cbcvebase.

Fortinet Fortios vulnerabilities

277 known vulnerabilities affecting fortinet/fortios.

Total CVEs
277
CISA KEV
19
actively exploited
Public exploits
24
Exploited in wild
25
Severity breakdown
CRITICAL25HIGH86MEDIUM156LOW10

Vulnerabilities

Page 7 of 14
CVE-2018-13381P3HIGHCVSS 7.5≤ 5.2.14≥ 5.4.0, ≤ 5.4.12+2 more2019-06-04
CVE-2018-13381 [HIGH] CWE-119 CVE-2018-13381: A buffer overflow vulnerability in Fortinet FortiOS 6.0.0 through 6.0.4, 5.6.0 through 5.6.7, 5.4 an A buffer overflow vulnerability in Fortinet FortiOS 6.0.0 through 6.0.4, 5.6.0 through 5.6.7, 5.4 and earlier versions and FortiProxy 2.0.0, 1.2.8 and earlier versions under SSL VPN web portal allows a non-authenticated attacker to perform a Denial-of-service attack via special craft message payloads.
nvd
CVE-2019-17655P3HIGHCVSS 7.5fixed in 6.2.32020-06-16
CVE-2019-17655 [HIGH] CWE-312 CVE-2019-17655: A cleartext storage in a file or on disk (CWE-313) vulnerability in FortiOS SSL VPN 6.2.0 through 6. A cleartext storage in a file or on disk (CWE-313) vulnerability in FortiOS SSL VPN 6.2.0 through 6.2.2, 6.0.9 and earlier and FortiProxy 2.0.0, 1.2.9 and earlier may allow an attacker to retrieve a logged-in SSL VPN user's credentials should that attacker be able to read the session file stored on the targeted device's system.
nvd
CVE-2024-46670P3HIGHCVSS 7.5≥ 7.2.0, < 7.2.10≥ 7.4.0, < 7.4.5+3 more2025-01-14
CVE-2024-46670 [HIGH] CWE-125 CVE-2024-46670: An Out-of-bounds Read vulnerability [CWE-125] in FortiOS version 7.6.0, version 7.4.4 and below, ver An Out-of-bounds Read vulnerability [CWE-125] in FortiOS version 7.6.0, version 7.4.4 and below, version 7.2.9 and below and FortiSASE FortiOS tenant version 24.3.b IPsec IKE service may allow an unauthenticated remote attacker to trigger memory consumption leading to Denial of Service via crafted requests.
nvd
CVE-2024-47570P3MEDIUMCVSS 6.6≥ 7.0.4, ≤ 7.0.17≥ 7.2.0, < 7.2.8+3 more2025-12-09
CVE-2024-47570 [MEDIUM] CWE-532 CVE-2024-47570: An insertion of sensitive information into log file vulnerability [CWE-532] in FortiOS 7.4.0 through An insertion of sensitive information into log file vulnerability [CWE-532] in FortiOS 7.4.0 through 7.4.3, 7.2.0 through 7.2.7, 7.0 all versions; FortiProxy 7.4.0 through 7.4.3, 7.2.0 through 7.2.11; FortiPAM 1.4 all versions, 1.3 all versions, 1.2 all versions, 1.1 all versions, 1.0 all versions and FortiSRA 1.4 all versions may allow a read-only
nvd
CVE-2025-25252P3MEDIUMCVSS 6.5≥ 6.4.0, < 7.0.17≥ 7.2.0, < 7.2.11+7 more2025-10-14
CVE-2025-25252 [MEDIUM] CWE-613 CVE-2025-25252: An Insufficient Session Expiration vulnerability [CWE-613] in FortiOS SSL VPN 7.6.0 through 7.6.2, 7 An Insufficient Session Expiration vulnerability [CWE-613] in FortiOS SSL VPN 7.6.0 through 7.6.2, 7.4.0 through 7.4.6, 7.2.0 through 7.2.10, 7.0.0 through 7.0.16, 6.4 all versions may allow a remote attacker (e.g. a former admin whose account was removed and whose session was terminated) in possession of the SAML record of a user session to access
nvd
CVE-2022-38380P3MEDIUMCVSS 4.3≥ 7.0.0, ≤ 7.0.7v7.2.02022-11-02
CVE-2022-38380 [MEDIUM] CVE-2022-38380: An improper access control [CWE-284] vulnerability in FortiOS version 7.2.0 and versions 7.0.0 throu An improper access control [CWE-284] vulnerability in FortiOS version 7.2.0 and versions 7.0.0 through 7.0.7 may allow a remote authenticated read-only user to modify the interface settings via the API.
nvd
CVE-2018-13376P3HIGHCVSS 7.5≤ 5.2.12≥ 5.4.6, ≤ 5.4.7+1 more2018-11-27
