Fortinet Fortios vulnerabilities
277 known vulnerabilities affecting fortinet/fortios.
Total CVEs
277
CISA KEV
19
actively exploited
Public exploits
24
Exploited in wild
25
Severity breakdown
CRITICAL25HIGH86MEDIUM156LOW10
Vulnerabilities
Page 9 of 14
CVE-2024-55599P4MEDIUMCVSS 5.3≥ 6.4.0, < 7.2.11≥ 7.4.0, < 7.4.8+5 more2025-07-08
CVE-2024-55599 [MEDIUM] CWE-358 CVE-2024-55599: An Improperly Implemented Security Check for Standard vulnerability [CWE-358] in FortiOS version 7.6
An Improperly Implemented Security Check for Standard vulnerability [CWE-358] in FortiOS version 7.6.0, version 7.4.7 and below, 7.0 all versions, 6.4 all versions and FortiProxy version 7.6.1 and below, version 7.4.8 and below, 7.2 all versions, 7.0 all versions may allow a remote unauthenticated user to bypass the DNS filter via Apple devices.
nvd
CVE-2023-33306P4MEDIUMCVSS 6.5≥ 6.4.0, < 6.4.13≥ 7.0.0, < 7.0.11+4 more2023-06-16
CVE-2023-33306 [MEDIUM] CWE-476 CVE-2023-33306: A null pointer dereference in Fortinet FortiOS before 7.2.5, before 7.0.11 and before 6.4.13, Forti
A null pointer dereference in Fortinet FortiOS before 7.2.5, before 7.0.11 and before 6.4.13, FortiProxy before 7.2.4 and before 7.0.10 allows attacker to denial of sslvpn service via specifically crafted request in bookmark parameter.
nvd
CVE-2025-67862P4MEDIUMCVSS 6.7≥ 6.4.0, ≤ 6.4.16≥ 7.0.0, ≤ 7.0.16+6 more2026-06-09
CVE-2025-67862 [MEDIUM] CWE-1244 CVE-2025-67862: An Internal Asset Exposed to Unsafe Debug Access Level or State vulnerability [CWE-1244] vulnerabili
An Internal Asset Exposed to Unsafe Debug Access Level or State vulnerability [CWE-1244] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.2, FortiOS 7.4.0 through 7.4.7, FortiOS 7.2.0 through 7.2.10, FortiOS 7.0.0 through 7.0.16, FortiOS 6.4 all versions, FortiProxy 7.6.0 through 7.6.3, FortiProxy 7.4.0 through 7.4.10, FortiProxy 7.2.0 through 7
nvd
CVE-2022-23439P4MEDIUMCVSS 6.1≥ 6.0.0, < 7.0.6≥ 7.2.0, < 7.2.5+6 more2025-01-22
CVE-2022-23439 [MEDIUM] CWE-610 CVE-2022-23439: A externally controlled reference to a resource in another sphere vulnerability in Fortinet allows
A externally controlled reference to a resource in another sphere vulnerability in Fortinet allows attacker to poison web caches via crafted HTTP requests, where the `Host` header points to an arbitrary webserver
nvd
CVE-2025-47890P4MEDIUMCVSS 6.1≥ 6.4.0, < 7.4.9≥ 7.6.0, < 7.6.4+5 more2025-10-14
CVE-2025-47890 [MEDIUM] CWE-601 CVE-2025-47890: An URL Redirection to Untrusted Site vulnerabilities [CWE-601] vulnerability in Fortinet FortiOS 7.6
An URL Redirection to Untrusted Site vulnerabilities [CWE-601] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiProxy 7.6.0 through 7.6.3, FortiProxy 7.4 all versions, FortiProxy 7.2 all versions, FortiProxy 7.0 all versions, FortiSA
nvd
CVE-2024-46666P4MEDIUMCVSS 5.3≥ 6.4.0, < 7.2.9≥ 7.4.0, < 7.4.5+5 more2025-01-14
CVE-2024-46666 [MEDIUM] CWE-770 CVE-2024-46666: An allocation of resources without limits or throttling [CWE-770] vulnerability in FortiOS versions
An allocation of resources without limits or throttling [CWE-770] vulnerability in FortiOS versions 7.6.0, versions 7.4.4 through 7.4.0, 7.2 all versions, 7.0 all versions, 6.4 all versions may allow a remote unauthenticated attacker to prevent access to the GUI via specially crafted requests directed at specific endpoints.
