Fortinet Inc Fortios vulnerabilities
8 known vulnerabilities affecting fortinet_inc/fortios.
Total CVEs
8
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM7
Vulnerabilities
Page 1 of 1
CVE-2018-9194MEDIUMCVSS 5.9v6.0.1, 6.0.0v5.4.9, 5.4.8, 5.4.7, 5.4.62018-09-05
CVE-2018-9194 [MEDIUM] CWE-203 CVE-2018-9194: A plaintext recovery of encrypted messages or a Man-in-the-middle (MiTM) attack on RSA PKCS #1 v1.5
A plaintext recovery of encrypted messages or a Man-in-the-middle (MiTM) attack on RSA PKCS #1 v1.5 encryption may be possible without knowledge of the server's private key. Fortinet FortiOS 5.4.6 to 5.4.9, 6.0.0 and 6.0.1 are vulnerable by such attack under VIP SSL feature when CPx being used.
cvelistv5nvd
CVE-2018-9192MEDIUMCVSS 5.9v6.0.1, 6.0.0v5.4.9, 5.4.8, 5.4.7, 5.4.62018-09-05
CVE-2018-9192 [MEDIUM] CWE-203 CVE-2018-9192: A plaintext recovery of encrypted messages or a Man-in-the-middle (MiTM) attack on RSA PKCS #1 v1.5
A plaintext recovery of encrypted messages or a Man-in-the-middle (MiTM) attack on RSA PKCS #1 v1.5 encryption may be possible without knowledge of the server's private key. Fortinet FortiOS 5.4.6 to 5.4.9, 6.0.0 and 6.0.1 are vulnerable by such attack under SSL Deep Inspection feature when CPx being used.
cvelistv5nvd
CVE-2017-14185MEDIUMCVSS 5.3v5.6.0 to 5.6.2v5.4.0 to 5.4.8+1 more2018-05-25
CVE-2017-14185 [MEDIUM] CWE-200 CVE-2017-14185: An Information Disclosure vulnerability in Fortinet FortiOS 5.6.0 to 5.6.2, 5.4.0 to 5.4.8 and 5.2 a
An Information Disclosure vulnerability in Fortinet FortiOS 5.6.0 to 5.6.2, 5.4.0 to 5.4.8 and 5.2 all versions allows SSL VPN web portal users to access internal FortiOS configuration information (eg:addresses) via specifically crafted URLs inside the SSL-VPN web portal.
cvelistv5nvd
CVE-2017-14187MEDIUMCVSS 6.2v5.6.0 to 5.6.2v5.4.0 to 5.4.8+1 more2018-05-24
CVE-2017-14187 [MEDIUM] CWE-269 CVE-2017-14187: A local privilege escalation and local code execution vulnerability in Fortinet FortiOS 5.6.0 to 5.6
A local privilege escalation and local code execution vulnerability in Fortinet FortiOS 5.6.0 to 5.6.2, 5.4.0 to 5.4.8, and 5.2 and below versions allows attacker to execute unauthorized binary program contained on an USB drive plugged into a FortiGate via linking the aforementioned binary program to a command that is allowed to be run by the fnsysc
cvelistv5nvd
CVE-2017-14190MEDIUMCVSS 6.1v5.6.0 to 5.6.2v5.4.0 to 5.4.7+1 more2018-01-29
CVE-2017-14190 [MEDIUM] CWE-79 CVE-2017-14190: A Cross-site Scripting vulnerability in Fortinet FortiOS 5.6.0 to 5.6.2, 5.4.0 to 5.4.7, 5.2 and ear
A Cross-site Scripting vulnerability in Fortinet FortiOS 5.6.0 to 5.6.2, 5.4.0 to 5.4.7, 5.2 and earlier, allows attacker to inject arbitrary web script or HTML via maliciously crafted "Host" header in user HTTP requests.
cvelistv5nvd
CVE-2017-7738HIGHCVSS 7.2v5.6.0 to 5.6.2v5.4.0 to 5.4.5+1 more2017-12-13
CVE-2017-7738 [HIGH] CWE-200 CVE-2017-7738: An Information Disclosure vulnerability in Fortinet FortiOS 5.6.0 to 5.6.2, 5.4.0 to 5.4.5, 5.2 and
An Information Disclosure vulnerability in Fortinet FortiOS 5.6.0 to 5.6.2, 5.4.0 to 5.4.5, 5.2 and below versions allow an admin user with super_admin privileges to view the current SSL VPN web portal session info which may contains user credentials through the fnsysctl CLI command.
cvelistv5nvd
CVE-2017-14186MEDIUMCVSS 5.4PoCv5.6.0 to 5.6.2v5.4.0 to 5.4.6+2 more2017-11-29
CVE-2017-14186 [MEDIUM] CWE-79 CVE-2017-14186: A Cross-site Scripting (XSS) vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.7, 5.4 a
A Cross-site Scripting (XSS) vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.7, 5.4 and below versions under SSL VPN web portal allows a remote user to inject arbitrary web script or HTML in the context of the victim's browser via the login redir parameter. An URL Redirection attack may also be feasible by injecting an external URL via
cvelistv5nvd
CVE-2017-7739MEDIUMCVSS 6.1v5.6.0v5.4.5, 5.4.4, 5.4.3, 5.4.2, 5.4.1, 5.4.0+1 more2017-11-13
CVE-2017-7739 [MEDIUM] CWE-79 CVE-2017-7739: A reflected Cross-site Scripting (XSS) vulnerability in web proxy disclaimer response web pages in F
A reflected Cross-site Scripting (XSS) vulnerability in web proxy disclaimer response web pages in Fortinet FortiOS 5.6.0, 5.4.0 to 5.4.5, 5.2.0 to 5.2.11 allows an unauthenticated attacker to inject arbitrary web script or HTML in the context of the victim's browser via sending a maliciously crafted URL to the victim.
cvelistv5nvd