cbcvebase.

Fortinet Fortipam vulnerabilities

35 known vulnerabilities affecting fortinet/fortipam.

Total CVEs
35
CISA KEV
1
actively exploited
Public exploits
2
Exploited in wild
1
Severity breakdown
CRITICAL3HIGH14MEDIUM18

Vulnerabilities

Page 2 of 2
CVE-2024-47570P3MEDIUMCVSS 6.6≥ 1.0.0, ≤ 1.4.3≥ 1.4.0, ≤ 1.4.3+3 more2025-12-09
CVE-2024-47570 [MEDIUM] CWE-532 CVE-2024-47570: An insertion of sensitive information into log file vulnerability [CWE-532] in FortiOS 7.4.0 through An insertion of sensitive information into log file vulnerability [CWE-532] in FortiOS 7.4.0 through 7.4.3, 7.2.0 through 7.2.7, 7.0 all versions; FortiProxy 7.4.0 through 7.4.3, 7.2.0 through 7.2.11; FortiPAM 1.4 all versions, 1.3 all versions, 1.2 all versions, 1.1 all versions, 1.0 all versions and FortiSRA 1.4 all versions may allow a read-only
nvd
CVE-2025-25248P3MEDIUMCVSS 6.5≥ 1.0.0, < 1.4.3v1.5.0+5 more2025-08-12
CVE-2025-25248 [MEDIUM] CWE-190 CVE-2025-25248: An Integer Overflow or Wraparound vulnerability [CWE-190] in FortiOS version 7.6.2 and below, versio An Integer Overflow or Wraparound vulnerability [CWE-190] in FortiOS version 7.6.2 and below, version 7.4.7 and below, version 7.2.10 and below, 7.2 all versions, 6.4 all versions, FortiProxy version 7.6.2 and below, version 7.4.3 and below, 7.2 all versions, 7.0 all versions, 2.0 all versions and FortiPAM version 1.5.0, version 1.4.2 and below, 1.3
nvd
CVE-2023-36640P4MEDIUMCVSS 6.7≤ 1.0.3≥ 1.0.0, ≤ 1.0.32024-05-14
CVE-2023-36640 [MEDIUM] CWE-134 CVE-2023-36640: A use of externally-controlled format string vulnerability in Fortinet FortiOS 7.4.0, FortiOS 7.2.0 A use of externally-controlled format string vulnerability in Fortinet FortiOS 7.4.0, FortiOS 7.2.0 through 7.2.5, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiOS 6.2 all versions, FortiOS 6.0.0 through 6.0.16, FortiPAM 1.1.0, FortiPAM 1.0 all versions, FortiProxy 7.2.0 through 7.2.5, FortiProxy 7.0.0 through 7.0.11, FortiProxy 2.0 all ve
nvd
CVE-2023-37934P4MEDIUMCVSS 6.5≥ 1.0.0, < 1.1.0≥ 1.0.0, ≤ 1.0.32024-01-10
CVE-2023-37934 [MEDIUM] CWE-770 CVE-2023-37934: An allocation of resources without limits or throttling vulnerability [CWE-770] in FortiPAM 1.0 all An allocation of resources without limits or throttling vulnerability [CWE-770] in FortiPAM 1.0 all versions allows an authenticated attacker to perform a denial of service attack via sending crafted HTTP or HTTPS requests in a high frequency.
nvd
CVE-2023-40721P4MEDIUMCVSS 6.7≥ 1.0.0, < 1.2.0≥ 1.1.0, ≤ 1.1.2+1 more2025-02-11
CVE-2023-40721 [MEDIUM] CWE-134 CVE-2023-40721: A use of externally-controlled format string vulnerability [CWE-134] vulnerability in Fortinet allo A use of externally-controlled format string vulnerability [CWE-134] vulnerability in Fortinet allows a privileged attacker to execute arbitrary code or commands via specially crafted requests.
nvd
CVE-2025-54821P4MEDIUMCVSS 6.0≥ 1.0.0, < 1.6.1v1.6.0+6 more2025-11-18
CVE-2025-54821 [MEDIUM] CWE-269 CVE-2025-54821: An Improper Privilege Management vulnerability [CWE-269] vulnerability in Fortinet FortiOS 7.6.0 thr An Improper Privilege Management vulnerability [CWE-269] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.11, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiPAM 1.6.0, FortiPAM 1.5 all versions, FortiPAM 1.4 all versions, FortiPAM 1.3 all versions, FortiPAM 1.2 all versions, FortiPA
nvd
CVE-2024-26008P4MEDIUMCVSS 5.3≥ 1.0.0, < 1.3.0v1.2.0+2 more2025-10-14
CVE-2024-26008 [MEDIUM] CWE-754 CVE-2024-26008: An improper check or handling of exceptional conditions vulnerability [CWE-703] in FortiOS version 7 An improper check or handling of exceptional conditions vulnerability [CWE-703] in FortiOS version 7.4.0 through 7.4.3 and before 7.2.7, FortiProxy version 7.4.0 through 7.4.3 and before 7.2.9, FortiPAM before 1.2.0 and FortiSwitchManager version 7.2.0 through 7.2.3 and version 7.0.0 through 7.0.3 fgfm daemon may allow an unauthenticated attacker to
