Fortinet Fortios vulnerabilities
277 known vulnerabilities affecting fortinet/fortios.
Total CVEs
277
CISA KEV
19
actively exploited
Public exploits
24
Exploited in wild
25
Severity breakdown
CRITICAL25HIGH86MEDIUM156LOW10
Vulnerabilities
Page 8 of 14
CVE-2023-33305P3MEDIUMCVSS 6.5≥ 5.0.0, ≤ 5.0.14≥ 5.2.0, ≤ 5.2.15+7 more2023-06-13
CVE-2023-33305 [MEDIUM] CWE-835 CVE-2023-33305: A loop with unreachable exit condition ('infinite loop') in Fortinet FortiOS version 7.2.0 through 7
A loop with unreachable exit condition ('infinite loop') in Fortinet FortiOS version 7.2.0 through 7.2.4, FortiOS version 7.0.0 through 7.0.10, FortiOS 6.4 all versions, FortiOS 6.2 all versions, FortiOS 6.0 all versions, FortiProxy version 7.2.0 through 7.2.3, FortiProxy version 7.0.0 through 7.0.9, FortiProxy 2.0 all versions, FortiProxy 1.2 all v
nvd
CVE-2022-45861P3MEDIUMCVSS 6.5≥ 6.2.0, ≤ 6.2.13≥ 6.4.0, ≤ 6.4.11+2 more2023-03-07
CVE-2022-45861 [MEDIUM] CWE-824 CVE-2022-45861: An access of uninitialized pointer vulnerability [CWE-824] in the SSL VPN portal of Fortinet FortiOS
An access of uninitialized pointer vulnerability [CWE-824] in the SSL VPN portal of Fortinet FortiOS version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.9 and before 6.4.11 and FortiProxy version 7.2.0 through 7.2.1, version 7.0.0 through 7.0.7 and before 2.0.11 allows a remote authenticated attacker to crash the sslvpn daemon via an HTTP GET req
nvd
CVE-2025-24471P3MEDIUMCVSS 6.5≥ 7.4.0, < 7.4.8≥ 7.6.0, < 7.6.2+2 more2025-06-10
CVE-2025-24471 [MEDIUM] CWE-295 CVE-2025-24471: An Improper Certificate Validation vulnerability [CWE-295] in FortiOS version 7.6.1 and below, versi
An Improper Certificate Validation vulnerability [CWE-295] in FortiOS version 7.6.1 and below, version 7.4.7 and below may allow an EAP verified remote user to connect from FortiClient via revoked certificate.
nvd
CVE-2023-29179P4MEDIUMCVSS 6.5≥ 6.4.0, < 6.4.13≥ 7.0.0, < 7.0.12+4 more2024-02-22
CVE-2023-29179 [MEDIUM] CWE-476 CVE-2023-29179: A null pointer dereference in Fortinet FortiOS version 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.
A null pointer dereference in Fortinet FortiOS version 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through 6.4.12, Fortiproxy version 7.2.0 through 7.2.4, 7.0.0 through 7.0.10 allows attacker to denial of service via specially crafted HTTP requests.
nvd
CVE-2025-58325P4MEDIUMCVSS 6.7≥ 6.4.0, < 7.0.16≥ 7.2.0, < 7.2.11+6 more2025-10-14
CVE-2025-58325 [MEDIUM] CWE-684 CVE-2025-58325: An Incorrect Provision of Specified Functionality vulnerability [CWE-684] in FortiOS 7.6.0, 7.4.0 th
An Incorrect Provision of Specified Functionality vulnerability [CWE-684] in FortiOS 7.6.0, 7.4.0 through 7.4.5, 7.2.5 through 7.2.10, 7.0.0 through 7.0.15, 6.4 all versions may allow a local authenticated attacker to execute system commands via crafted CLI commands.
nvd
CVE-2023-36640P4MEDIUMCVSS 6.7≥ 6.0.0, ≤ 6.0.16≥ 6.2.0, ≤ 6.2.16+3 more2024-05-14
CVE-2023-36640 [MEDIUM] CWE-134 CVE-2023-36640: A use of externally-controlled format string vulnerability in Fortinet FortiOS 7.4.0, FortiOS 7.2.0
A use of externally-controlled format string vulnerability in Fortinet FortiOS 7.4.0, FortiOS 7.2.0 through 7.2.5, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiOS 6.2 all versions, FortiOS 6.0.0 through 6.0.16, FortiPAM 1.1.0, FortiPAM 1.0 all versions, FortiProxy 7.2.0 through 7.2.5, FortiProxy 7.0.0 through 7.0.11, FortiProxy 2.0 all ve
nvd
CVE-2023-26207P4MEDIUMCVSS 6.5≥ 7.2.0, ≤ 7.2.42023-06-13
CVE-2023-26207 [MEDIUM] CWE-532 CVE-2023-26207: An insertion of sensitive information into log file vulnerability in Fortinet FortiOS 7.2.0 through
An insertion of sensitive information into log file vulnerability in Fortinet FortiOS 7.2.0 through 7.2.4 and FortiProxy 7.0.0 through 7.0.10. 7.2.0 through 7.2.1 allows an attacker to read certain passwords in plain text.
