cbcvebase.

Fortinet Fortios vulnerabilities

277 known vulnerabilities affecting fortinet/fortios.

Total CVEs
277
CISA KEV
19
actively exploited
Public exploits
24
Exploited in wild
25
Severity breakdown
CRITICAL25HIGH86MEDIUM156LOW10

Vulnerabilities

Page 6 of 14
CVE-2021-41024P3HIGHCVSS 7.5v7.0.0v7.0.12021-12-08
CVE-2021-41024 [HIGH] CWE-22 CVE-2021-41024: A relative path traversal [CWE-23] vulnerabiltiy in FortiOS versions 7.0.0 and 7.0.1 and FortiProxy A relative path traversal [CWE-23] vulnerabiltiy in FortiOS versions 7.0.0 and 7.0.1 and FortiProxy verison 7.0.0 may allow an unauthenticated, unauthorized attacker to inject path traversal character sequences to disclose sensitive information of the server via the GET request of the login page.
nvd
CVE-2024-26007P3HIGHCVSS 7.5v7.4.12024-05-14
CVE-2024-26007 [HIGH] CWE-703 CVE-2024-26007: An improper check or handling of exceptional conditions vulnerability [CWE-703] in Fortinet FortiOS An improper check or handling of exceptional conditions vulnerability [CWE-703] in Fortinet FortiOS version 7.4.1 allows an unauthenticated attacker to provoke a denial of service on the administrative interface via crafted HTTP requests.
nvd
CVE-2023-37935P3HIGHCVSS 7.5≥ 7.0.0, ≤ 7.0.12≥ 7.2.0, ≤ 7.2.5+1 more2023-10-10
CVE-2023-37935 [HIGH] CWE-598 CVE-2023-37935: A use of GET request method with sensitive query strings vulnerability in Fortinet FortiOS 7.0.0 - 7 A use of GET request method with sensitive query strings vulnerability in Fortinet FortiOS 7.0.0 - 7.0.12, 7.2.0 - 7.2.5 and 7.4.0 allows an attacker to view plaintext passwords of remote services such as RDP or VNC, if the attacker is able to read the GET requests to those services.
nvd
CVE-2022-35842P3HIGHCVSS 7.5≥ 6.4.0, ≤ 6.4.9≥ 7.0.0, ≤ 7.0.6+1 more2022-11-02
CVE-2022-35842 [HIGH] CWE-200 CVE-2022-35842: An exposure of sensitive information to an unauthorized actor vulnerabiltiy [CWE-200] in FortiOS SSL An exposure of sensitive information to an unauthorized actor vulnerabiltiy [CWE-200] in FortiOS SSL-VPN versions 7.2.0, versions 7.0.0 through 7.0.6 and versions 6.4.0 through 6.4.9 may allow a remote unauthenticated attacker to gain information about LDAP and SAML settings configured in FortiOS.
nvd
CVE-2025-61624P3MEDIUMCVSS 6.5≥ 6.4.0, < 7.4.10≥ 7.6.0, < 7.6.5+5 more2026-04-14
CVE-2025-61624 [MEDIUM] CWE-22 CVE-2025-61624: An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') [CWE-22] vulnerabi An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') [CWE-22] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, FortiOS 7.4.0 through 7.4.9, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiPAM 1.7.0, FortiPAM 1.6 all versions, FortiPAM 1.5 all versions, FortiPAM 1.4 all versions, Fo
nvd
CVE-2021-26103P3HIGHCVSS 8.8≥ 5.6.0, ≤ 5.6.14≥ 6.0.0, ≤ 6.0.13+3 more2021-12-08
CVE-2021-26103 [HIGH] CWE-345 CVE-2021-26103: An insufficient verification of data authenticity vulnerability (CWE-345) in the user interface of F An insufficient verification of data authenticity vulnerability (CWE-345) in the user interface of FortiProxy verison 2.0.3 and below, 1.2.11 and below and FortiGate verison 7.0.0, 6.4.6 and below, 6.2.9 and below of SSL VPN portal may allow a remote, unauthenticated attacker to conduct a cross-site request forgery (CSRF) attack . Only SSL VPN in web
nvd
CVE-2022-30307P3HIGHCVSS 8.1≥ 6.4.0, < 6.4.10≥ 7.0.1, < 7.0.8+1 more2022-11-02
CVE-2022-30307 [HIGH] CVE-2022-30307: A key management error vulnerability [CWE-320] affecting the RSA SSH host key in FortiOS 7.2.0 and b A key management error vulnerability [CWE-320] affecting the RSA SSH host key in FortiOS 7.2.0 and below, 7.0.6 and below, 6.4.9 and below may allow an unauthenticated attacker to perform a man in the middle attack.
