Fortinet Fortipam vulnerabilities

29 known vulnerabilities affecting fortinet/fortipam.

Total CVEs
29
CISA KEV
1
actively exploited
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL4HIGH14MEDIUM11

Vulnerabilities

Page 1 of 2
CVE-2024-47570MEDIUMCVSS 6.6≥ 1.0.0, ≤ 1.4.3≥ 1.4.0, ≤ 1.4.3+3 more2025-12-09
CVE-2024-47570 [MEDIUM] CWE-532 CVE-2024-47570: An insertion of sensitive information into log file vulnerability [CWE-532] in FortiOS 7.4.0 through An insertion of sensitive information into log file vulnerability [CWE-532] in FortiOS 7.4.0 through 7.4.3, 7.2.0 through 7.2.7, 7.0 all versions; FortiProxy 7.4.0 through 7.4.3, 7.2.0 through 7.2.11; FortiPAM 1.4 all versions, 1.3 all versions, 1.2 all versions, 1.1 all versions, 1.0 all versions and FortiSRA 1.4 all versions may allow a read-only
cvelistv5nvd
CVE-2025-54821MEDIUMCVSS 6.0≥ 1.0.0, < 1.6.1v1.6.0+6 more2025-11-18
CVE-2025-54821 [LOW] CWE-269 CVE-2025-54821: An Improper Privilege Management vulnerability [CWE-269] vulnerability in Fortinet FortiOS 7.6.0 thr An Improper Privilege Management vulnerability [CWE-269] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4 all versions, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiPAM 1.6.0, FortiPAM 1.5 all versions, FortiPAM 1.4 all versions, FortiPAM 1.3 all versions, FortiPAM 1.2 all versions, FortiPAM 1.1 a
cvelistv5nvd
CVE-2025-61713MEDIUMCVSS 4.4≥ 1.0.0, < 1.6.1v1.6.0+6 more2025-11-18
CVE-2025-61713 [MEDIUM] CWE-316 CVE-2025-61713: A Cleartext Storage of Sensitive Information in Memory vulnerability [CWE-316] in Fortinet FortiPAM A Cleartext Storage of Sensitive Information in Memory vulnerability [CWE-316] in Fortinet FortiPAM 1.6.0, FortiPAM 1.5 all versions, FortiPAM 1.4 all versions, FortiPAM 1.3 all versions, FortiPAM 1.2 all versions, FortiPAM 1.1 all versions, FortiPAM 1.0 all versions may allow an authenticated attacker with read-write admin privileges to the CLI to o
cvelistv5nvd
CVE-2025-49201CRITICALCVSS 9.8≥ 1.0.0, < 1.4.3v1.5.0+5 more2025-10-14
CVE-2025-49201 [HIGH] CWE-1390 CVE-2025-49201: A weak authentication vulnerability in Fortinet FortiPAM 1.5.0, FortiPAM 1.4.0 through 1.4.2, FortiP A weak authentication vulnerability in Fortinet FortiPAM 1.5.0, FortiPAM 1.4.0 through 1.4.2, FortiPAM 1.3 all versions, FortiPAM 1.2 all versions, FortiPAM 1.1 all versions, FortiPAM 1.0 all versions, FortiSwitchManager 7.2.0 through 7.2.4 allows attacker to execute unauthorized code or commands via specially crafted http requests
cvelistv5nvd
CVE-2025-22258HIGHCVSS 7.2≥ 1.0.0, < 1.4.3v1.5.0+5 more2025-10-14
CVE-2025-22258 [MEDIUM] CWE-122 CVE-2025-22258: A heap-based buffer overflow in Fortinet FortiSRA 1.5.0, 1.4.0 through 1.4.2, FortiPAM 1.5.0, 1.4.0 A heap-based buffer overflow in Fortinet FortiSRA 1.5.0, 1.4.0 through 1.4.2, FortiPAM 1.5.0, 1.4.0 through 1.4.2, 1.3.0 through 1.3.1, 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiProxy 7.6.0 through 7.6.1, 7.4.0 through 7.4.7, FortiOS 7.6.0 through 7.6.2, 7.4.0 through 7.4.6, 7.2.0 through 7.2.10, 7.0.2 through 7.0.16, FortiSwitchManager 7
cvelistv5nvd
CVE-2025-57740HIGHCVSS 8.8≥ 1.0.0, < 1.4.3v1.5.0+5 more2025-10-14
CVE-2025-57740 [HIGH] CWE-122 CVE-2025-57740: An Heap-based Buffer Overflow vulnerability [CWE-122] in FortiOS version 7.6.2 and below, version 7. An Heap-based Buffer Overflow vulnerability [CWE-122] in FortiOS version 7.6.2 and below, version 7.4.7 and below, version 7.2.10 and below, 7.0 all versions, 6.4 all versions; FortiPAM version 1.5.0, version 1.4.2 and below, 1.3 all versions, 1.2 all versions, 1.1 all versions, 1.0 all versions and FortiProxy version 7.6.2 and below, version 7.4.3 an
cvelistv5nvd
CVE-2025-25253HIGHCVSS 7.5v1.4.12025-10-14
CVE-2025-25253 [HIGH] CWE-297 CVE-2025-25253: An Improper Validation of Certificate with Host Mismatch vulnerability [CWE-297] in FortiProxy versi An Improper Validation of Certificate with Host Mismatch vulnerability [CWE-297] in FortiProxy version 7.6.1 and below, version 7.4.8 and below, 7.2 all versions, 7.0 all versions and FortiOS version 7.6.2 and below, version 7.4.8 and below, 7.2 all versions, 7.0 all versions ZTNA proxy may allow an unauthenticated attacker in a man-in-the middle posi