nvd
CVE-2023-48784P4MEDIUMCVSS 6.7≥ 6.4.0, < 7.0.16≥ 7.2.0, < 7.2.8+5 more2024-04-09
CVE-2023-48784 [MEDIUM] CWE-134 CVE-2023-48784: A use of externally-controlled format string vulnerability [CWE-134] in FortiOS version 7.4.1 and be
A use of externally-controlled format string vulnerability [CWE-134] in FortiOS version 7.4.1 and below, version 7.2.7 and below, 7.0 all versions, 6.4 all versions command line interface may allow a local privileged attacker with super-admin profile and CLI access to execute arbitrary code or commands via specially crafted requests.
nvd
CVE-2023-29182P4MEDIUMCVSS 6.7≥ 6.2.0, < 7.0.4≥ 7.0.0, ≤ 7.0.3+2 more2023-08-17
CVE-2023-29182 [MEDIUM] CWE-121 CVE-2023-29182: A stack-based buffer overflow vulnerability [CWE-121] in Fortinet FortiOS before 7.0.3 allows a priv
A stack-based buffer overflow vulnerability [CWE-121] in Fortinet FortiOS before 7.0.3 allows a privileged attacker to execute arbitrary code via specially crafted CLI commands, provided the attacker were able to evade FortiOS stack protections.
nvd
CVE-2023-40721P4MEDIUMCVSS 6.7≥ 6.2.0, < 7.0.14≥ 7.2.0, < 7.2.7+5 more2025-02-11
CVE-2023-40721 [MEDIUM] CWE-134 CVE-2023-40721: A use of externally-controlled format string vulnerability [CWE-134] vulnerability in Fortinet allo
A use of externally-controlled format string vulnerability [CWE-134] vulnerability in Fortinet allows a privileged attacker to execute arbitrary code or commands via specially crafted requests.
nvd
CVE-2020-6648P4MEDIUMCVSS 6.5fixed in 6.0.12≥ 6.2.0, < 6.2.52020-10-21
CVE-2020-6648 [MEDIUM] CWE-312 CVE-2020-6648: A cleartext storage of sensitive information vulnerability in FortiOS command line interface in vers
A cleartext storage of sensitive information vulnerability in FortiOS command line interface in versions 6.2.4 and earlier and FortiProxy 2.0.0, 1.2.9 and earlier may allow an authenticated attacker to obtain sensitive information such as users passwords by connecting to FortiGate CLI and executing the "diag sys ha checksum show" command.
nvd
CVE-2019-5587P4MEDIUMCVSS 6.5fixed in 6.0.52019-06-04
CVE-2019-5587 [MEDIUM] CWE-345 CVE-2019-5587: Lack of root file system integrity checking in Fortinet FortiOS VM application images all versions b
Lack of root file system integrity checking in Fortinet FortiOS VM application images all versions below 6.0.5 may allow attacker to implant malicious programs into the installing image by reassembling the image through specific methods.
nvd
CVE-2024-54021P4MEDIUMCVSS 5.8≥ 7.2.0, < 7.2.9≥ 7.4.0, < 7.4.5+3 more2025-01-14
CVE-2024-54021 [MEDIUM] CWE-113 CVE-2024-54021: An Improper Neutralization of CRLF Sequences in HTTP Headers ('http response splitting') vulnerabili
An Improper Neutralization of CRLF Sequences in HTTP Headers ('http response splitting') vulnerability [CWE-113] in Fortinet FortiOS 7.2.0 through 7.6.0, FortiProxy 7.2.0 through 7.4.5 may allow a remote unauthenticated attacker to bypass the file filter via crafted HTTP headers.
