Fortinet Fortirecorder vulnerabilities
16 known vulnerabilities affecting fortinet/fortirecorder.
Total CVEs
16
CISA KEV
1
actively exploited
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH3MEDIUM10
Vulnerabilities
Page 1 of 1
CVE-2025-55717MEDIUMCVSS 4.0≥ 6.4.0, < 7.2.4≥ 7.2.0, ≤ 7.2.3+2 more2026-03-10
CVE-2025-55717 [MEDIUM] CWE-312 CVE-2025-55717: A cleartext storage of sensitive information vulnerability [CWE-312] vulnerability in Fortinet Forti
A cleartext storage of sensitive information vulnerability [CWE-312] vulnerability in Fortinet FortiMail 7.6.0 through 7.6.2, FortiMail 7.4.0 through 7.4.4, FortiMail 7.2.0 through 7.2.7, FortiMail 7.0.0 through 7.0.8, FortiRecorder 7.2.0 through 7.2.3, FortiRecorder 7.0 all versions, FortiRecorder 6.4 all versions, FortiVoice 7.2.0, FortiVoice 7.0.
cvelistv5nvd
CVE-2024-47569MEDIUMCVSS 4.3≥ 7.0.0, < 7.0.5≥ 7.2.0, < 7.2.2+2 more2025-10-14
CVE-2024-47569 [MEDIUM] CWE-201 CVE-2024-47569: A insertion of sensitive information into sent data vulnerability in Fortinet FortiMail 7.4.0 throug
A insertion of sensitive information into sent data vulnerability in Fortinet FortiMail 7.4.0 through 7.4.2, FortiMail 7.2.0 through 7.2.6, FortiMail 7.0 all versions, FortiManager 7.6.0 through 7.6.1, FortiManager 7.4.1 through 7.4.3, FortiManager Cloud 7.4.1 through 7.4.3, FortiNDR 7.6.0 through 7.6.1, FortiNDR 7.4.0 through 7.4.8, FortiNDR 7.2 al
cvelistv5nvd
CVE-2024-40588MEDIUMCVSS 4.4≥ 6.4.0, < 7.0.5≥ 7.2.0, < 7.2.2+3 more2025-08-12
CVE-2024-40588 [MEDIUM] CWE-23 CVE-2024-40588: Multiple relative path traversal vulnerabilities [CWE-23] vulnerability in Fortinet FortiCamera 2.1
Multiple relative path traversal vulnerabilities [CWE-23] vulnerability in Fortinet FortiCamera 2.1 all versions, FortiCamera 2.0.0, FortiCamera 1.1 all versions, FortiCamera 1.0 all versions, FortiMail 7.6.0 through 7.6.1, FortiMail 7.4.0 through 7.4.3, FortiMail 7.2 all versions, FortiMail 7.0 all versions, FortiMail 6.4 all versions, FortiNDR 7.6.0
cvelistv5nvd
CVE-2025-32756CRITICALCVSS 9.8KEV≥ 6.4.0, < 6.4.6≥ 7.0.0, < 7.0.6+4 more2025-05-13
CVE-2025-32756 [CRITICAL] CWE-121 CVE-2025-32756: A stack-based buffer overflow vulnerability [CWE-121] vulnerability in Fortinet FortiCamera 2.1.0 th
A stack-based buffer overflow vulnerability [CWE-121] vulnerability in Fortinet FortiCamera 2.1.0 through 2.1.3, FortiCamera 2.0 all versions, FortiCamera 1.1 all versions, FortiMail 7.6.0 through 7.6.2, FortiMail 7.4.0 through 7.4.4, FortiMail 7.2.0 through 7.2.7, FortiMail 7.0.0 through 7.0.8, FortiNDR 7.6.0, FortiNDR 7.4.0 through 7.4.7, FortiN
cvelistv5nvd
CVE-2021-24008MEDIUMCVSS 5.3≥ 6.0.0, < 6.0.42025-03-28
CVE-2021-24008 [MEDIUM] CWE-200 CVE-2021-24008: An exposure of sensitive system information to an unauthorized control sphere vulnerability [CWE-497
