CVE-2024-46670
- EPSS 0.19%
- Veröffentlicht 14.01.2025 14:15:32
- Zuletzt bearbeitet 31.01.2025 16:12:16
An Out-of-bounds Read vulnerability [CWE-125] in FortiOS version 7.6.0, version 7.4.4 and below, version 7.2.9 and below and FortiSASE FortiOS tenant version 24.3.b IPsec IKE service may allow an unauthenticated remote attacker to trigger memory cons...
CVE-2024-48884
- EPSS 0.54%
- Veröffentlicht 14.01.2025 14:15:32
- Zuletzt bearbeitet 08.08.2025 16:00:27
A improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiManager versions 7.6.0 through 7.6.1, 7.4.1 through 7.4.3, FortiOS versions 7.6.0, 7.4.0 through 7.4.4, 7.2.5 through 7.2.9, 7.0.0 through 7.0.15, 6.4.0...
CVE-2024-46665
- EPSS 0.08%
- Veröffentlicht 14.01.2025 14:15:31
- Zuletzt bearbeitet 31.01.2025 16:09:23
An insertion of sensitive information into sent data vulnerability [CWE-201] in FortiOS 7.6.0, 7.4.0 through 7.4.4 may allow an attacker in a man-in-the-middle position to retrieve the RADIUS accounting server shared secret via intercepting accountin...
CVE-2024-46666
- EPSS 0.15%
- Veröffentlicht 14.01.2025 14:15:31
- Zuletzt bearbeitet 22.07.2025 21:26:43
An allocation of resources without limits or throttling [CWE-770] vulnerability in FortiOS versions 7.6.0, versions 7.4.4 through 7.4.0, 7.2 all versions, 7.0 all versions, 6.4 all versions may allow a remote unauthenticated attacker to prevent acces...
CVE-2024-46668
- EPSS 0.3%
- Veröffentlicht 14.01.2025 14:15:31
- Zuletzt bearbeitet 31.01.2025 16:10:13
An allocation of resources without limits or throttling vulnerability [CWE-770] in FortiOS versions 7.4.0 through 7.4.4, versions 7.2.0 through 7.2.8, versions 7.0.0 through 7.0.15, and versions 6.4.0 through 6.4.15 may allow an unauthenticated remot...
CVE-2024-36504
- EPSS 0.24%
- Veröffentlicht 14.01.2025 14:15:30
- Zuletzt bearbeitet 22.07.2025 21:26:23
An out-of-bounds read vulnerability [CWE-125] in FortiOS SSLVPN web portal versions 7.4.0 through 7.4.4, versions 7.2.0 through 7.2.8, 7.0 all verisons, and 6.4 all versions may allow an authenticated attacker to perform a denial of service on the SS...
CVE-2023-42785
- EPSS 0.52%
- Veröffentlicht 14.01.2025 14:15:27
- Zuletzt bearbeitet 17.01.2025 20:42:36
A null pointer dereference in FortiOS versions 7.4.0 through 7.4.1, 7.2.0 through 7.2.5, 7.0 all versions, 6.4 all versions , 6.2 all versions and 6.0 all versions allows attacker to trigger a denial of service via a crafted http request.
CVE-2023-42786
- EPSS 0.52%
- Veröffentlicht 14.01.2025 14:15:27
- Zuletzt bearbeitet 17.01.2025 20:42:31
A null pointer dereference in FortiOS versions 7.4.0 through 7.4.1, 7.2.0 through 7.2.5, 7.0 all versions, 6.4 all versions , 6.2 all versions and 6.0 all versions allows attacker to trigger a denial of service via a crafted http request.
CVE-2023-46715
- EPSS 0.05%
- Veröffentlicht 14.01.2025 14:15:27
- Zuletzt bearbeitet 31.01.2025 17:20:44
An origin validation error [CWE-346] vulnerability in Fortinet FortiOS IPSec VPN version 7.4.0 through 7.4.1 and version 7.2.6 and below allows an authenticated IPSec VPN user with dynamic IP addressing to send (but not receive) packets spoofing the...
CVE-2020-12820
- EPSS 0.62%
- Veröffentlicht 19.12.2024 11:15:05
- Zuletzt bearbeitet 21.01.2025 20:42:17
Under non-default configuration, a stack-based buffer overflow in FortiOS version 6.0.10 and below, version 5.6.12 and below may allow a remote attacker authenticated to the SSL VPN to crash the FortiClient NAC daemon (fcnacd) and potentially execute...