cbcvebase.

Fortinet Fortiproxy vulnerabilities

130 known vulnerabilities affecting fortinet/fortiproxy.

Total CVEs
130
CISA KEV
12
actively exploited
Public exploits
10
Exploited in wild
14
Severity breakdown
CRITICAL17HIGH39MEDIUM71LOW3

Vulnerabilities

Page 3 of 7
CVE-2023-46718P3HIGHCVSS 7.8≥ 7.0.0, < 7.4.8≥ 7.4.0, ≤ 7.4.7+2 more2025-10-14
CVE-2023-46718 [HIGH] CWE-121 CVE-2023-46718: A stack-based buffer overflow in Fortinet FortiOS version 7.4.0 through 7.4.1 and 7.2.0 through 7.2. A stack-based buffer overflow in Fortinet FortiOS version 7.4.0 through 7.4.1 and 7.2.0 through 7.2.7 and 7.0.0 through 7.0.12 and 6.4.6 through 6.4.15 and 6.2.9 through 6.2.16 and 6.0.13 through 6.0.18 allows attacker to execute unauthorized code or commands via specially crafted CLI commands.
nvd
CVE-2024-26010P3HIGHCVSS 7.5≥ 1.0.0, < 7.0.17≥ 7.2.0, < 7.2.10+8 more2024-06-11
CVE-2024-26010 [HIGH] CWE-121 CVE-2024-26010: A stack-based buffer overflow in Fortinet FortiPAM version 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through A stack-based buffer overflow in Fortinet FortiPAM version 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiWeb, FortiAuthenticator, FortiSwitchManager version 7.2.0 through 7.2.3, 7.0.1 through 7.0.3, FortiOS version 7.4.0 through 7.4.3, 7.2.0 through 7.2.7, 7.0.0 through 7.0.14, 6.4.0 through 6.4.15, 6.2.0 through 6.2.16, 6.0.0 through 6.0.18,
nvd
CVE-2023-45583P3HIGHCVSS 7.2fixed in 7.0.12fixed in 7.2.6+2 more2024-05-14
CVE-2023-45583 [HIGH] CWE-134 CVE-2023-45583: A use of externally-controlled format string vulnerability in Fortinet FortiOS 7.4.0, FortiOS 7.2.0 A use of externally-controlled format string vulnerability in Fortinet FortiOS 7.4.0, FortiOS 7.2.0 through 7.2.5, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiOS 6.2 all versions, FortiOS 6.0.0 through 6.0.16, FortiPAM 1.1.0, FortiPAM 1.0 all versions, FortiProxy 7.2.0 through 7.2.5, FortiProxy 7.0.0 through 7.0.11, FortiProxy 2.0 all vers
nvd
CVE-2025-22258P3HIGHCVSS 7.2≥ 7.4.0, < 7.4.8≥ 7.6.0, < 7.6.2+2 more2025-10-14
CVE-2025-22258 [HIGH] CWE-122 CVE-2025-22258: A heap-based buffer overflow in Fortinet FortiSRA 1.5.0, 1.4.0 through 1.4.2, FortiPAM 1.5.0, 1.4.0 A heap-based buffer overflow in Fortinet FortiSRA 1.5.0, 1.4.0 through 1.4.2, FortiPAM 1.5.0, 1.4.0 through 1.4.2, 1.3.0 through 1.3.1, 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiProxy 7.6.0 through 7.6.1, 7.4.0 through 7.4.7, FortiOS 7.6.0 through 7.6.2, 7.4.0 through 7.4.6, 7.2.0 through 7.2.10, 7.0.2 through 7.0.16, FortiSwitchManager 7.2
nvd
CVE-2026-59837P3MEDIUMCVSS 6.6≥ 7.2.0, < 7.4.14≥ 7.4.0, ≤ 7.4.13+1 more2026-07-14
CVE-2026-59837 [MEDIUM] CWE-121 CVE-2026-59837: A stack-based buffer overflow vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2 all A stack-based buffer overflow vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2 all versions, FortiPAM 1.8.0 through 1.8.2, FortiPAM 1.7 all versions, FortiPAM 1.6 all versions, FortiPAM 1.5 all versions, FortiPAM 1.4 all versions, FortiPAM 1.3 all versions, FortiPAM 1.2 all versions, FortiPAM 1.1 all versions, FortiPAM 1.0 all vers