cvelistv5nvd
CVE-2024-26008MEDIUMCVSS 5.3≥ 1.0.0, < 1.3.0v1.2.0+2 more2025-10-14
CVE-2024-26008 [MEDIUM] CWE-754 CVE-2024-26008: An improper check or handling of exceptional conditions vulnerability [CWE-703] in FortiOS version 7 An improper check or handling of exceptional conditions vulnerability [CWE-703] in FortiOS version 7.4.0 through 7.4.3 and before 7.2.7, FortiProxy version 7.4.0 through 7.4.3 and before 7.2.9, FortiPAM before 1.2.0 and FortiSwitchManager version 7.2.0 through 7.2.3 and version 7.0.0 through 7.0.3 fgfm daemon may allow an unauthenticated attacker to
cvelistv5nvd
CVE-2024-47569MEDIUMCVSS 4.3≥ 1.0.0, ≤ 1.3.1≥ 1.3.0, ≤ 1.3.1+2 more2025-10-14
CVE-2024-47569 [MEDIUM] CWE-201 CVE-2024-47569: A insertion of sensitive information into sent data vulnerability in Fortinet FortiMail 7.4.0 throug A insertion of sensitive information into sent data vulnerability in Fortinet FortiMail 7.4.0 through 7.4.2, FortiMail 7.2.0 through 7.2.6, FortiMail 7.0 all versions, FortiManager 7.6.0 through 7.6.1, FortiManager 7.4.1 through 7.4.3, FortiManager Cloud 7.4.1 through 7.4.3, FortiNDR 7.6.0 through 7.6.1, FortiNDR 7.4.0 through 7.4.8, FortiNDR 7.2 al
cvelistv5nvd
CVE-2024-26009HIGHCVSS 8.1≥ 1.0.0, ≤ 1.2.0v1.2.0+1 more2025-08-12
CVE-2024-26009 [HIGH] CWE-288 CVE-2024-26009: An authentication bypass using an alternate path or channel [CWE-288] vulnerability in Fortinet Fort An authentication bypass using an alternate path or channel [CWE-288] vulnerability in Fortinet FortiOS version 6.4.0 through 6.4.15 and before 6.2.16, FortiProxy version 7.4.0 through 7.4.2, 7.2.0 through 7.2.8 and before 7.0.15 & FortiPAM before version 1.2.0 allows an unauthenticated attacker to seize control of a managed device via crafted FGFM re
cvelistv5nvd
CVE-2023-45584HIGHCVSS 7.2≥ 1.0.0, ≤ 1.1.2≥ 1.1.0, ≤ 1.1.22025-08-12
CVE-2023-45584 [MEDIUM] CWE-415 CVE-2023-45584: A double free vulnerability [CWE-415] vulnerability in Fortinet FortiOS 7.4.0, FortiOS 7.2.0 through A double free vulnerability [CWE-415] vulnerability in Fortinet FortiOS 7.4.0, FortiOS 7.2.0 through 7.2.5, FortiOS 7.0.0 through 7.0.12, FortiOS 6.4 all versions, FortiPAM 1.1 all versions, FortiPAM 1.0 all versions, FortiProxy 7.4.0 through 7.4.1, FortiProxy 7.2.0 through 7.2.7, FortiProxy 7.0.0 through 7.0.13 allows a privileged attacker to execu
cvelistv5nvd
CVE-2025-25248MEDIUMCVSS 6.5≥ 1.0.0, < 1.4.3v1.5.0+5 more2025-08-12
CVE-2025-25248 [MEDIUM] CWE-190 CVE-2025-25248: An Integer Overflow or Wraparound vulnerability [CWE-190] in FortiOS version 7.6.2 and below, versio An Integer Overflow or Wraparound vulnerability [CWE-190] in FortiOS version 7.6.2 and below, version 7.4.7 and below, version 7.2.10 and below, 7.2 all versions, 6.4 all versions, FortiProxy version 7.6.2 and below, version 7.4.3 and below, 7.2 all versions, 7.0 all versions, 2.0 all versions and FortiPAM version 1.5.0, version 1.4.2 and below, 1.3
cvelistv5nvd
CVE-2025-22256HIGHCVSS 8.8≥ 1.0.0, < 1.0.4≥ 1.1.0, < 1.1.3+6 more2025-06-10
CVE-2025-22256 [MEDIUM] CWE-280 CVE-2025-22256: A improper handling of insufficient permissions or privileges in Fortinet FortiPAM 1.4.0 through 1.4 A improper handling of insufficient permissions or privileges in Fortinet FortiPAM 1.4.0 through 1.4.1, 1.3.0, 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiSRA 1.4.0 through 1.4.1 allows attacker to improper access control via specially crafted HTTP requests
cvelistv5nvd
CVE-2024-50562MEDIUMCVSS 4.8PoC≥ 1.4.0, ≤ 1.4.1v1.3.0+3 more2025-06-10
CVE-2024-50562 [MEDIUM] CWE-613 CVE-2024-50562: An Insufficient Session Expiration vulnerability [CWE-613] in FortiOS SSL-VPN version 7.6.0, version An Insufficient Session Expiration vulnerability [CWE-613] in FortiOS SSL-VPN version 7.6.0, version 7.4.6 and below, version 7.2.10 and below, 7.0 all versions, 6.4 all versions may allow an attacker in possession of a cookie used to log in the SSL-VPN portal to log in again, although the session has expired or was logged out.