CVE-2018-13376 [HIGH] CVE-2018-13376: An uninitialized memory buffer leak exists in Fortinet FortiOS 5.6.1 to 5.6.3, 5.4.6 to 5.4.7, 5.2 a An uninitialized memory buffer leak exists in Fortinet FortiOS 5.6.1 to 5.6.3, 5.4.6 to 5.4.7, 5.2 all versions under web proxy's disclaimer response web pages, potentially causing sensitive data to be displayed in the HTTP response.
nvd
CVE-2017-3130P3HIGHCVSS 7.5v5.0.0v5.0.1+30 more2017-08-10
CVE-2017-3130 [HIGH] CWE-200 CVE-2017-3130: An information disclosure vulnerability in Fortinet FortiOS 5.6.0, 5.4.4 and below versions allows a An information disclosure vulnerability in Fortinet FortiOS 5.6.0, 5.4.4 and below versions allows attacker to get FortiOS version info by inspecting FortiOS IKE VendorID packets.
nvd
CVE-2017-17544P3HIGHCVSS 7.2≤ 5.4.0≥ 5.6.0, ≤ 5.6.10+2 more2019-04-09
CVE-2017-17544 [HIGH] CWE-269 CVE-2017-17544: A privilege escalation vulnerability in Fortinet FortiOS 6.0.0 to 6.0.6, 5.6.0 to 5.6.10, 5.4 and be A privilege escalation vulnerability in Fortinet FortiOS 6.0.0 to 6.0.6, 5.6.0 to 5.6.10, 5.4 and below allows admin users to elevate their profile to super_admin via restoring modified configurations.
nvd
CVE-2020-15938P3HIGHCVSS 7.5≤ 6.2.5≥ 6.4.0, ≤ 6.4.22021-03-04
CVE-2020-15938 [HIGH] CVE-2020-15938: When traffic other than HTTP/S (eg: SSH traffic, etc...) traverses the FortiGate in version below 6. When traffic other than HTTP/S (eg: SSH traffic, etc...) traverses the FortiGate in version below 6.2.5 and below 6.4.2 on port 80/443, it is not redirected to the transparent proxy policy for processing, as it doesn't have a valid HTTP header.
nvd
CVE-2019-17656P3MEDIUMCVSS 6.5≤ 6.0.10≥ 6.2.0, ≤ 6.2.22021-04-12
CVE-2019-17656 [MEDIUM] CWE-787 CVE-2019-17656: A Stack-based Buffer Overflow vulnerability in the HTTPD daemon of FortiOS 6.0.10 and below, 6.2.2 a A Stack-based Buffer Overflow vulnerability in the HTTPD daemon of FortiOS 6.0.10 and below, 6.2.2 and below and FortiProxy 1.0.x, 1.1.x, 1.2.9 and below, 2.0.0 and below may allow an authenticated remote attacker to crash the service by sending a malformed PUT request to the server. Fortinet is not aware of any successful exploitation of this vulne
nvd
CVE-2025-22862P3MEDIUMCVSS 6.7≥ 7.0.6, < 7.2.12≥ 7.4.0, < 7.4.8+3 more2025-10-02
CVE-2025-22862 [MEDIUM] CWE-288 CVE-2025-22862: An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] in FortiOS 7.4.0 An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] in FortiOS 7.4.0 through 7.4.7, 7.2.0 through 7.2.11, 7.0.6 and above; and FortiProxy 7.6.0 through 7.6.2, 7.4.0 through 7.4.8, 7.2 all versions, 7.0.5 and above may allow an authenticated attacker to elevate their privileges via triggering a malicious Webhook action
nvd
CVE-2025-25248P3MEDIUMCVSS 6.5≥ 6.4.0, < 7.2.11≥ 7.4.0, < 7.4.8+6 more2025-08-12
CVE-2025-25248 [MEDIUM] CWE-190 CVE-2025-25248: An Integer Overflow or Wraparound vulnerability [CWE-190] in FortiOS version 7.6.2 and below, versio An Integer Overflow or Wraparound vulnerability [CWE-190] in FortiOS version 7.6.2 and below, version 7.4.7 and below, version 7.2.10 and below, 7.2 all versions, 6.4 all versions, FortiProxy version 7.6.2 and below, version 7.4.3 and below, 7.2 all versions, 7.0 all versions, 2.0 all versions and FortiPAM version 1.5.0, version 1.4.2 and below, 1.3
nvd
CVE-2024-50568P3MEDIUMCVSS 5.9≥ 6.4.2, < 7.2.9≥ 7.4.0, < 7.4.4+4 more2025-06-10
