Fortinet Fortivoice vulnerabilities

24 known vulnerabilities affecting fortinet/fortivoice.

Total CVEs
24
CISA KEV
1
actively exploited
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL4HIGH10MEDIUM10

Vulnerabilities

Page 1 of 2
CVE-2025-55717MEDIUMCVSS 4.0≥ 7.0.0, < 7.0.7v7.2.0+1 more2026-03-10
CVE-2025-55717 [MEDIUM] CWE-312 CVE-2025-55717: A cleartext storage of sensitive information vulnerability [CWE-312] vulnerability in Fortinet Forti A cleartext storage of sensitive information vulnerability [CWE-312] vulnerability in Fortinet FortiMail 7.6.0 through 7.6.2, FortiMail 7.4.0 through 7.4.4, FortiMail 7.2.0 through 7.2.7, FortiMail 7.0.0 through 7.0.8, FortiRecorder 7.2.0 through 7.2.3, FortiRecorder 7.0 all versions, FortiRecorder 6.4 all versions, FortiVoice 7.2.0, FortiVoice 7.0.
cvelistv5nvd
CVE-2025-58693MEDIUMCVSS 6.5≥ 7.0.0, < 7.0.8≥ 7.2.0, < 7.2.3+2 more2026-01-13
CVE-2025-58693 [MEDIUM] CWE-22 CVE-2025-58693: An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in F An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiVoice 7.2.0 through 7.2.2, FortiVoice 7.0.0 through 7.0.7 allows a privileged attacker to delete files from the underlying filesystem via crafted HTTP or HTTPs requests.
cvelistv5nvd
CVE-2025-64156HIGHCVSS 7.2≥ 6.0.0, ≤ 6.0.12≥ 6.4.0, ≤ 6.4.11+2 more2025-12-09
CVE-2025-64156 [HIGH] CWE-89 CVE-2025-64156: An improper neutralization of special elements used in an sql command ('sql injection') vulnerabilit An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiVoice 7.2.0 through 7.2.2, FortiVoice 7.0.0 through 7.0.7, FortiVoice 6.4 all versions, FortiVoice 6.0 all versions may allow an authenticated privileged attacker to execute unauthorized code or commands via crafted requests
cvelistv5nvd
CVE-2025-60024HIGHCVSS 8.8≥ 7.0.0, < 7.0.8≥ 7.2.0, < 7.2.3+2 more2025-12-09
CVE-2025-60024 [HIGH] CWE-22 CVE-2025-60024: Multiple Improper Limitations of a Pathname to a Restricted Directory ('Path Traversal') vulnerabili Multiple Improper Limitations of a Pathname to a Restricted Directory ('Path Traversal') vulnerabilities [CWE-22] vulnerability in Fortinet FortiVoice 7.2.0 through 7.2.2, FortiVoice 7.0.0 through 7.0.7 may allow a privileged authenticated attacker to write arbitrary files via specifically HTTP or HTTPS commands
cvelistv5nvd
CVE-2025-58692HIGHCVSS 8.8≥ 7.0.0, < 7.0.8≥ 7.2.0, < 7.2.3+1 more2025-11-18
CVE-2025-58692 [HIGH] CWE-89 CVE-2025-58692: An improper neutralization of special elements used in an SQL Command ("SQL Injection") vulnerabilit An improper neutralization of special elements used in an SQL Command ("SQL Injection") vulnerability [CWE-89] vulnerability in Fortinet FortiVoice 7.2.0 through 7.2.2, FortiVoice 7.0.0 through 7.0.7 allows an authenticated attacker to execute unauthorized code or commands via specifically crafted HTTP or HTTPS requests.
cvelistv5nvd
CVE-2025-47856HIGHCVSS 7.2≥ 6.4.0, < 6.4.11≥ 7.0.0, < 7.0.7+3 more2025-10-14
CVE-2025-47856 [HIGH] CWE-78 CVE-2025-47856: Two improper neutralization of special elements used in an OS command ('OS Command Injection') vulne Two improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] in Fortinet FortiVoice version 7.2.0, 7.0.0 through 7.0.6 and before 6.4.10 allows a privileged attacker to execute arbitrary code or commands via crafted HTTP/HTTPS or CLI requests.