nvd
CVE-2022-43953P3HIGHCVSS 7.8≥ 6.2.0, ≤ 6.2.15≥ 6.4.0, ≤ 6.4.12+2 more2023-06-13
CVE-2022-43953 [HIGH] CWE-134 CVE-2022-43953: A use of externally-controlled format string in Fortinet FortiOS version 7.2.0 through 7.2.4, FortiO A use of externally-controlled format string in Fortinet FortiOS version 7.2.0 through 7.2.4, FortiOS all versions 7.0, FortiOS all versions 6.4, FortiOS all versions 6.2, FortiProxy version 7.2.0 through 7.2.1, FortiProxy version 7.0.0 through 7.0.7 allows attacker to execute unauthorized code or commands via specially crafted commands.
nvd
CVE-2023-22639P3HIGHCVSS 7.8≥ 6.0.0, ≤ 6.0.17≥ 6.2.0, ≤ 6.2.15+3 more2023-06-13
CVE-2023-22639 [HIGH] CWE-787 CVE-2023-22639: A out-of-bounds write in Fortinet FortiOS version 7.2.0 through 7.2.3, FortiOS version 7.0.0 through A out-of-bounds write in Fortinet FortiOS version 7.2.0 through 7.2.3, FortiOS version 7.0.0 through 7.0.10, FortiOS version 6.4.0 through 6.4.12, FortiOS all versions 6.2, FortiOS all versions 6.0, FortiProxy version 7.2.0 through 7.2.2, FortiProxy version 7.0.0 through 7.0.8, FortiProxy all versions 2.0, FortiProxy all versions 1.2, FortiProxy all v
nvd
CVE-2022-29055P3HIGHCVSS 7.5≥ 6.2.0, < 6.2.11≥ 6.4.0, < 6.4.10+2 more2022-10-18
CVE-2022-29055 [HIGH] CWE-824 CVE-2022-29055: A access of uninitialized pointer in Fortinet FortiOS version 7.2.0, 7.0.0 through 7.0.5, 6.4.0 thro A access of uninitialized pointer in Fortinet FortiOS version 7.2.0, 7.0.0 through 7.0.5, 6.4.0 through 6.4.8, 6.2.0 through 6.2.10, 6.0.x, FortiProxy version 7.0.0 through 7.0.4, 2.0.0 through 2.0.9, 1.2.x allows a remote unauthenticated or authenticated attacker to crash the sslvpn daemon via an HTTP GET request.
nvd
CVE-2025-22254P3HIGHCVSS 7.2≥ 6.4.0, < 6.4.16≥ 7.0.0, < 7.0.17+8 more2025-06-10
CVE-2025-22254 [HIGH] CWE-269 CVE-2025-22254: An Improper Privilege Management vulnerability [CWE-269] vulnerability in Fortinet FortiOS 7.6.0 thr An Improper Privilege Management vulnerability [CWE-269] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1, FortiOS 7.4.0 through 7.4.6, FortiOS 7.2.0 through 7.2.10, FortiOS 7.0.0 through 7.0.16, FortiOS 6.4.0 through 6.4.15, FortiProxy 7.6.0 through 7.6.1, FortiProxy 7.4.0 through 7.4.7, FortiWeb 7.6.0 through 7.6.1, FortiWeb 7.4.0 through 7.4.6
nvd
CVE-2023-29180P3HIGHCVSS 7.5≥ 6.0.0, < 6.0.17≥ 6.2.0, < 6.2.15+8 more2024-02-22
CVE-2023-29180 [HIGH] CWE-476 CVE-2023-29180: A null pointer dereference in Fortinet FortiOS version 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6. A null pointer dereference in Fortinet FortiOS version 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through 6.4.12, 6.2.0 through 6.2.14, 6.0.0 through 6.0.16, FortiProxy 7.2.0 through 7.2.3, 7.0.0 through 7.0.10, 2.0.0 through 2.0.12, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6, 1.0.0 through 1.0.7 allows attacker to denial of service via specially
nvd
CVE-2021-26108P3HIGHCVSS 7.5≥ 5.6.0, ≤ 5.6.13≥ 6.0.0, ≤ 6.0.12+3 more2021-12-08
CVE-2021-26108 [HIGH] CWE-798 CVE-2021-26108: A use of hard-coded cryptographic key vulnerability in the SSLVPN of FortiOS before 7.0.1 may allow A use of hard-coded cryptographic key vulnerability in the SSLVPN of FortiOS before 7.0.1 may allow an attacker to retrieve the key by reverse engineering.
nvd
CVE-2024-40591P3HIGHCVSS 7.2≥ 6.4.0, < 6.4.16≥ 7.0.0, < 7.0.16+7 more2025-02-11