cvelistv5nvd
CVE-2024-45324HIGHCVSS 7.2≥ 1.0.0, ≤ 1.3.1≥ 1.4.0, < 1.4.3+4 more2025-03-11
CVE-2024-45324 [HIGH] CWE-134 CVE-2024-45324: A use of externally-controlled format string vulnerability [CWE-134] in FortiOS version 7.4.0 throug A use of externally-controlled format string vulnerability [CWE-134] in FortiOS version 7.4.0 through 7.4.4, version 7.2.0 through 7.2.9, version 7.0.0 through 7.0.15 and before 6.4.15, FortiProxy version 7.4.0 through 7.4.6, version 7.2.0 through 7.2.12 and before 7.0.19, FortiPAM version 1.4.0 through 1.4.2 and before 1.3.1, FortiSRA version 1.4.0 t
cvelistv5nvd
CVE-2023-40721MEDIUMCVSS 6.7≥ 1.0.0, < 1.2.0≥ 1.1.0, ≤ 1.1.2+1 more2025-02-11
CVE-2023-40721 [MEDIUM] CWE-134 CVE-2023-40721: A use of externally-controlled format string vulnerability [CWE-134] vulnerability in Fortinet allo A use of externally-controlled format string vulnerability [CWE-134] vulnerability in Fortinet allows a privileged attacker to execute arbitrary code or commands via specially crafted requests.
cvelistv5nvd
CVE-2024-46670HIGHCVSS 7.5≥ 1.4.0, ≤ 1.4.1v1.3.0+3 more2025-01-14
CVE-2024-46670 [HIGH] CWE-125 CVE-2024-46670: An Out-of-bounds Read vulnerability [CWE-125] in FortiOS version 7.6.0, version 7.4.4 and below, ver An Out-of-bounds Read vulnerability [CWE-125] in FortiOS version 7.6.0, version 7.4.4 and below, version 7.2.9 and below and FortiSASE FortiOS tenant version 24.3.b IPsec IKE service may allow an unauthenticated remote attacker to trigger memory consumption leading to Denial of Service via crafted requests.
cvelistv5nvd
CVE-2024-52963MEDIUMCVSS 5.9≥ 1.4.0, ≤ 1.4.2≥ 1.3.0, ≤ 1.3.1+3 more2025-01-14
CVE-2024-52963 [LOW] CWE-787 CVE-2024-52963: A out-of-bounds write in Fortinet FortiOS versions 7.6.0, 7.4.0 through 7.4.6, 7.2.0 through 7.2.10, A out-of-bounds write in Fortinet FortiOS versions 7.6.0, 7.4.0 through 7.4.6, 7.2.0 through 7.2.10, 7.0.0 through 7.0.16, 6.4.0 through 6.4.15 allows attacker to trigger a denial of service via specially crafted packets.
cvelistv5nvd
CVE-2024-26011CRITICALCVSS 9.8≥ 1.0.0, < 1.3.0v1.2.0+2 more2024-11-12
CVE-2024-26011 [MEDIUM] CWE-306 CVE-2024-26011: A missing authentication for critical function in Fortinet FortiManager version 7.4.0 through 7.4.2, A missing authentication for critical function in Fortinet FortiManager version 7.4.0 through 7.4.2, 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through 6.4.14, FortiPAM version 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiProxy version 7.4.0 through 7.4.2, 7.2.0 through 7.2.9, 7.0.0 through 7.0.17, 2.0.0 through 2.0.14, 1.2.0 through
cvelistv5nvd
CVE-2022-45862HIGHCVSS 8.8≥ 1.0.0, < 1.4.0v1.3.0+3 more2024-08-13
CVE-2022-45862 [LOW] CWE-613 CVE-2022-45862: An insufficient session expiration vulnerability [CWE-613] vulnerability in FortiOS 7.2.5 and below, An insufficient session expiration vulnerability [CWE-613] vulnerability in FortiOS 7.2.5 and below, 7.0 all versions, 6.4 all versions; FortiProxy 7.2 all versions, 7.0 all versions; FortiPAM 1.3 all versions, 1.2 all versions, 1.1 all versions, 1.0 all versions; FortiSwitchManager 7.2.1 and below, 7.0 all versions GUI may allow attackers to re-use we
cvelistv5nvd