cvelistv5nvd
CVE-2024-47569MEDIUMCVSS 4.3≥ 6.0.7, < 6.4.10≥ 7.0.0, < 7.0.5+3 more2025-10-14
CVE-2024-47569 [MEDIUM] CWE-201 CVE-2024-47569: A insertion of sensitive information into sent data vulnerability in Fortinet FortiMail 7.4.0 throug A insertion of sensitive information into sent data vulnerability in Fortinet FortiMail 7.4.0 through 7.4.2, FortiMail 7.2.0 through 7.2.6, FortiMail 7.0 all versions, FortiManager 7.6.0 through 7.6.1, FortiManager 7.4.1 through 7.4.3, FortiManager Cloud 7.4.1 through 7.4.3, FortiNDR 7.6.0 through 7.6.1, FortiNDR 7.4.0 through 7.4.8, FortiNDR 7.2 al
cvelistv5nvd
CVE-2024-40588MEDIUMCVSS 4.4≥ 6.0.0, < 6.4.10≥ 7.0.0, < 7.0.5+3 more2025-08-12
CVE-2024-40588 [MEDIUM] CWE-23 CVE-2024-40588: Multiple relative path traversal vulnerabilities [CWE-23] vulnerability in Fortinet FortiCamera 2.1 Multiple relative path traversal vulnerabilities [CWE-23] vulnerability in Fortinet FortiCamera 2.1 all versions, FortiCamera 2.0.0, FortiCamera 1.1 all versions, FortiCamera 1.0 all versions, FortiMail 7.6.0 through 7.6.1, FortiMail 7.4.0 through 7.4.3, FortiMail 7.2 all versions, FortiMail 7.0 all versions, FortiMail 6.4 all versions, FortiNDR 7.6.0
cvelistv5nvd
CVE-2025-32756CRITICALCVSS 9.8KEV≥ 6.4.0, < 6.4.11≥ 7.0.0, < 7.0.7+3 more2025-05-13
CVE-2025-32756 [CRITICAL] CWE-121 CVE-2025-32756: A stack-based buffer overflow vulnerability [CWE-121] vulnerability in Fortinet FortiCamera 2.1.0 th A stack-based buffer overflow vulnerability [CWE-121] vulnerability in Fortinet FortiCamera 2.1.0 through 2.1.3, FortiCamera 2.0 all versions, FortiCamera 1.1 all versions, FortiMail 7.6.0 through 7.6.2, FortiMail 7.4.0 through 7.4.4, FortiMail 7.2.0 through 7.2.7, FortiMail 7.0.0 through 7.0.8, FortiNDR 7.6.0, FortiNDR 7.4.0 through 7.4.7, FortiN
cvelistv5nvd
CVE-2024-50565HIGHCVSS 7.5≥ 6.0.0, < 6.4.9≥ 7.0.0, < 7.0.3+3 more2025-04-08
CVE-2024-50565 [LOW] CWE-300 CVE-2024-50565: A improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in For A improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in Fortinet FortiOS version 7.4.0 through 7.4.3, 7.2.0 through 7.2.7, 7.0.0 through 7.0.14, 6.4.0 through 6.4.15 and 6.2.0 through 6.2.16, Fortinet FortiProxy version 7.4.0 through 7.4.2, 7.2.0 through 7.2.9, 7.0.0 through 7.0.15 and 2.0.0 through 2.0.14, Fort
cvelistv5nvd
CVE-2024-26013HIGHCVSS 7.5≥ 6.0.0, < 6.4.9≥ 7.0.0, < 7.0.32025-04-08
CVE-2024-26013 [HIGH] CWE-923 CVE-2024-26013: A improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in For A improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in Fortinet FortiOS version 7.4.0 through 7.4.4, 7.2.0 through 7.2.8, 7.0.0 through 7.0.15, 6.4.0 through 6.4.15 and before 6.2.16, Fortinet FortiProxy version 7.4.0 through 7.4.2, 7.2.0 through 7.2.9 and before 7.0.15, Fortinet FortiManager version 7.4.0 thr
nvd
CVE-2021-24008MEDIUMCVSS 5.3≥ 6.0.0, < 6.0.72025-03-28
CVE-2021-24008 [MEDIUM] CWE-200 CVE-2021-24008: An exposure of sensitive system information to an unauthorized control sphere vulnerability [CWE-497 An exposure of sensitive system information to an unauthorized control sphere vulnerability [CWE-497] in FortiDDoS version 5.4.0, version 5.3.2 and below, version 5.2.0, version 5.1.0, version 5.0.0, version 4.7.0, version 4.6.0, version 4.5.0, version 4.4.2 and below, FortiDDoS-CM version 5.3.0, version 5.2.0, version 5.1.0, version 5.0.0, version
nvd
CVE-2022-23439MEDIUMCVSS 6.1≥ 6.0.0, < 6.4.9≥ 7.0.0, ≤ 7.0.1+2 more2025-01-22
CVE-2022-23439 [MEDIUM] CWE-610 CVE-2022-23439: A externally controlled reference to a resource in another sphere vulnerability in Fortinet allows A externally controlled reference to a resource in another sphere vulnerability in Fortinet allows attacker to poison web caches via crafted HTTP requests, where the `Host` header points to an arbitrary webserver