nvd
CVE-2023-47536P4MEDIUMCVSS 5.3≥ 6.4.0, ≤ 6.4.14≥ 7.0.0, ≤ 7.0.13+1 more2023-12-13
CVE-2023-47536 [MEDIUM] CWE-284 CVE-2023-47536: An improper access control vulnerability [CWE-284] in FortiOS version 7.2.0, version 7.0.13 and belo
An improper access control vulnerability [CWE-284] in FortiOS version 7.2.0, version 7.0.13 and below, version 6.4.14 and below and FortiProxy version 7.2.3 and below, version 7.0.9 and below, version 2.0.12 and below may allow a remote unauthenticated attacker to bypass the firewall deny geolocalisation policy via timing the bypass with a GeoIP dat
nvd
CVE-2013-4604P4MEDIUMCVSS 6.5≤ 5.0.2v5.0.12013-06-25
CVE-2013-4604 [MEDIUM] CWE-264 CVE-2013-4604: Fortinet FortiOS before 5.0.3 on FortiGate devices does not properly restrict Guest capabilities, wh
Fortinet FortiOS before 5.0.3 on FortiGate devices does not properly restrict Guest capabilities, which allows remote authenticated users to read, modify, or delete the records of arbitrary users by leveraging the Guest role.
nvd
CVE-2021-44170P4MEDIUMCVSS 6.7≥ 6.0.0, ≤ 6.0.14≥ 6.2.0, < 6.2.11+2 more2022-07-18
CVE-2021-44170 [MEDIUM] CWE-787 CVE-2021-44170: A stack-based buffer overflow vulnerability [CWE-121] in the command line interpreter of FortiOS bef
A stack-based buffer overflow vulnerability [CWE-121] in the command line interpreter of FortiOS before 7.0.4 and FortiProxy before 2.0.8 may allow an authenticated attacker to execute unauthorized code or commands via specially crafted command line arguments.
nvd
CVE-2021-43072P4MEDIUMCVSS 6.7≥ 6.0.0, < 6.2.11≥ 6.4.0, < 6.4.9+1 more2023-07-18
CVE-2021-43072 [MEDIUM] CWE-120 CVE-2021-43072: A buffer copy without checking size of input ('classic buffer overflow') in Fortinet FortiAnalyzer v
A buffer copy without checking size of input ('classic buffer overflow') in Fortinet FortiAnalyzer version 7.0.2 and below, version 6.4.7 and below, version 6.2.9 and below, version 6.0.11 and below, version 5.6.11 and below, FortiManager version 7.0.2 and below, version 6.4.7 and below, version 6.2.9 and below, version 6.0.11 and below, version 5.6
nvd
CVE-2023-28002P4MEDIUMCVSS 6.7≥ 6.0.0, ≤ 6.0.17≥ 6.2.0, ≤ 6.2.15+3 more2023-11-14
CVE-2023-28002 [MEDIUM] CWE-354 CVE-2023-28002: An improper validation of integrity check value vulnerability [CWE-354] in FortiOS 7.2.0 through 7.2
An improper validation of integrity check value vulnerability [CWE-354] in FortiOS 7.2.0 through 7.2.3, 7.0.0 through 7.0.12, 6.4 all versions, 6.2 all versions, 6.0 all versions and VMs may allow a local attacker with admin privileges to boot a malicious image on the device and bypass the filesystem integrity check in place.
nvd
CVE-2018-9195P4MEDIUMCVSS 5.9≤ 6.0.6vFortiOS 6.0.7 and below2019-11-21
CVE-2018-9195 [MEDIUM] CWE-798 CVE-2018-9195: Use of a hardcoded cryptographic key in the FortiGuard services communication protocol may allow a M
Use of a hardcoded cryptographic key in the FortiGuard services communication protocol may allow a Man in the middle with knowledge of the key to eavesdrop on and modify information (URL/SPAM services in FortiOS 5.6, and URL/SPAM/AV services in FortiOS 6.0.; URL rating in FortiClient) sent and received from Fortiguard severs by decrypting these messag
nvd
CVE-2016-8492P4MEDIUMCVSS 5.9≤ 4.3.18v4.3.0+7 more2017-02-08
CVE-2016-8492 [MEDIUM] CWE-200 CVE-2016-8492: The implementation of an ANSI X9.31 RNG in Fortinet FortiGate allows attackers to gain unauthorized
The implementation of an ANSI X9.31 RNG in Fortinet FortiGate allows attackers to gain unauthorized read access to data handled by the device via IPSec/TLS decryption.