CVE-2024-50568 [MEDIUM] CWE-300 CVE-2024-50568: A channel accessible by non-endpoint vulnerability [CWE-300] in Fortinet FortiOS version 7.4.0 throu A channel accessible by non-endpoint vulnerability [CWE-300] in Fortinet FortiOS version 7.4.0 through 7.4.3, 7.2.0 through 7.2.7 and before 7.0.14 & FortiProxy version 7.4.0 through 7.4.3, 7.2.0 through 7.2.9 and before 7.0.16 allows an unauthenticated attacker with the knowledge of device specific data to spoof the identity of a downstream device
nvd
CVE-2022-42476P3HIGHCVSS 8.2≥ 6.2.0, ≤ 6.2.12≥ 6.4.0, ≤ 6.4.11+2 more2023-03-07
CVE-2022-42476 [HIGH] CWE-23 CVE-2022-42476: A relative path traversal vulnerability [CWE-23] in Fortinet FortiOS version 7.2.0 through 7.2.2, 7. A relative path traversal vulnerability [CWE-23] in Fortinet FortiOS version 7.2.0 through 7.2.2, 7.0.0 through 7.0.8 and before 6.4.11, FortiProxy version 7.2.0 through 7.2.2 and 7.0.0 through 7.0.8 allows privileged VDOM administrators to escalate their privileges to super admin of the box via crafted CLI requests.
nvd
CVE-2015-1452P3HIGHCVSS 7.8v5.0.72015-02-02
CVE-2015-1452 [HIGH] CWE-17 CVE-2015-1452: The Control and Provisioning of Wireless Access Points (CAPWAP) daemon in Fortinet FortiOS 5.0 Patch The Control and Provisioning of Wireless Access Points (CAPWAP) daemon in Fortinet FortiOS 5.0 Patch 7 build 4457 allows remote attackers to cause a denial of service (locked CAPWAP Access Controller) via a large number of ClientHello DTLS messages.
nvd
CVE-2025-55018P3MEDIUMCVSS 5.8≥ 6.4.3, ≤ 6.4.16≥ 7.0.0, < 7.4.10+4 more2026-02-10
CVE-2025-55018 [MEDIUM] CWE-444 CVE-2025-55018: An inconsistent interpretation of http requests ('http request smuggling') vulnerability in Fortinet An inconsistent interpretation of http requests ('http request smuggling') vulnerability in Fortinet FortiOS 7.6.0, FortiOS 7.4.0 through 7.4.9, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4.3 through 6.4.16 may allow an unauthenticated attacker to smuggle an unlogged http request through the firewall policies via a specially craft
nvd
CVE-2017-7738P3HIGHCVSS 7.2≤ 5.2≥ 5.4.0, ≤ 5.4.5+1 more2017-12-13
CVE-2017-7738 [HIGH] CWE-200 CVE-2017-7738: An Information Disclosure vulnerability in Fortinet FortiOS 5.6.0 to 5.6.2, 5.4.0 to 5.4.5, 5.2 and An Information Disclosure vulnerability in Fortinet FortiOS 5.6.0 to 5.6.2, 5.4.0 to 5.4.5, 5.2 and below versions allow an admin user with super_admin privileges to view the current SSL VPN web portal session info which may contains user credentials through the fnsysctl CLI command.
nvd
CVE-2021-24012P3HIGHCVSS 7.3≥ 6.4.0, < 6.4.52021-06-02
CVE-2021-24012 [HIGH] CWE-295 CVE-2021-24012: An improper following of a certificate's chain of trust vulnerability in FortiGate versions 6.4.0 to An improper following of a certificate's chain of trust vulnerability in FortiGate versions 6.4.0 to 6.4.4 may allow an LDAP user to connect to SSLVPN with any certificate that is signed by a trusted Certificate Authority.
nvd
CVE-2023-36641P3MEDIUMCVSS 6.5≥ 6.0.0, ≤ 6.0.17≥ 6.2.0, ≤ 6.2.15+4 more2023-11-14
CVE-2023-36641 [MEDIUM] CWE-197 CVE-2023-36641: A numeric truncation error in Fortinet FortiProxy version 7.2.0 through 7.2.4, FortiProxy version 7. A numeric truncation error in Fortinet FortiProxy version 7.2.0 through 7.2.4, FortiProxy version 7.0.0 through 7.0.10, FortiProxy 2.0 all versions, FortiProxy 1.2 all versions, FortiProxy 1.1, all versions, FortiProxy 1.0 all versions, FortiOS version 7.4.0, FortiOS version 7.2.0 through 7.2.5, FortiOS version 7.0.0 through 7.0.12, FortiOS 6.4 all
nvd
Fortinet Fortios vulnerabilities | cvebase