cvelistv5nvd
CVE-2024-48885CRITICALCVSS 9.1≥ 6.0.0, ≤ 6.4.10≥ 7.0.0, ≤ 7.0.5+1 more2025-01-16
CVE-2024-48885 [MEDIUM] CWE-22 CVE-2024-48885: A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fo A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiRecorder 7.2.0 through 7.2.1, FortiRecorder 7.0.0 through 7.0.4, FortiVoice 7.0.0 through 7.0.4, FortiVoice 6.4.0 through 6.4.9, FortiVoice 6.0 all versions, FortiWeb 7.6.0, FortiWeb 7.4.0 through 7.4.4, FortiWeb 7.2 all versions, FortiWeb
cvelistv5nvd
CVE-2024-48884CRITICALCVSS 9.1≥ 6.0.0, ≤ 6.4.10≥ 7.0.0, ≤ 7.0.52025-01-14
CVE-2024-48884 [HIGH] CWE-22 CVE-2024-48884: A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fo A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiManager 7.6.0 through 7.6.1, FortiManager 7.4.1 through 7.4.3, FortiManager Cloud 7.4.1 through 7.4.3, FortiOS 7.6.0, FortiOS 7.4.0 through 7.4.4, FortiOS 7.2.0 through 7.2.9, FortiOS 7.0.0 through 7.0.15, FortiOS 6.4.0 through 6.4.15, FortiP
nvd
CVE-2023-37931HIGHCVSS 8.8≥ 6.0.0, < 6.4.9≥ 7.0.0, < 7.0.2+3 more2025-01-14
CVE-2023-37931 [HIGH] CWE-89 CVE-2023-37931: An improper neutralization of special elements used in an sql command ('sql injection') vulnerabilit An improper neutralization of special elements used in an sql command ('sql injection') vulnerability [CWE-88] in FortiVoice Entreprise version 7.0.0 through 7.0.1 and before 6.4.8 allows an authenticated attacker to perform a blind sql injection attack via sending crafted HTTP or HTTPS requests
cvelistv5nvd
CVE-2024-40587MEDIUMCVSS 6.7≥ 6.0.0, < 6.4.10≥ 7.0.0, < 7.0.5+3 more2025-01-14
CVE-2024-40587 [MEDIUM] CWE-78 CVE-2024-40587: An improper neutralization of special elements used in an OS command ('OS Command Injection') vulner An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiVoice version 7.0.0 through 7.0.4 and before 6.4.9 allows an authenticated privileged attacker to execute unauthorized code or commands via crafted CLI requests.
cvelistv5nvd
CVE-2023-40720HIGHCVSS 7.1≥ 6.0.0, ≤ 6.0.12≥ 6.4.0, ≤ 6.4.8+3 more2024-05-14
CVE-2023-40720 [HIGH] CWE-639 CVE-2023-40720: An authorization bypass through user-controlled key vulnerability [CWE-639] in FortiVoiceEntreprise An authorization bypass through user-controlled key vulnerability [CWE-639] in FortiVoiceEntreprise version 7.0.0 through 7.0.1 and before 6.4.8 allows an authenticated attacker to read the SIP configuration of other users via crafted HTTP or HTTPS requests.
cvelistv5nvd
CVE-2023-37932MEDIUMCVSS 6.5≥ 6.0.0, ≤ 6.0.12≥ 6.4.0, < 6.4.8+2 more2024-01-10
CVE-2023-37932 [MEDIUM] CWE-22 CVE-2023-37932: An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability [CWE An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability [CWE-22] in FortiVoiceEntreprise version 7.0.0 and before 6.4.7 allows an authenticated attacker to read arbitrary files from the system via sending crafted HTTP or HTTPS requests
cvelistv5nvd
CVE-2022-27488HIGHCVSS 8.8≥ 6.0.0, ≤ 6.0.11≥ 6.4.0, ≤ 6.4.72023-12-13
CVE-2022-27488 [HIGH] CWE-352 CVE-2022-27488: A cross-site request forgery (CSRF) in Fortinet FortiVoiceEnterprise version 6.4.x, 6.0.x, FortiSwit A cross-site request forgery (CSRF) in Fortinet FortiVoiceEnterprise version 6.4.x, 6.0.x, FortiSwitch version 7.0.0 through 7.0.4, 6.4.0 through 6.4.10, 6.2.0 through 6.2.7, 6.0.x, FortiMail version 7.0.0 through 7.0.3, 6.4.0 through 6.4.6, 6.2.x, 6.0.x FortiRecorder version 6.4.0 through 6.4.2, 6.0.x, 2.7.x, 2.6.x, FortiNDR version 1.x.x allows a re
cvelistv5nvd