cbcvebase.

Fortinet Fortiproxy vulnerabilities

130 known vulnerabilities affecting fortinet/fortiproxy.

Total CVEs
130
CISA KEV
12
actively exploited
Public exploits
10
Exploited in wild
14
Severity breakdown
CRITICAL17HIGH39MEDIUM71LOW3

Vulnerabilities

Page 1 of 7
CVE-2022-42475P1CRITICALCVSS 9.8KEVPoCRansomware≥ 1.0.0, ≤ 1.0.7≥ 1.1.0, ≤ 1.1.6+7 more2023-01-02
CVE-2022-42475 [CRITICAL] CWE-197 CVE-2022-42475: A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 t A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0 through 6.4.10, 6.2.0 through 6.2.11, 6.0.15 and earlier and FortiProxy SSL-VPN 7.2.0 through 7.2.1, 7.0.7 and earlier may allow a remote unauthenticated attacker to execute arbitrary code or commands via specifically crafted req
nvd
CVE-2024-55591P1CRITICALCVSS 9.8KEVPoCRansomware≥ 7.0.0, < 7.0.20≥ 7.2.0, < 7.2.13+2 more2025-01-14
CVE-2024-55591 [CRITICAL] CWE-288 CVE-2024-55591: An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiO An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy version 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12 allows a remote attacker to gain super-admin privileges via crafted requests to Node.js websocket module.
nvd
CVE-2018-13379P1CRITICALCVSS 9.8KEVPoCRansomwarefixed in 1.2.9v2.0.02019-06-04
CVE-2018-13379 [CRITICAL] CWE-22 CVE-2018-13379: An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiO An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.3 to 5.6.7 and 5.4.6 to 5.4.12 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 to 1.1.6, 1.0.0 to 1.0.7 under SSL VPN web portal allows an unauthenticated attacker to download system files via special crafted HTTP resource requests.
nvd
CVE-2022-40684P1CRITICALCVSS 9.8KEVPoCRansomware≥ 7.0.0, < 7.0.7v7.2.02022-10-18
CVE-2022-40684 [CRITICAL] CWE-287 CVE-2022-40684: An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7. An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6, FortiProxy version 7.2.0 and version 7.0.0 through 7.0.6 and FortiSwitchManager version 7.2.0 and 7.0.0 allows an unauthenticated atttacker to perform operations on the administrative interface via speciall
nvd
CVE-2024-21762P1CRITICALCVSS 9.8KEVPoCRansomware≥ 1.0.0, < 2.0.14≥ 7.0.0, < 7.0.15+9 more2024-02-09
CVE-2024-21762 [CRITICAL] CWE-787 CVE-2024-21762: A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 t A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, 6.0.0 through 6.0.17, FortiProxy versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0.14, 2.0.0 through 2.0.13, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6, 1.0.0 through 1.0.7
nvd
CVE-2023-27997P1CRITICALCVSS 9.8KEVPoCRansomware≥ 1.1.0, ≤ 1.1.6≥ 1.2.0, ≤ 1.2.13+3 more2023-06-13
CVE-2023-27997 [CRITICAL] CWE-122 CVE-2023-27997: A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0 A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, version 6.4.12 and below, version 6.0.16 and below and FortiProxy version 7.2.3 and below, version 7.0.9 and below, version 2.0.12 and below, version 1.2 all versions, version 1.1 all versions SSL-VPN may allow a remote attacker to ex
nvd
CVE-2024-23113P1CRITICALCVSS 9.8KEVPoC≥ 7.0.0, ≤ 7.0.14≥ 7.2.0, ≤ 7.2.8+1 more2024-02-15
CVE-2024-23113 [CRITICAL] CWE-134 CVE-2024-23113: A use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 A use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, FortiProxy versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0.14, FortiPAM versions 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiSwitchManager versions 7.2.0 through 7.2.3, 7.0.0 throu