nvd
CVE-2024-50565P3HIGHCVSS 7.5≥ 2.0.0, < 7.0.16≥ 7.2.0, < 7.2.10+1 more2025-04-08
CVE-2024-50565 [HIGH] CWE-300 CVE-2024-50565: A improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in For A improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in Fortinet FortiOS version 7.4.0 through 7.4.3, 7.2.0 through 7.2.7, 7.0.0 through 7.0.14, 6.4.0 through 6.4.15 and 6.2.0 through 6.2.16, Fortinet FortiProxy version 7.4.0 through 7.4.2, 7.2.0 through 7.2.9, 7.0.0 through 7.0.15 and 2.0.0 through 2.0.14, For
nvd
CVE-2025-25253P3HIGHCVSS 7.5≥ 7.0.0, < 7.4.9≥ 7.6.0, < 7.6.2+4 more2025-10-14
CVE-2025-25253 [HIGH] CWE-297 CVE-2025-25253: An Improper Validation of Certificate with Host Mismatch vulnerability [CWE-297] in FortiProxy versi An Improper Validation of Certificate with Host Mismatch vulnerability [CWE-297] in FortiProxy version 7.6.1 and below, version 7.4.8 and below, 7.2 all versions, 7.0 all versions and FortiOS version 7.6.2 and below, version 7.4.8 and below, 7.2 all versions, 7.0 all versions ZTNA proxy may allow an unauthenticated attacker in a man-in-the middle posi
nvd
CVE-2022-39948P3HIGHCVSS 7.4≥ 1.2.0, ≤ 2.0.9≥ 7.0.0, < 7.0.7+2 more2023-02-16
CVE-2022-39948 [HIGH] CWE-295 CVE-2022-39948: An improper certificate validation vulnerability [CWE-295] in FortiOS 7.2.0 through 7.2.3, 7.0.0 thr An improper certificate validation vulnerability [CWE-295] in FortiOS 7.2.0 through 7.2.3, 7.0.0 through 7.0.7, 6.4 all versions, 6.2 all versions, 6.0 all versions and FortiProxy 7.0.0 through 7.0.6, 2.0 all versions, 1.2 all versions may allow a remote and unauthenticated attacker to perform a Man-in-the-Middle attack on the communication channel be
nvd
CVE-2024-45324P3HIGHCVSS 7.2≥ 7.0.0, < 7.0.20≥ 7.2.0, < 7.2.13+5 more2025-03-11
CVE-2024-45324 [HIGH] CWE-134 CVE-2024-45324: A use of externally-controlled format string vulnerability [CWE-134] in FortiOS version 7.4.0 throug A use of externally-controlled format string vulnerability [CWE-134] in FortiOS version 7.4.0 through 7.4.4, version 7.2.0 through 7.2.9, version 7.0.0 through 7.0.15 and before 6.4.15, FortiProxy version 7.4.0 through 7.4.6, version 7.2.0 through 7.2.12 and before 7.0.19, FortiPAM version 1.4.0 through 1.4.2 and before 1.3.1, FortiSRA version 1.4.0 t
nvd
CVE-2021-41024P3HIGHCVSS 7.5v7.0.02021-12-08
CVE-2021-41024 [HIGH] CWE-22 CVE-2021-41024: A relative path traversal [CWE-23] vulnerabiltiy in FortiOS versions 7.0.0 and 7.0.1 and FortiProxy A relative path traversal [CWE-23] vulnerabiltiy in FortiOS versions 7.0.0 and 7.0.1 and FortiProxy verison 7.0.0 may allow an unauthenticated, unauthorized attacker to inject path traversal character sequences to disclose sensitive information of the server via the GET request of the login page.