nvd
CVE-2024-52963P4MEDIUMCVSS 5.9≥ 1.4.0, ≤ 1.4.2≥ 1.3.0, ≤ 1.3.1+3 more2025-01-14
CVE-2024-52963 [MEDIUM] CWE-787 CVE-2024-52963: A out-of-bounds write in Fortinet FortiOS versions 7.6.0, 7.4.0 through 7.4.6, 7.2.0 through 7.2.10, A out-of-bounds write in Fortinet FortiOS versions 7.6.0, 7.4.0 through 7.4.6, 7.2.0 through 7.2.10, 7.0.0 through 7.0.16, 6.4.0 through 6.4.15 allows attacker to trigger a denial of service via specially crafted packets.
nvd
CVE-2026-59839P4MEDIUMCVSS 5.5≥ 1.0.0, < 1.7.3v1.8.0+8 more2026-07-14
CVE-2026-59839 [MEDIUM] CWE-22 CVE-2026-59839: A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fo A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiOS 7.6.0 through 7.6.6, FortiOS 7.4.0 through 7.4.9, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiPAM 1.8.0, FortiPAM 1.7.0 through 1.7.2, FortiPAM 1.6 all versions, FortiPAM 1.5 all versions, FortiPAM
nvd
CVE-2026-23573P4MEDIUMCVSS 6.1≥ 1.0.0, < 1.8.1v1.8.0+8 more2026-07-14
CVE-2026-23573 [MEDIUM] CWE-79 CVE-2026-23573: An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerabilit An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.6, FortiOS 7.4 all versions, FortiOS 7.2 all versions, FortiPAM 1.8.0, FortiPAM 1.7 all versions, FortiPAM 1.6 all versions, FortiPAM 1.5 all versions, FortiPAM 1.4 all versions, FortiPAM 1
nvd
CVE-2024-47569P4MEDIUMCVSS 4.3≥ 1.0.0, ≤ 1.3.1≥ 1.3.0, ≤ 1.3.1+2 more2025-10-14
CVE-2024-47569 [MEDIUM] CWE-201 CVE-2024-47569: A insertion of sensitive information into sent data vulnerability in Fortinet FortiMail 7.4.0 throug A insertion of sensitive information into sent data vulnerability in Fortinet FortiMail 7.4.0 through 7.4.2, FortiMail 7.2.0 through 7.2.6, FortiMail 7.0 all versions, FortiManager 7.6.0 through 7.6.1, FortiManager 7.4.1 through 7.4.3, FortiManager Cloud 7.4.1 through 7.4.3, FortiNDR 7.6.0 through 7.6.1, FortiNDR 7.4.0 through 7.4.8, FortiNDR 7.2 al
nvd
CVE-2025-62826P4MEDIUMCVSS 4.3v1.7.0≥ 1.6.0, ≤ 1.6.2+6 more2026-07-14
CVE-2025-62826 [MEDIUM] CWE-113 CVE-2025-62826: An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerabili An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CWE-113] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, FortiOS 7.4 all versions, FortiOS 7.2 all versions, FortiProxy 7.6.0 through 7.6.4, FortiProxy 7.4 all versions, FortiProxy 7.2 all versions may allow an attacker able to intercept an
nvd
CVE-2025-62675P4MEDIUMCVSS 4.3v1.7.0≥ 1.6.0, ≤ 1.6.2+6 more2026-07-14
CVE-2025-62675 [MEDIUM] CWE-113 CVE-2025-62675: An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerabili An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CWE-113] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, FortiOS 7.4 all versions, FortiOS 7.2 all versions, FortiProxy 7.6.0 through 7.6.4, FortiProxy 7.4 all versions, FortiProxy 7.2 all versions may allow an attacker in possession of a v
nvd
CVE-2026-59840P4MEDIUMCVSS 4.3v1.7.0≥ 1.6.0, ≤ 1.6.2+6 more2026-07-14
CVE-2026-59840 [MEDIUM] CWE-126 CVE-2026-59840: A buffer over-read vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4. A buffer over-read vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiProxy 7.6.0 through 7.6.5, FortiProxy 7.4.0 through 7.4.13, FortiProxy 7.2 all versions, FortiProxy 7.0 all versions may allow attacker to information disclosure via
nvd
CVE-2025-61713P4MEDIUMCVSS 4.4≥ 1.0.0, < 1.6.1v1.6.0+6 more2025-11-18
CVE-2025-61713 [MEDIUM] CWE-316 CVE-2025-61713: A Cleartext Storage of Sensitive Information in Memory vulnerability [CWE-316] in Fortinet FortiPAM A Cleartext Storage of Sensitive Information in Memory vulnerability [CWE-316] in Fortinet FortiPAM 1.6.0, FortiPAM 1.5 all versions, FortiPAM 1.4 all versions, FortiPAM 1.3 all versions, FortiPAM 1.2 all versions, FortiPAM 1.1 all versions, FortiPAM 1.0 all versions may allow an authenticated attacker with read-write admin privileges to the CLI to o
nvd
Fortinet Fortipam vulnerabilities | cvebase