nvd
CVE-2018-13382P1HIGHCVSS 7.5KEVPoCRansomwarefixed in 1.2.9v2.0.02019-06-04
CVE-2018-13382 [HIGH] CWE-863 CVE-2018-13382: An Improper Authorization vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.8 and 5.4.1 An Improper Authorization vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.8 and 5.4.1 to 5.4.10 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 to 1.1.6, 1.0.0 to 1.0.7 under SSL VPN web portal allows an unauthenticated attacker to modify the password of an SSL VPN web portal user via specially crafted HTTP requests
nvd
CVE-2026-24858P1CRITICALCVSS 9.8KEV≥ 7.0.0, ≤ 7.0.22≥ 7.2.0, ≤ 7.2.15+2 more2026-01-27
CVE-2026-24858 [CRITICAL] CWE-288 CVE-2026-24858: An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.5, FortiAnalyzer 7.4.0 through 7.4.9, FortiAnalyzer 7.2.0 through 7.2.11, FortiAnalyzer 7.0.0 through 7.0.15, FortiManager 7.6.0 through 7.6.5, FortiManager 7.4.0 through 7.4.9, FortiManager 7.2.0 through 7.
nvd
CVE-2025-59718P1CRITICALCVSS 9.8KEVRansomware≥ 7.0.0, < 7.0.22≥ 7.2.0, < 7.2.15+6 more2025-12-09
CVE-2025-59718 [CRITICAL] CWE-347 CVE-2025-59718: A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7 A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiProxy 7.6.0 through 7.6.3, FortiProxy 7.4.0 through 7.4.10, FortiProxy 7.2.0 through 7.2.14, FortiProxy 7.0.0 through 7.0.21, FortiSwitchManager 7.2.
nvd
CVE-2025-24472P1HIGHCVSS 8.1KEVRansomware≥ 7.0.0, < 7.0.20≥ 7.2.0, < 7.2.13+2 more2025-02-11
CVE-2025-24472 [HIGH] CWE-288 CVE-2025-24472: An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiO An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS 7.0.0 through 7.0.16 and FortiProxy 7.2.0 through 7.2.12, 7.0.0 through 7.0.19 may allow a remote unauthenticated attacker with prior knowledge of upstream and downstream devices serial numbers to gain super-admin privileges on the downstream device,
nvd
CVE-2018-13383P1MEDIUMCVSS 6.5KEVRansomwarefixed in 1.2.9v2.0.02019-05-29
CVE-2018-13383 [MEDIUM] CWE-787 CVE-2018-13383: A heap buffer overflow in Fortinet FortiOS 6.0.0 through 6.0.4, 5.6.0 through 5.6.10, 5.4.0 through A heap buffer overflow in Fortinet FortiOS 6.0.0 through 6.0.4, 5.6.0 through 5.6.10, 5.4.0 through 5.4.12, 5.2.14 and earlier and FortiProxy 2.0.0, 1.2.8 and earlier in the SSL VPN web portal may cause the SSL VPN web service termination for logged in users due to a failure to properly handle javascript href data when proxying webpages.
nvd
CVE-2022-41335P1HIGHCVSS 8.1Exploited≥ 1.1.0, ≤ 1.1.6≥ 1.2.0, ≤ 1.2.13+8 more2023-02-16
CVE-2022-41335 [HIGH] CWE-23 CVE-2022-41335: A relative path traversal vulnerability [CWE-23] in Fortinet FortiOS version 7.2.0 through 7.2.2, 7. A relative path traversal vulnerability [CWE-23] in Fortinet FortiOS version 7.2.0 through 7.2.2, 7.0.0 through 7.0.8 and before 6.4.10, FortiProxy version 7.2.0 through 7.2.1, 7.0.0 through 7.0.7 and before 2.0.10, FortiSwitchManager 7.2.0 and before 7.0.0 allows an authenticated attacker to read and write files on the underlying Linux system via craf
nvd
CVE-2024-21754P2MEDIUMCVSS 4.4Exploited≥ 2.0.0, ≤ 2.0.14≥ 7.0.0, ≤ 7.0.18+3 more2024-06-11
CVE-2024-21754 [MEDIUM] CWE-916 CVE-2024-21754: A use of password hash with insufficient computational effort vulnerability [CWE-916] affecting Fort A use of password hash with insufficient computational effort vulnerability [CWE-916] affecting FortiOS version 7.4.3 and below, 7.2 all versions, 7.0 all versions, 6.4 all versions and FortiProxy version 7.4.2 and below, 7.2 all versions, 7.0 all versions, 2.0 all versions may allow a privileged attacker with super-admin profile and CLI access to d
