Fortinet Fortiproxy vulnerabilities
130 known vulnerabilities affecting fortinet/fortiproxy.
Total CVEs
130
CISA KEV
12
actively exploited
Public exploits
10
Exploited in wild
14
Severity breakdown
CRITICAL17HIGH39MEDIUM71LOW3
Vulnerabilities
Page 2 of 7
CVE-2022-41331P2CRITICALCVSS 9.8≥ 1.0.0, < 2.0.02023-04-11
CVE-2022-41331 [CRITICAL] CWE-306 CVE-2022-41331: A missing authentication for critical function vulnerability [CWE-306] in FortiPresence infrastructu
A missing authentication for critical function vulnerability [CWE-306] in FortiPresence infrastructure server before version 1.2.1 allows a remote, unauthenticated attacker to access the Redis and MongoDB instances via crafted authentication requests.
nvd
CVE-2024-26011P2CRITICALCVSS 9.8≥ 1.0.0, < 7.0.17≥ 7.2.0, < 7.2.10+8 more2024-11-12
CVE-2024-26011 [CRITICAL] CWE-306 CVE-2024-26011: A missing authentication for critical function in Fortinet FortiManager version 7.4.0 through 7.4.2,
A missing authentication for critical function in Fortinet FortiManager version 7.4.0 through 7.4.2, 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through 6.4.14, FortiPAM version 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiProxy version 7.4.0 through 7.4.2, 7.2.0 through 7.2.9, 7.0.0 through 7.0.17, 2.0.0 through 2.0.14, 1.2.0 throug
nvd
CVE-2024-48886P2CRITICALCVSS 9.8≥ 2.0.0, < 2.0.15≥ 7.0.0, < 7.0.18+6 more2025-01-14
CVE-2024-48886 [CRITICAL] CWE-1390 CVE-2024-48886: A weak authentication in Fortinet FortiOS versions 7.4.0 through 7.4.4, 7.2.0 through 7.2.8, 7.0.0 t
A weak authentication in Fortinet FortiOS versions 7.4.0 through 7.4.4, 7.2.0 through 7.2.8, 7.0.0 through 7.0.15, 6.4.0 through 6.4.15, FortiProxy versions 7.4.0 through 7.4.4, 7.2.0 through 7.2.10, 7.0.0 through 7.0.17, 2.0.0 through 2.0.14, FortiManager versions 7.6.0 through 7.6.1, 7.4.1 through 7.4.3, FortiManager Cloud versions 7.4.1 throug
nvd
CVE-2025-57740P3HIGHCVSS 8.8≥ 7.0.0, < 7.4.4≥ 7.6.0, < 7.6.3+4 more2025-10-14
CVE-2025-57740 [HIGH] CWE-122 CVE-2025-57740: An Heap-based Buffer Overflow vulnerability [CWE-122] in FortiOS version 7.6.2 and below, version 7.
An Heap-based Buffer Overflow vulnerability [CWE-122] in FortiOS version 7.6.2 and below, version 7.4.7 and below, version 7.2.10 and below, 7.0 all versions, 6.4 all versions; FortiPAM version 1.5.0, version 1.4.2 and below, 1.3 all versions, 1.2 all versions, 1.1 all versions, 1.0 all versions and FortiProxy version 7.6.2 and below, version 7.4.3 an
nvd
CVE-2024-26009P3HIGHCVSS 8.1≥ 7.0.0, < 7.0.16≥ 7.2.0, < 7.2.9+4 more2025-08-12
CVE-2024-26009 [HIGH] CWE-288 CVE-2024-26009: An authentication bypass using an alternate path or channel [CWE-288] vulnerability in Fortinet Fort
An authentication bypass using an alternate path or channel [CWE-288] vulnerability in Fortinet FortiOS 6.4.0 through 6.4.15, FortiOS 6.2.0 through 6.2.16, FortiOS 6.0 all versions, FortiPAM 1.2.0, FortiPAM 1.1.0 through 1.1.2, FortiPAM 1.0.0 through 1.0.3, FortiProxy 7.4.0 through 7.4.2, FortiProxy 7.2.0 through 7.2.8, FortiProxy 7.0.0 through 7.0.15
nvd
CVE-2023-22640P3HIGHCVSS 8.8v1.0.0v1.1.0+8 more2023-05-03
CVE-2023-22640 [HIGH] CWE-787 CVE-2023-22640: A out-of-bounds write in Fortinet FortiOS version 7.2.0 through 7.2.3, FortiOS version 7.0.0 through
A out-of-bounds write in Fortinet FortiOS version 7.2.0 through 7.2.3, FortiOS version 7.0.0 through 7.0.10, FortiOS version 6.4.0 through 6.4.11, FortiOS version 6.2.0 through 6.2.13, FortiOS all versions 6.0, FortiProxy version 7.2.0 through 7.2.1, FortiProxy version 7.0.0 through 7.0.7, FortiProxy all versions 2.0, FortiProxy all versions 1.2, Fort
nvd
CVE-2023-36639P3HIGHCVSS 8.8≥ 7.0.0, ≤ 7.0.10≥ 7.2.0, ≤ 7.2.42023-12-13
CVE-2023-36639 [HIGH] CWE-134 CVE-2023-36639: A use of externally-controlled format string in Fortinet FortiProxy versions 7.2.0 through 7.2.4, 7.
