Fortinet Fortiproxy vulnerabilities
130 known vulnerabilities affecting fortinet/fortiproxy.
Total CVEs
130
CISA KEV
12
actively exploited
Public exploits
10
Exploited in wild
14
Severity breakdown
CRITICAL17HIGH39MEDIUM71LOW3
Vulnerabilities
Page 7 of 7
CVE-2021-43074P4MEDIUMCVSS 4.3≥ 1.0.0, < 2.0.8≥ 7.0.0, < 7.0.2+5 more2023-02-16
CVE-2021-43074 [MEDIUM] CWE-347 CVE-2021-43074: An improper verification of cryptographic signature vulnerability [CWE-347] in FortiWeb 6.4 all vers
An improper verification of cryptographic signature vulnerability [CWE-347] in FortiWeb 6.4 all versions, 6.3.16 and below, 6.2 all versions, 6.1 all versions, 6.0 all versions; FortiOS 7.0.3 and below, 6.4.8 and below, 6.2 all versions, 6.0 all versions; FortiSwitch 7.0.3 and below, 6.4.10 and below, 6.2 all versions, 6.0 all versions; FortiProxy 7
nvd
CVE-2021-22128P4MEDIUMCVSS 4.3≤ 1.2.9v2.0.02021-03-04
CVE-2021-22128 [MEDIUM] CVE-2021-22128: An improper access control vulnerability in FortiProxy SSL VPN portal 2.0.0, 1.2.9 and below version
An improper access control vulnerability in FortiProxy SSL VPN portal 2.0.0, 1.2.9 and below versions may allow an authenticated, remote attacker to access internal service such as the ZebOS Shell on the FortiProxy appliance through the Quick Connection functionality.
nvd
CVE-2023-29178P4MEDIUMCVSS 4.3≥ 1.1.0, ≤ 1.1.6≥ 1.2.0, ≤ 1.2.13+7 more2023-06-13
CVE-2023-29178 [MEDIUM] CWE-824 CVE-2023-29178: A access of uninitialized pointer vulnerability [CWE-824] in Fortinet FortiProxy version 7.2.0 thro
A access of uninitialized pointer vulnerability [CWE-824] in Fortinet FortiProxy version 7.2.0 through 7.2.3 and before 7.0.9 and FortiOS version 7.2.0 through 7.2.4 and before 7.0.11 allows an authenticated attacker to repetitively crash the httpsd process via crafted HTTP or HTTPS requests.
nvd
CVE-2024-23111P4MEDIUMCVSS 4.8≥ 7.0.0, < 7.0.15≥ 7.2.0, < 7.2.9+4 more2024-06-11
CVE-2024-23111 [MEDIUM] CWE-79 CVE-2024-23111: An improper neutralization of input during web page Generation ('Cross-site Scripting') vulnerabilit
An improper neutralization of input during web page Generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiOS version 7.4.3 and below, 7.2 all versions, 7.0 all versions and FortiProxy version 7.4.2 and below, 7.2 all versions, 7.0 all versions reboot page may allow a remote privileged attacker with super-admin access to execute JavaScrip
nvd
CVE-2021-43206P4MEDIUMCVSS 4.3≥ 2.0.0, < 2.0.9≥ 7.0.0, < 7.0.22022-05-04
CVE-2021-43206 [MEDIUM] CWE-209 CVE-2021-43206: A server-generated error message containing sensitive information in Fortinet FortiOS 7.0.0 through
A server-generated error message containing sensitive information in Fortinet FortiOS 7.0.0 through 7.0.3, 6.4.0 through 6.4.8, 6.2.x, 6.0.x and FortiProxy 7.0.0 through 7.0.1, 2.0.x allows malicious webservers to retrieve a web proxy's client username and IP via same origin HTTP requests triggering proxy-generated HTTP status codes pages.
nvd
CVE-2021-42755P4MEDIUMCVSS 4.3≥ 1.0.0, ≤ 1.0.7≥ 1.1.0, ≤ 1.1.6+3 more2022-07-18
CVE-2021-42755 [MEDIUM] CWE-190 CVE-2021-42755: An integer overflow / wraparound vulnerability [CWE-190] in FortiSwitch 7.0.2 and below, 6.4.9 and b
An integer overflow / wraparound vulnerability [CWE-190] in FortiSwitch 7.0.2 and below, 6.4.9 and below, 6.2.x, 6.0.x; FortiRecorder 6.4.2 and below, 6.0.10 and below; FortiOS 7.0.2 and below, 6.4.8 and below, 6.2.10 and below, 6.0.x; FortiProxy 7.0.0, 2.0.6 and below, 1.2.x, 1.1.x, 1.0.x; FortiVoiceEnterprise 6.4.3 and below, 6.0.10 and below dhcp
nvd
CVE-2022-41327P4MEDIUMCVSS 4.4≥ 7.0.0, ≤ 7.0.7v7.2.0+2 more2023-06-13
CVE-2022-41327 [MEDIUM] CWE-319 CVE-2022-41327: A cleartext transmission of sensitive information vulnerability [CWE-319] in Fortinet FortiOS versio
A cleartext transmission of sensitive information vulnerability [CWE-319] in Fortinet FortiOS version 7.2.0 through 7.2.4, 7.0.0 through 7.0.8, FortiProxy version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.8 allows an authenticated attacker with readonly superadmin privileges to intercept traffic in order to obtain other adminstrators cookies via dia
nvd
CVE-2022-42474P4LOWCVSS 2.7≥ 1.0.0, ≤ 1.0.7≥ 1.1.0, ≤ 1.1.6+6 more2023-06-13
CVE-2022-42474 [LOW] CWE-23 CVE-2022-42474: A relative path traversal vulnerability [CWE-23] in Fortinet FortiOS version 7.2.0 through 7.2.3, ve
A relative path traversal vulnerability [CWE-23] in Fortinet FortiOS version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.9 and before 6.4.12, FortiProxy version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.7, FortiSwitchManager version 7.2.0 through 7.2.1 and before 7.0.1 allows an privileged attacker to delete arbitrary directories from the filesystem
nvd
CVE-2022-29054P4LOWCVSS 3.3≥ 1.1.0, ≤ 1.1.6≥ 1.2.0, ≤ 1.2.13+6 more2023-02-16
CVE-2022-29054 [LOW] CWE-329 CVE-2022-29054: A missing cryptographic steps vulnerability [CWE-325] in the functions that encrypt the DHCP and DNS
A missing cryptographic steps vulnerability [CWE-325] in the functions that encrypt the DHCP and DNS keys in Fortinet FortiOS version 7.2.0, 7.0.0 through 7.0.5, 6.4.0 through 6.4.9, 6.2.x and 6.0.x may allow an attacker in possession of the encrypted key to decipher it.
nvd
CVE-2023-29184P4LOWCVSS 2.3≥ 1.1.0, < 7.0.9≥ 7.2.0, < 7.2.3+5 more2025-06-10
CVE-2023-29184 [LOW] CWE-459 CVE-2023-29184: An incomplete cleanup vulnerability [CWE-459] in FortiOS 7.2 all versions and before & FortiProxy v
An incomplete cleanup vulnerability [CWE-459] in FortiOS 7.2 all versions and before & FortiProxy version 7.2.0 through 7.2.2 and before 7.0.8 allows a VDOM privileged attacker to add SSH key files on the system silently via crafted CLI requests.
nvd
← Previous7 / 7