nvd
CVE-2025-61624P3MEDIUMCVSS 6.5≥ 7.0.0, < 7.4.12≥ 7.6.0, < 7.6.5+4 more2026-04-14
CVE-2025-61624 [MEDIUM] CWE-22 CVE-2025-61624: An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') [CWE-22] vulnerabi An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') [CWE-22] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, FortiOS 7.4.0 through 7.4.9, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiPAM 1.7.0, FortiPAM 1.6 all versions, FortiPAM 1.5 all versions, FortiPAM 1.4 all versions, Fo
nvd
CVE-2021-26103P3HIGHCVSS 8.8≥ 1.2.0, ≤ 1.2.11≥ 2.0.0, ≤ 2.0.32021-12-08
CVE-2021-26103 [HIGH] CWE-345 CVE-2021-26103: An insufficient verification of data authenticity vulnerability (CWE-345) in the user interface of F An insufficient verification of data authenticity vulnerability (CWE-345) in the user interface of FortiProxy verison 2.0.3 and below, 1.2.11 and below and FortiGate verison 7.0.0, 6.4.6 and below, 6.2.9 and below of SSL VPN portal may allow a remote, unauthenticated attacker to conduct a cross-site request forgery (CSRF) attack . Only SSL VPN in web
nvd
CVE-2022-43953P3HIGHCVSS 7.8≥ 7.0.0, ≤ 7.0.7v7.2.0+2 more2023-06-13
CVE-2022-43953 [HIGH] CWE-134 CVE-2022-43953: A use of externally-controlled format string in Fortinet FortiOS version 7.2.0 through 7.2.4, FortiO A use of externally-controlled format string in Fortinet FortiOS version 7.2.0 through 7.2.4, FortiOS all versions 7.0, FortiOS all versions 6.4, FortiOS all versions 6.2, FortiProxy version 7.2.0 through 7.2.1, FortiProxy version 7.0.0 through 7.0.7 allows attacker to execute unauthorized code or commands via specially crafted commands.
nvd
CVE-2023-22639P3HIGHCVSS 7.8≥ 1.0.0, ≤ 1.0.7≥ 1.1.0, ≤ 1.1.6+7 more2023-06-13
CVE-2023-22639 [HIGH] CWE-787 CVE-2023-22639: A out-of-bounds write in Fortinet FortiOS version 7.2.0 through 7.2.3, FortiOS version 7.0.0 through A out-of-bounds write in Fortinet FortiOS version 7.2.0 through 7.2.3, FortiOS version 7.0.0 through 7.0.10, FortiOS version 6.4.0 through 6.4.12, FortiOS all versions 6.2, FortiOS all versions 6.0, FortiProxy version 7.2.0 through 7.2.2, FortiProxy version 7.0.0 through 7.0.8, FortiProxy all versions 2.0, FortiProxy all versions 1.2, FortiProxy all v
nvd
CVE-2022-29055P3HIGHCVSS 7.5≥ 1.2.6, < 1.2.13≥ 2.0.0, < 2.0.10+2 more2022-10-18
CVE-2022-29055 [HIGH] CWE-824 CVE-2022-29055: A access of uninitialized pointer in Fortinet FortiOS version 7.2.0, 7.0.0 through 7.0.5, 6.4.0 thro A access of uninitialized pointer in Fortinet FortiOS version 7.2.0, 7.0.0 through 7.0.5, 6.4.0 through 6.4.8, 6.2.0 through 6.2.10, 6.0.x, FortiProxy version 7.0.0 through 7.0.4, 2.0.0 through 2.0.9, 1.2.x allows a remote unauthenticated or authenticated attacker to crash the sslvpn daemon via an HTTP GET request.
