
CVE-2022-35842P3HIGHCVSS 7.5≥ 6.4.0, ≤ 6.4.9≥ 7.0.0, ≤ 7.0.6+1 more2022-11-02
CVE-2022-35842 [HIGH] CWE-200 CVE-2022-35842: An exposure of sensitive information to an unauthorized actor vulnerabiltiy [CWE-200] in FortiOS SSL
An exposure of sensitive information to an unauthorized actor vulnerabiltiy [CWE-200] in FortiOS SSL-VPN versions 7.2.0, versions 7.0.0 through 7.0.6 and versions 6.4.0 through 6.4.9 may allow a remote unauthenticated attacker to gain information about LDAP and SAML settings configured in FortiOS.
nvd
CVE-2025-22254P3HIGHCVSS 7.2≥ 6.4.0, < 6.4.16≥ 7.0.0, < 7.0.17+8 more2025-06-10
CVE-2025-22254 [HIGH] CWE-269 CVE-2025-22254: An Improper Privilege Management vulnerability [CWE-269] vulnerability in Fortinet FortiOS 7.6.0 thr
An Improper Privilege Management vulnerability [CWE-269] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1, FortiOS 7.4.0 through 7.4.6, FortiOS 7.2.0 through 7.2.10, FortiOS 7.0.0 through 7.0.16, FortiOS 6.4.0 through 6.4.15, FortiProxy 7.6.0 through 7.6.1, FortiProxy 7.4.0 through 7.4.7, FortiWeb 7.6.0 through 7.6.1, FortiWeb 7.4.0 through 7.4.6
nvd
CVE-2025-61624P3MEDIUMCVSS 6.5≥ 6.4.0, < 7.4.10≥ 7.6.0, < 7.6.5+5 more2026-04-14
CVE-2025-61624 [MEDIUM] CWE-22 CVE-2025-61624: An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') [CWE-22] vulnerabi
An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') [CWE-22] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, FortiOS 7.4.0 through 7.4.9, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiPAM 1.7.0, FortiPAM 1.6 all versions, FortiPAM 1.5 all versions, FortiPAM 1.4 all versions, Fo
nvd
CVE-2023-29180P3HIGHCVSS 7.5≥ 6.0.0, < 6.0.17≥ 6.2.0, < 6.2.15+8 more2024-02-22
CVE-2023-29180 [HIGH] CWE-476 CVE-2023-29180: A null pointer dereference in Fortinet FortiOS version 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.
A null pointer dereference in Fortinet FortiOS version 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through 6.4.12, 6.2.0 through 6.2.14, 6.0.0 through 6.0.16, FortiProxy 7.2.0 through 7.2.3, 7.0.0 through 7.0.10, 2.0.0 through 2.0.12, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6, 1.0.0 through 1.0.7 allows attacker to denial of service via specially
nvd
CVE-2021-26108P3HIGHCVSS 7.5≥ 5.6.0, ≤ 5.6.13≥ 6.0.0, ≤ 6.0.12+3 more2021-12-08
CVE-2021-26108 [HIGH] CWE-798 CVE-2021-26108: A use of hard-coded cryptographic key vulnerability in the SSLVPN of FortiOS before 7.0.1 may allow
A use of hard-coded cryptographic key vulnerability in the SSLVPN of FortiOS before 7.0.1 may allow an attacker to retrieve the key by reverse engineering.
nvd
CVE-2022-43953P3HIGHCVSS 7.8≥ 6.2.0, ≤ 6.2.15≥ 6.4.0, ≤ 6.4.12+2 more2023-06-13
CVE-2022-43953 [HIGH] CWE-134 CVE-2022-43953: A use of externally-controlled format string in Fortinet FortiOS version 7.2.0 through 7.2.4, FortiO
A use of externally-controlled format string in Fortinet FortiOS version 7.2.0 through 7.2.4, FortiOS all versions 7.0, FortiOS all versions 6.4, FortiOS all versions 6.2, FortiProxy version 7.2.0 through 7.2.1, FortiProxy version 7.0.0 through 7.0.7 allows attacker to execute unauthorized code or commands via specially crafted commands.
nvd
CVE-2024-40591P3HIGHCVSS 7.2≥ 6.4.0, < 6.4.16≥ 7.0.0, < 7.0.16+7 more2025-02-11
CVE-2024-40591 [HIGH] CWE-266 CVE-2024-40591: An incorrect privilege assignment vulnerability [CWE-266] in Fortinet FortiOS version 7.6.0, 7.4.0 t
An incorrect privilege assignment vulnerability [CWE-266] in Fortinet FortiOS version 7.6.0, 7.4.0 through 7.4.4, 7.2.0 through 7.2.9 and before 7.0.15 allows an authenticated admin whose access profile has the Security Fabric permission to escalate their privileges to super-admin by connecting the targetted FortiGate to a malicious upstream FortiGate
nvd
CVE-2019-15703P3HIGHCVSS 7.5≤ 5.6.9≥ 6.0.0, < 6.0.9+1 more2019-10-24
CVE-2019-15703 [HIGH] CWE-331 CVE-2019-15703: An Insufficient Entropy in PRNG vulnerability in Fortinet FortiOS 6.2.1, 6.2.0, 6.0.8 and below for
An Insufficient Entropy in PRNG vulnerability in Fortinet FortiOS 6.2.1, 6.2.0, 6.0.8 and below for device not enable hardware TRNG token and models not support builtin TRNG seed allows attacker to theoretically recover the long term ECDSA secret in a TLS client with a RSA handshake and mutual ECDSA authentication via the help of flush+reload side chan
nvd
CVE-2024-23662P3HIGHCVSS 7.5≥ 6.4.0, < 7.2.6≥ 7.4.0, < 7.4.2+4 more2024-04-09
CVE-2024-23662 [HIGH] CWE-200 CVE-2024-23662: An exposure of sensitive information to an unauthorized actor in Fortinet FortiOS at least version a
An exposure of sensitive information to an unauthorized actor in Fortinet FortiOS at least version at least 7.4.0 through 7.4.1 and 7.2.0 through 7.2.5 and 7.0.0 through 7.0.15 and 6.4.0 through 6.4.15 allows attacker to information disclosure via HTTP requests.
nvd
CVE-2018-9185P3HIGHCVSS 8.1≤ 6.0.02018-07-05
CVE-2018-9185 [HIGH] CWE-200 CVE-2018-9185: An information disclosure vulnerability in Fortinet FortiOS 6.0.0 and below versions reveals user's
An information disclosure vulnerability in Fortinet FortiOS 6.0.0 and below versions reveals user's web portal login credentials in a Javascript file sent to client-side when pages bookmarked in web portal use the Single Sign-On feature.
nvd