CVE-2024-40591 [HIGH] CWE-266 CVE-2024-40591: An incorrect privilege assignment vulnerability [CWE-266] in Fortinet FortiOS version 7.6.0, 7.4.0 t An incorrect privilege assignment vulnerability [CWE-266] in Fortinet FortiOS version 7.6.0, 7.4.0 through 7.4.4, 7.2.0 through 7.2.9 and before 7.0.15 allows an authenticated admin whose access profile has the Security Fabric permission to escalate their privileges to super-admin by connecting the targetted FortiGate to a malicious upstream FortiGate
nvd
CVE-2019-15703P3HIGHCVSS 7.5≤ 5.6.9≥ 6.0.0, < 6.0.9+1 more2019-10-24
CVE-2019-15703 [HIGH] CWE-331 CVE-2019-15703: An Insufficient Entropy in PRNG vulnerability in Fortinet FortiOS 6.2.1, 6.2.0, 6.0.8 and below for An Insufficient Entropy in PRNG vulnerability in Fortinet FortiOS 6.2.1, 6.2.0, 6.0.8 and below for device not enable hardware TRNG token and models not support builtin TRNG seed allows attacker to theoretically recover the long term ECDSA secret in a TLS client with a RSA handshake and mutual ECDSA authentication via the help of flush+reload side chan
nvd
CVE-2024-23662P3HIGHCVSS 7.5≥ 6.4.0, < 7.2.6≥ 7.4.0, < 7.4.2+4 more2024-04-09
CVE-2024-23662 [HIGH] CWE-200 CVE-2024-23662: An exposure of sensitive information to an unauthorized actor in Fortinet FortiOS at least version a An exposure of sensitive information to an unauthorized actor in Fortinet FortiOS at least version at least 7.4.0 through 7.4.1 and 7.2.0 through 7.2.5 and 7.0.0 through 7.0.15 and 6.4.0 through 6.4.15 allows attacker to information disclosure via HTTP requests.
nvd
CVE-2018-9185P3HIGHCVSS 8.1≤ 6.0.02018-07-05
CVE-2018-9185 [HIGH] CWE-200 CVE-2018-9185: An information disclosure vulnerability in Fortinet FortiOS 6.0.0 and below versions reveals user's An information disclosure vulnerability in Fortinet FortiOS 6.0.0 and below versions reveals user's web portal login credentials in a Javascript file sent to client-side when pages bookmarked in web portal use the Single Sign-On feature.
nvd
CVE-2021-26110P3HIGHCVSS 7.8≥ 5.6.0, ≤ 5.6.14≥ 6.0.0, ≤ 6.0.12+3 more2021-12-08
CVE-2021-26110 [HIGH] CVE-2021-26110: An improper access control vulnerability [CWE-284] in FortiOS autod daemon 7.0.0, 6.4.6 and below, 6 An improper access control vulnerability [CWE-284] in FortiOS autod daemon 7.0.0, 6.4.6 and below, 6.2.9 and below, 6.0.12 and below and FortiProxy 2.0.1 and below, 1.2.9 and below may allow an authenticated low-privileged attacker to escalate their privileges to super_admin via a specific crafted configuration of fabric automation CLI script and auto-script
nvd
CVE-2022-22299P3HIGHCVSS 7.8≥ 5.0.0, ≤ 5.0.14≥ 5.2.0, ≤ 5.2.15+6 more2022-08-05
CVE-2022-22299 [HIGH] CWE-134 CVE-2022-22299: A format string vulnerability [CWE-134] in the command line interpreter of FortiADC version 6.0.0 th A format string vulnerability [CWE-134] in the command line interpreter of FortiADC version 6.0.0 through 6.0.4, FortiADC version 6.1.0 through 6.1.5, FortiADC version 6.2.0 through 6.2.1, FortiProxy version 1.0.0 through 1.0.7, FortiProxy version 1.1.0 through 1.1.6, FortiProxy version 1.2.0 through 1.2.13, FortiProxy version 2.0.0 through 2.0.7, For
nvd
CVE-2005-3057P3CRITICALCVSS 10.0≤ 2.8_mr10≤ 3_beta2005-12-31
CVE-2005-3057 [CRITICAL] CVE-2005-3057: The FTP component in FortiGate 2.8 running FortiOS 2.8MR10 and v3beta, and other versions before 3.0 The FTP component in FortiGate 2.8 running FortiOS 2.8MR10 and v3beta, and other versions before 3.0 MR1, allows remote attackers to bypass the Fortinet FTP anti-virus engine by sending a STOR command and uploading a file before the FTP server response has been sent, as demonstrated using LFTP.
nvd
Fortinet Fortios vulnerabilities | cvebase