A use of externally-controlled format string in Fortinet FortiProxy versions 7.2.0 through 7.2.4, 7.0.0 through 7.0.10, FortiOS versions 7.4.0, 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through 6.4.12, 6.2.0 through 6.2.15, 6.0.0 through 6.0.17, FortiPAM versions 1.0.0 through 1.0.3 allows attacker to execute unauthorized code or commands via s
nvd
CVE-2022-45862P3HIGHCVSS 8.8≥ 7.0.0, < 7.4.0≥ 7.2.0, ≤ 7.2.11+1 more2024-08-13
CVE-2022-45862 [HIGH] CWE-613 CVE-2022-45862: An insufficient session expiration vulnerability [CWE-613] vulnerability in FortiOS 7.2.5 and below,
An insufficient session expiration vulnerability [CWE-613] vulnerability in FortiOS 7.2.5 and below, 7.0 all versions, 6.4 all versions; FortiProxy 7.2 all versions, 7.0 all versions; FortiPAM 1.3 all versions, 1.2 all versions, 1.1 all versions, 1.0 all versions; FortiSwitchManager 7.2.1 and below, 7.0 all versions GUI may allow attackers to re-use w
nvd
CVE-2023-29181P3HIGHCVSS 8.8≥ 1.0.0, < 2.0.13≥ 7.0.0, < 7.0.11+7 more2024-02-22
CVE-2023-29181 [HIGH] CWE-134 CVE-2023-29181: A use of externally-controlled format string in Fortinet FortiOS 7.2.0 through 7.2.4, 7.0.0 through
A use of externally-controlled format string in Fortinet FortiOS 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through 6.4.12, 6.2.0 through 6.2.14, 6.0.0 through 6.0.16, FortiProxy 7.2.0 through 7.2.4, 7.0.0 through 7.0.10, 2.0.0 through 2.0.12, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6, 1.0.0 through 1.0.7, FortiPAM 1.0.0 through 1.0.3 allows atta
nvd
CVE-2023-37930P3HIGHCVSS 8.8≥ 7.0.0, < 7.0.13≥ 7.2.0, < 7.2.7+2 more2025-04-08
CVE-2023-37930 [HIGH] CWE-908 CVE-2023-37930: Multiple issues including the use of uninitialized ressources [CWE-908] and excessive iteration [CWE
Multiple issues including the use of uninitialized ressources [CWE-908] and excessive iteration [CWE-834] vulnerabilities vulnerability in Fortinet allows a VPN user to corrupt memory potentially leading to code or commands execution via specifically crafted requests.
nvd
CVE-2022-43947P3HIGHCVSS 8.8≥ 1.0.0, ≤ 2.0.9≥ 7.0.0, < 7.0.8+6 more2023-04-11
CVE-2022-43947 [HIGH] CWE-307 CVE-2022-43947: An improper restriction of excessive authentication attempts vulnerability [CWE-307] in Fortinet For
An improper restriction of excessive authentication attempts vulnerability [CWE-307] in Fortinet FortiOS version 7.2.0 through 7.2.3 and before 7.0.10, FortiProxy version 7.2.0 through 7.2.2 and before 7.0.8 administrative interface allows an attacker with a valid user account to perform brute-force attacks on other user accounts via injecting valid l
nvd
CVE-2023-41677P3HIGHCVSS 8.8≥ 1.0.0, < 7.0.14≥ 7.2.0, < 7.2.8+8 more2024-04-09
CVE-2023-41677 [HIGH] CWE-522 CVE-2023-41677: A insufficiently protected credentials in Fortinet FortiProxy 7.4.0, 7.2.0 through 7.2.6, 7.0.0 thro
A insufficiently protected credentials in Fortinet FortiProxy 7.4.0, 7.2.0 through 7.2.6, 7.0.0 through 7.0.12, 2.0.0 through 2.0.13, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6, 1.0.0 through 1.0.7, Fortinet FortiOS 7.4.0 through 7.4.1, 7.2.0 through 7.2.6, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, 6.0.0 through 6.0.17 allows at
nvd
CVE-2023-42790P3HIGHCVSS 8.1≥ 2.0.0, ≤ 2.0.13≥ 7.0.0, ≤ 7.0.12+2 more2024-03-12
CVE-2023-42790 [HIGH] CWE-121 CVE-2023-42790: A stack-based buffer overflow vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2.0 t
A stack-based buffer overflow vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2.0 through 7.2.5, FortiOS 7.0.0 through 7.0.12, FortiOS 6.4.0 through 6.4.14, FortiOS 6.2.0 through 6.2.15, FortiProxy 7.4.0, FortiProxy 7.2.0 through 7.2.6, FortiProxy 7.0.0 through 7.0.12, FortiProxy 2.0.0 through 2.0.13, FortiSASE 23.2.b allows attacker
nvd
CVE-2025-22252P3HIGHCVSS 7.2v7.6.0≥ 7.6.0, ≤ 7.6.12025-05-28
CVE-2025-22252 [HIGH] CWE-306 CVE-2025-22252: A missing authentication for critical function in Fortinet FortiProxy versions 7.6.0 through 7.6.1,
A missing authentication for critical function in Fortinet FortiProxy versions 7.6.0 through 7.6.1, FortiSwitchManager version 7.2.5, and FortiOS versions 7.4.4 through 7.4.6 and version 7.6.0 may allow an attacker with knowledge of an existing admin account to access the device as a valid admin via an authentication bypass.