nvd
CVE-2018-13380P3MEDIUMCVSS 6.1PoC≤ 1.2.8v2.0.02019-06-04
CVE-2018-13380 [MEDIUM] CWE-79 CVE-2018-13380: A Cross-site Scripting (XSS) vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.7, 5.4.0 A Cross-site Scripting (XSS) vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.7, 5.4.0 to 5.4.12, 5.2 and below and Fortinet FortiProxy 2.0.0, 1.2.8 and below under SSL VPN web portal allows attacker to execute unauthorized malicious script code via the error or message handling parameters.
nvd
CVE-2023-25610P2CRITICALCVSS 9.8≥ 1.1.0, < 7.0.9≥ 7.2.0, < 7.2.3+5 more2025-03-24
CVE-2023-25610 [CRITICAL] CWE-124 CVE-2023-25610: A buffer underwrite ('buffer underflow') vulnerability in the administrative interface of Fortinet F A buffer underwrite ('buffer underflow') vulnerability in the administrative interface of Fortinet FortiOS version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.6, version 6.4.0 through 6.4.11 and version 6.2.12 and below, FortiProxy version 7.2.0 through 7.2.2, version 7.0.0 through 7.0.8, version 2.0.12 and below and FortiOS-6K7K version 7.0.5,
nvd
CVE-2024-48884P2CRITICALCVSS 9.1≥ 1.0.0, < 7.0.19≥ 7.2.0, < 7.2.12+8 more2025-01-14
CVE-2024-48884 [CRITICAL] CWE-22 CVE-2024-48884: A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fo A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiManager 7.6.0 through 7.6.1, FortiManager 7.4.1 through 7.4.3, FortiManager Cloud 7.4.1 through 7.4.3, FortiOS 7.6.0, FortiOS 7.4.0 through 7.4.4, FortiOS 7.2.0 through 7.2.9, FortiOS 7.0.0 through 7.0.15, FortiOS 6.4.0 through 6.4.15, Fo
nvd
CVE-2023-33308P2CRITICALCVSS 9.8≥ 7.0.0, ≤ 7.0.9v7.2.0+3 more2023-07-26
CVE-2023-33308 [CRITICAL] CWE-121 CVE-2023-33308: A stack-based overflow vulnerability [CWE-124] in Fortinet FortiOS version 7.0.0 through 7.0.10 and A stack-based overflow vulnerability [CWE-124] in Fortinet FortiOS version 7.0.0 through 7.0.10 and 7.2.0 through 7.2.3 and FortiProxy version 7.0.0 through 7.0.9 and 7.2.0 through 7.2.2 allows a remote unauthenticated attacker to execute arbitrary code or command via crafted packets reaching proxy policies or firewall policies with proxy mode alon
nvd
CVE-2023-42789P2CRITICALCVSS 9.8≥ 2.0.0, ≤ 2.0.13≥ 7.0.0, ≤ 7.0.12+2 more2024-03-12
CVE-2023-42789 [CRITICAL] CWE-787 CVE-2023-42789: A out-of-bounds write vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2.0 through 7 A out-of-bounds write vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2.0 through 7.2.5, FortiOS 7.0.0 through 7.0.12, FortiOS 6.4.0 through 6.4.14, FortiOS 6.2.0 through 6.2.15, FortiProxy 7.4.0, FortiProxy 7.2.0 through 7.2.6, FortiProxy 7.0.0 through 7.0.12, FortiProxy 2.0.0 through 2.0.13, FortiSASE 23.2.b allows attacker to e
nvd
CVE-2022-35843P2CRITICALCVSS 9.8≥ 1.2.0, ≤ 1.2.13≥ 2.0.0, ≤ 2.0.10+1 more2022-12-06
CVE-2022-35843 [CRITICAL] CWE-284 CVE-2022-35843: An authentication bypass by assumed-immutable data vulnerability [CWE-302] in the FortiOS SSH login An authentication bypass by assumed-immutable data vulnerability [CWE-302] in the FortiOS SSH login component 7.2.0, 7.0.0 through 7.0.7, 6.4.0 through 6.4.9, 6.2 all versions, 6.0 all versions and FortiProxy SSH login component 7.0.0 through 7.0.5, 2.0.0 through 2.0.10, 1.2.0 all versions may allow a remote and unauthenticated attacker to login in
nvd
Fortinet Fortiproxy vulnerabilities | cvebase