nvd
CVE-2025-54821P4MEDIUMCVSS 6.0≥ 6.4.0, < 7.6.4≥ 7.6.0, ≤ 7.6.3+4 more2025-11-18
CVE-2025-54821 [MEDIUM] CWE-269 CVE-2025-54821: An Improper Privilege Management vulnerability [CWE-269] vulnerability in Fortinet FortiOS 7.6.0 thr
An Improper Privilege Management vulnerability [CWE-269] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.11, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiPAM 1.6.0, FortiPAM 1.5 all versions, FortiPAM 1.4 all versions, FortiPAM 1.3 all versions, FortiPAM 1.2 all versions, FortiPA
nvd
CVE-2023-42786P4MEDIUMCVSS 6.5≥ 6.0.0, < 7.2.6≥ 7.4.0, < 7.4.2+6 more2025-01-14
CVE-2023-42786 [MEDIUM] CWE-476 CVE-2023-42786: A null pointer dereference in FortiOS versions 7.4.0 through 7.4.1, 7.2.0 through 7.2.5, 7.0 all ver
A null pointer dereference in FortiOS versions 7.4.0 through 7.4.1, 7.2.0 through 7.2.5, 7.0 all versions, 6.4 all versions , 6.2 all versions and 6.0 all versions allows attacker to trigger a denial of service via a crafted http request.
nvd
CVE-2024-36504P4MEDIUMCVSS 6.5≥ 6.4.0, < 7.2.9≥ 7.4.0, < 7.4.5+4 more2025-01-14
CVE-2024-36504 [MEDIUM] CWE-125 CVE-2024-36504: An out-of-bounds read vulnerability [CWE-125] in FortiOS SSLVPN web portal versions 7.4.0 through 7.
An out-of-bounds read vulnerability [CWE-125] in FortiOS SSLVPN web portal versions 7.4.0 through 7.4.4, versions 7.2.0 through 7.2.8, 7.0 all verisons, and 6.4 all versions may allow an authenticated attacker to perform a denial of service on the SSLVPN web portal via a specially crafted URL.
nvd
CVE-2023-42785P4MEDIUMCVSS 6.5≥ 6.0.0, < 7.2.6≥ 7.4.0, < 7.4.2+6 more2025-01-14
CVE-2023-42785 [MEDIUM] CWE-476 CVE-2023-42785: A null pointer dereference in FortiOS versions 7.4.0 through 7.4.1, 7.2.0 through 7.2.5, 7.0 all ver
A null pointer dereference in FortiOS versions 7.4.0 through 7.4.1, 7.2.0 through 7.2.5, 7.0 all versions, 6.4 all versions , 6.2 all versions and 6.0 all versions allows attacker to trigger a denial of service via a crafted http request.
nvd
CVE-2024-46669P4MEDIUMCVSS 6.5≥ 7.2.0, < 7.4.5≥ 7.4.0, ≤ 7.4.4+1 more2025-01-14
CVE-2024-46669 [MEDIUM] CWE-190 CVE-2024-46669: An Integer Overflow or Wraparound vulnerability [CWE-190] in version 7.4.4 and below, version 7.2.10
An Integer Overflow or Wraparound vulnerability [CWE-190] in version 7.4.4 and below, version 7.2.10 and below; FortiSASE version 23.4.b FortiOS tenant IPsec IKE service may allow an authenticated attacker to crash the IPsec tunnel via crafted requests, resulting in potential denial of service.
nvd
CVE-2023-33307P4MEDIUMCVSS 6.5≥ 7.0.0, < 7.0.11≥ 7.2.0, < 7.2.5+2 more2023-06-16
CVE-2023-33307 [MEDIUM] CWE-476 CVE-2023-33307: A null pointer dereference in Fortinet FortiOS before 7.2.5 and before 7.0.11, FortiProxy before 7.2
A null pointer dereference in Fortinet FortiOS before 7.2.5 and before 7.0.11, FortiProxy before 7.2.3 and before 7.0.9 allows attacker to denial of sslvpn service via specifically crafted request in network parameter.
nvd
CVE-2024-26008P4MEDIUMCVSS 5.3≥ 6.2.0, < 7.2.8≥ 7.4.0, < 7.4.4+5 more2025-10-14
CVE-2024-26008 [MEDIUM] CWE-754 CVE-2024-26008: An improper check or handling of exceptional conditions vulnerability [CWE-703] in FortiOS version 7
An improper check or handling of exceptional conditions vulnerability [CWE-703] in FortiOS version 7.4.0 through 7.4.3 and before 7.2.7, FortiProxy version 7.4.0 through 7.4.3 and before 7.2.9, FortiPAM before 1.2.0 and FortiSwitchManager version 7.2.0 through 7.2.3 and version 7.0.0 through 7.0.3 fgfm daemon may allow an unauthenticated attacker to
nvd