nvd
CVE-2023-44250P3HIGHCVSS 8.8v7.4.0v7.4.1+1 more2024-01-10
CVE-2023-44250 [HIGH] CWE-269 CVE-2023-44250: An improper privilege management vulnerability [CWE-269] in a Fortinet FortiOS HA cluster version 7.
An improper privilege management vulnerability [CWE-269] in a Fortinet FortiOS HA cluster version 7.4.0 through 7.4.1 and 7.2.5 and in a FortiProxy HA cluster version 7.4.0 through 7.4.1 allows an authenticated attacker to perform elevated actions via crafted HTTP or HTTPS requests.
nvd
CVE-2024-50562P4MEDIUMCVSS 4.8PoCv7.6.0≥ 7.4.0, ≤ 7.4.5+3 more2025-06-10
CVE-2024-50562 [MEDIUM] CWE-613 CVE-2024-50562: An Insufficient Session Expiration vulnerability [CWE-613] in FortiOS SSL-VPN version 7.6.0, version
An Insufficient Session Expiration vulnerability [CWE-613] in FortiOS SSL-VPN version 7.6.0, version 7.4.6 and below, version 7.2.10 and below, 7.0 all versions, 6.4 all versions may allow an attacker in possession of a cookie used to log in the SSL-VPN portal to log in again, although the session has expired or was logged out.
nvd
CVE-2023-45584P3HIGHCVSS 7.2≥ 7.0.0, < 7.0.14≥ 7.2.0, < 7.2.8+4 more2025-08-12
CVE-2023-45584 [HIGH] CWE-415 CVE-2023-45584: A double free vulnerability [CWE-415] vulnerability in Fortinet FortiOS 7.4.0, FortiOS 7.2.0 through
A double free vulnerability [CWE-415] vulnerability in Fortinet FortiOS 7.4.0, FortiOS 7.2.0 through 7.2.5, FortiOS 7.0.0 through 7.0.12, FortiOS 6.4 all versions, FortiPAM 1.1 all versions, FortiPAM 1.0 all versions, FortiProxy 7.4.0 through 7.4.1, FortiProxy 7.2.0 through 7.2.7, FortiProxy 7.0.0 through 7.0.13 allows a privileged attacker to execute
nvd
CVE-2024-50571P3HIGHCVSS 7.2≥ 1.0.0, < 7.0.20≥ 7.2.0, < 7.2.13+9 more2025-10-14
CVE-2024-50571 [HIGH] CWE-122 CVE-2024-50571: A heap-based buffer overflow vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.2, FortiAnaly
A heap-based buffer overflow vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.2, FortiAnalyzer 7.4.0 through 7.4.5, FortiAnalyzer 7.2.0 through 7.2.9, FortiAnalyzer 7.0.0 through 7.0.13, FortiAnalyzer 6.4 all versions, FortiAnalyzer 6.2 all versions, FortiAnalyzer 6.0 all versions, FortiAnalyzer Cloud 7.4.1 through 7.4.5, FortiAnalyzer Cloud
nvd
CVE-2024-26013P3HIGHCVSS 7.5≥ 2.0.0, < 7.0.16≥ 7.2.0, < 7.2.10+5 more2025-04-08
CVE-2024-26013 [HIGH] CWE-923 CVE-2024-26013: A improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in For
A improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in Fortinet FortiOS version 7.4.0 through 7.4.4, 7.2.0 through 7.2.8, 7.0.0 through 7.0.15, 6.4.0 through 6.4.15 and before 6.2.16, Fortinet FortiProxy version 7.4.0 through 7.4.2, 7.2.0 through 7.2.9 and before 7.0.15, Fortinet FortiManager version 7.4.0 thr
nvd
CVE-2024-52965P3HIGHCVSS 7.2≥ 7.0.0, < 7.0.21≥ 7.2.0, < 7.2.14+6 more2025-07-08
CVE-2024-52965 [HIGH] CWE-304 CVE-2024-52965: A missing critical step in authentication vulnerability [CWE-304] in Fortinet FortiOS version 7.6.0
A missing critical step in authentication vulnerability [CWE-304] in Fortinet FortiOS version 7.6.0 through 7.6.1, 7.4.0 through 7.4.5, 7.2.0 through 7.2.10, and before 7.0.16 & FortiProxy version 7.6.0 through 7.6.1, 7.4.0 through 7.4.8, 7.2.0 through 7.2.13 and before 7.0.20 allows an API-user using api-key + PKI user certificate authentication to lo
nvd