An exposure of sensitive system information to an unauthorized control sphere vulnerability [CWE-497] in FortiDDoS version 5.4.0, version 5.3.2 and below, version 5.2.0, version 5.1.0, version 5.0.0, version 4.7.0, version 4.6.0, version 4.5.0, version 4.4.2 and below, FortiDDoS-CM version 5.3.0, version 5.2.0, version 5.1.0, version 5.0.0, version
nvd
CVE-2022-23439MEDIUMCVSS 6.1≥ 6.0.0, < 6.0.11≥ 6.4.0, < 6.4.3+4 more2025-01-22
CVE-2022-23439 [MEDIUM] CWE-610 CVE-2022-23439: A externally controlled reference to a resource in another sphere vulnerability in Fortinet allows
A externally controlled reference to a resource in another sphere vulnerability in Fortinet allows attacker to poison web caches via crafted HTTP requests, where the `Host` header points to an arbitrary webserver
cvelistv5nvd
CVE-2024-48885CRITICALCVSS 9.1≥ 7.0.0, < 7.0.5≥ 7.2.0, < 7.2.2+2 more2025-01-16
CVE-2024-48885 [MEDIUM] CWE-22 CVE-2024-48885: A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fo
A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiRecorder 7.2.0 through 7.2.1, FortiRecorder 7.0.0 through 7.0.4, FortiVoice 7.0.0 through 7.0.4, FortiVoice 6.4.0 through 6.4.9, FortiVoice 6.0 all versions, FortiWeb 7.6.0, FortiWeb 7.4.0 through 7.4.4, FortiWeb 7.2 all versions, FortiWeb
cvelistv5nvd
CVE-2024-48884CRITICALCVSS 9.1≥ 7.0.0, < 7.0.5≥ 7.2.0, < 7.2.22025-01-14
CVE-2024-48884 [HIGH] CWE-22 CVE-2024-48884: A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fo
A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiManager 7.6.0 through 7.6.1, FortiManager 7.4.1 through 7.4.3, FortiManager Cloud 7.4.1 through 7.4.3, FortiOS 7.6.0, FortiOS 7.4.0 through 7.4.4, FortiOS 7.2.0 through 7.2.9, FortiOS 7.0.0 through 7.0.15, FortiOS 6.4.0 through 6.4.15, FortiP
nvd
CVE-2024-47566MEDIUMCVSS 6.0≥ 6.4.0, < 7.0.5≥ 7.2.0, < 7.2.2+3 more2025-01-14
CVE-2024-47566 [MEDIUM] CWE-22 CVE-2024-47566: A improper limitation of a pathname to a restricted directory ('path traversal') [CWE-23] in Fortine
A improper limitation of a pathname to a restricted directory ('path traversal') [CWE-23] in Fortinet FortiRecorder version 7.2.0 through 7.2.1 and before 7.0.4 allows a privileged attacker to delete files from the underlying filesystem via crafted CLI requests.
cvelistv5nvd
CVE-2024-46664MEDIUMCVSS 4.9≥ 6.4.0, < 7.0.5≥ 7.2.0, < 7.2.2+3 more2025-01-14
CVE-2024-46664 [MEDIUM] CWE-23 CVE-2024-46664: A relative path traversal in Fortinet FortiRecorder [CWE-23] version 7.2.0 through 7.2.1 and before
A relative path traversal in Fortinet FortiRecorder [CWE-23] version 7.2.0 through 7.2.1 and before 7.0.4 allows a privileged attacker to read files from the underlying filesystem via crafted HTTP or HTTPs requests.