nvd
CVE-2025-31366P4MEDIUMCVSS 6.1≥ 6.4.0, < 7.4.9≥ 7.6.0, < 7.6.4+5 more2025-10-14
CVE-2025-31366 [MEDIUM] CWE-79 CVE-2025-31366: An Improper Neutralization of Input During Web Page Generation vulnerability [CWE-79] vulnerability
An Improper Neutralization of Input During Web Page Generation vulnerability [CWE-79] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiProxy 7.6.0 through 7.6.3, FortiProxy 7.4 all versions, FortiProxy 7.2 all versions, FortiProxy 7.0
nvd
CVE-2025-47294P4MEDIUMCVSS 5.3≥ 6.4.0, < 7.0.15≥ 7.2.0, < 7.2.8+3 more2025-05-28
CVE-2025-47294 [MEDIUM] CWE-190 CVE-2025-47294: A integer overflow or wraparound in Fortinet FortiOS versions 7.2.0 through 7.2.7, versions 7.0.0 th
A integer overflow or wraparound in Fortinet FortiOS versions 7.2.0 through 7.2.7, versions 7.0.0 through 7.0.14 may allow a remote unauthenticated attacker to crash the csfd daemon via a specially crafted request.
nvd
CVE-2025-22251P4MEDIUMCVSS 5.3≥ 6.4.0, < 7.4.6v7.6.0+4 more2025-06-10
CVE-2025-22251 [MEDIUM] CWE-923 CVE-2025-22251: An improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in Fo
An improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in FortiOS 7.6.0, 7.4.0 through 7.4.5, 7.2 all versions, 7.0 all versions, 6.4 all versions may allow an unauthenticated attacker to inject unauthorized sessions via crafted FGSP session synchronization packets.
nvd
CVE-2021-41019P4MEDIUMCVSS 6.5≥ 6.4.0, ≤ 6.4.62021-11-02
CVE-2021-41019 [MEDIUM] CWE-295 CVE-2021-41019: An improper validation of certificate with host mismatch [CWE-297] vulnerability in FortiOS versions
An improper validation of certificate with host mismatch [CWE-297] vulnerability in FortiOS versions 6.4.6 and below may allow the connection to a malicious LDAP server via options in GUI, leading to disclosure of sensitive information, such as AD credentials.
nvd
CVE-2024-52963P4MEDIUMCVSS 5.9≥ 6.4.0, < 7.2.11≥ 7.4.0, < 7.4.8+5 more2025-01-14
CVE-2024-52963 [MEDIUM] CWE-787 CVE-2024-52963: A out-of-bounds write in Fortinet FortiOS versions 7.6.0, 7.4.0 through 7.4.6, 7.2.0 through 7.2.10,
A out-of-bounds write in Fortinet FortiOS versions 7.6.0, 7.4.0 through 7.4.6, 7.2.0 through 7.2.10, 7.0.0 through 7.0.16, 6.4.0 through 6.4.15 allows attacker to trigger a denial of service via specially crafted packets.
nvd
CVE-2021-36169P4MEDIUMCVSS 6.0≥ 5.6.0, ≤ 5.6.14≥ 6.0.0, ≤ 6.0.14+3 more2021-12-13
CVE-2021-36169 [MEDIUM] CVE-2021-36169: A Hidden Functionality in Fortinet FortiOS 7.x before 7.0.1, FortiOS 6.4.x before 6.4.7 allows attac
A Hidden Functionality in Fortinet FortiOS 7.x before 7.0.1, FortiOS 6.4.x before 6.4.7 allows attacker to Execute unauthorized code or commands via specific hex read/write operations.
nvd
CVE-2023-41675P4MEDIUMCVSS 5.3≥ 7.0.0, ≤ 7.0.10≥ 7.2.0, ≤ 7.2.42023-10-10
CVE-2023-41675 [MEDIUM] CWE-416 CVE-2023-41675: A use after free vulnerability [CWE-416] in FortiOS version 7.2.0 through 7.2.4 and version 7.0.0 th
A use after free vulnerability [CWE-416] in FortiOS version 7.2.0 through 7.2.4 and version 7.0.0 through 7.0.10 and FortiProxy version 7.2.0 through 7.2.2 and version 7.0.0 through 7.0.8 may allow an unauthenticated remote attacker to crash the WAD process via multiple crafted packets reaching proxy policies or firewall policies with proxy mode alo
nvd