nvd
CVE-2025-22254P3HIGHCVSS 7.2≥ 7.4.0, < 7.4.8≥ 7.6.0, < 7.6.2+2 more2025-06-10
CVE-2025-22254 [HIGH] CWE-269 CVE-2025-22254: An Improper Privilege Management vulnerability [CWE-269] vulnerability in Fortinet FortiOS 7.6.0 thr An Improper Privilege Management vulnerability [CWE-269] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1, FortiOS 7.4.0 through 7.4.6, FortiOS 7.2.0 through 7.2.10, FortiOS 7.0.0 through 7.0.16, FortiOS 6.4.0 through 6.4.15, FortiProxy 7.6.0 through 7.6.1, FortiProxy 7.4.0 through 7.4.7, FortiWeb 7.6.0 through 7.6.1, FortiWeb 7.4.0 through 7.4.6
nvd
CVE-2023-29180P3HIGHCVSS 7.5≥ 1.0.0, ≤ 1.0.7≥ 1.1.0, ≤ 1.1.6+7 more2024-02-22
CVE-2023-29180 [HIGH] CWE-476 CVE-2023-29180: A null pointer dereference in Fortinet FortiOS version 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6. A null pointer dereference in Fortinet FortiOS version 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through 6.4.12, 6.2.0 through 6.2.14, 6.0.0 through 6.0.16, FortiProxy 7.2.0 through 7.2.3, 7.0.0 through 7.0.10, 2.0.0 through 2.0.12, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6, 1.0.0 through 1.0.7 allows attacker to denial of service via specially
nvd
CVE-2021-26110P3HIGHCVSS 7.8≥ 1.0.0, ≤ 1.0.7≥ 1.1.0, ≤ 1.1.6+3 more2021-12-08
CVE-2021-26110 [HIGH] CVE-2021-26110: An improper access control vulnerability [CWE-284] in FortiOS autod daemon 7.0.0, 6.4.6 and below, 6 An improper access control vulnerability [CWE-284] in FortiOS autod daemon 7.0.0, 6.4.6 and below, 6.2.9 and below, 6.0.12 and below and FortiProxy 2.0.1 and below, 1.2.9 and below may allow an authenticated low-privileged attacker to escalate their privileges to super_admin via a specific crafted configuration of fabric automation CLI script and auto-script
nvd
CVE-2022-22299P3HIGHCVSS 7.8≥ 1.0.0, ≤ 1.0.7≥ 1.1.0, ≤ 1.1.6+4 more2022-08-05
CVE-2022-22299 [HIGH] CWE-134 CVE-2022-22299: A format string vulnerability [CWE-134] in the command line interpreter of FortiADC version 6.0.0 th A format string vulnerability [CWE-134] in the command line interpreter of FortiADC version 6.0.0 through 6.0.4, FortiADC version 6.1.0 through 6.1.5, FortiADC version 6.2.0 through 6.2.1, FortiProxy version 1.0.0 through 1.0.7, FortiProxy version 1.1.0 through 1.1.6, FortiProxy version 1.2.0 through 1.2.13, FortiProxy version 2.0.0 through 2.0.7, For
nvd
CVE-2018-13381P3HIGHCVSS 7.5≤ 1.2.8v2.0.02019-06-04
CVE-2018-13381 [HIGH] CWE-119 CVE-2018-13381: A buffer overflow vulnerability in Fortinet FortiOS 6.0.0 through 6.0.4, 5.6.0 through 5.6.7, 5.4 an A buffer overflow vulnerability in Fortinet FortiOS 6.0.0 through 6.0.4, 5.6.0 through 5.6.7, 5.4 and earlier versions and FortiProxy 2.0.0, 1.2.8 and earlier versions under SSL VPN web portal allows a non-authenticated attacker to perform a Denial-of-service attack via special craft message payloads.
nvd
Fortinet Fortiproxy vulnerabilities | cvebase