cvelistv5nvd
CVE-2024-56497MEDIUMCVSS 6.7≥ 6.4.0, < 6.4.5≥ 7.0.0, < 7.0.2+2 more2025-01-14
CVE-2024-56497 [MEDIUM] CWE-78 CVE-2024-56497: An improper neutralization of special elements used in an os command ('os command injection') in For
An improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiMail versions 7.2.0 through 7.2.4 and 7.0.0 through 7.0.6 and 6.4.0 through 6.4.7, FortiRecorder versions 7.0.0 and 6.4.0 through 6.4.4 allows attacker to execute unauthorized code or commands via the CLI.
cvelistv5nvd
CVE-2022-27488HIGHCVSS 8.8≥ 2.6.0, ≤ 2.6.3≥ 2.7.0, ≤ 2.7.7+2 more2023-12-13
CVE-2022-27488 [HIGH] CWE-352 CVE-2022-27488: A cross-site request forgery (CSRF) in Fortinet FortiVoiceEnterprise version 6.4.x, 6.0.x, FortiSwit
A cross-site request forgery (CSRF) in Fortinet FortiVoiceEnterprise version 6.4.x, 6.0.x, FortiSwitch version 7.0.0 through 7.0.4, 6.4.0 through 6.4.10, 6.2.0 through 6.2.7, 6.0.x, FortiMail version 7.0.0 through 7.0.3, 6.4.0 through 6.4.6, 6.2.x, 6.0.x FortiRecorder version 6.4.0 through 6.4.2, 6.0.x, 2.7.x, 2.6.x, FortiNDR version 1.x.x allows a re
cvelistv5nvd
CVE-2022-41333HIGHCVSS 7.5PoC≥ 6.4.0, ≤ 6.4.3≥ 6.0.0, ≤ 6.0.112023-03-07
CVE-2022-41333 [HIGH] CWE-400 CVE-2022-41333: An uncontrolled resource consumption vulnerability [CWE-400] in FortiRecorder version 6.4.3 and belo
An uncontrolled resource consumption vulnerability [CWE-400] in FortiRecorder version 6.4.3 and below, 6.0.11 and below login authentication mechanism may allow an unauthenticated attacker to make the device unavailable via crafted GET requests.
cvelistv5nvd
CVE-2022-22297MEDIUMCVSS 5.5≥ 6.4.0, ≤ 6.4.3≥ 6.0.0, ≤ 6.0.12+1 more2023-03-07
CVE-2022-22297 [MEDIUM] CWE-792 CVE-2022-22297: An incomplete filtering of one or more instances of special elements vulnerability [CWE-792] in the
An incomplete filtering of one or more instances of special elements vulnerability [CWE-792] in the command line interpreter of FortiWeb version 6.4.0 through 6.4.1, FortiWeb version 6.3.0 through 6.3.17, FortiWeb all versions 6.2, FortiWeb all versions 6.1, FortiWeb all versions 6.0, FortiRecorder version 6.4.0 through 6.4.3, FortiRecorder all versi
cvelistv5nvd
CVE-2021-36193HIGHCVSS 7.2≥ 6.4.0, ≤ 6.4.2≥ 6.0.0, ≤ 6.0.10+2 more2022-02-02
CVE-2021-36193 [MEDIUM] CWE-121 CVE-2021-36193: Multiple stack-based buffer overflows in the command line interpreter of FortiWeb before 6.4.2 may a
Multiple stack-based buffer overflows in the command line interpreter of FortiWeb before 6.4.2 may allow an authenticated attacker to achieve arbitrary code execution via specially crafted commands.
cvelistv5nvd
CVE-2021-42757MEDIUMCVSS 6.7≥ 6.4.0, ≤ 6.4.2≥ 6.0.0, ≤ 6.0.10+2 more2021-12-08
CVE-2021-42757 [MEDIUM] CWE-120 CVE-2021-42757: A buffer overflow [CWE-121] in the TFTP client library of FortiOS before 6.4.7 and FortiOS 7.0.0 thr
A buffer overflow [CWE-121] in the TFTP client library of FortiOS before 6.4.7 and FortiOS 7.0.0 through 7.0.2, may allow an authenticated local attacker to achieve arbitrary code execution via specially crafted command line arguments.
cvelistv5nvd