CVE-2024-21762
- EPSS 92.65%
- Veröffentlicht 09.02.2024 09:15:08
- Zuletzt bearbeitet 29.11.2024 15:23:32
A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, 6.0.0 through 6.0.17, FortiProxy versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 t...
CVE-2023-44250
- EPSS 0.13%
- Veröffentlicht 10.01.2024 18:15:46
- Zuletzt bearbeitet 21.11.2024 08:25:31
An improper privilege management vulnerability [CWE-269] in a Fortinet FortiOS HA cluster version 7.4.0 through 7.4.1 and 7.2.5 and in a FortiProxy HA cluster version 7.4.0 through 7.4.1 allows an authenticated attacker to perform elevated actions vi...
CVE-2023-47536
- EPSS 0.05%
- Veröffentlicht 13.12.2023 08:15:50
- Zuletzt bearbeitet 21.11.2024 08:30:24
An improper access control vulnerability [CWE-284] in FortiOS version 7.2.0, version 7.0.13 and below, version 6.4.14 and below and FortiProxy version 7.2.3 and below, version 7.0.9 and below, version 2.0.12 and below may allow a remote unauthenticat...
CVE-2023-41678
- EPSS 0.28%
- Veröffentlicht 13.12.2023 07:15:17
- Zuletzt bearbeitet 21.11.2024 08:21:28
A double free in Fortinet FortiOS versions 7.0.0 through 7.0.5, FortiPAM version 1.0.0 through 1.0.3, 1.1.0 through 1.1.1 allows attacker to execute unauthorized code or commands via specifically crafted request.
CVE-2023-36639
- EPSS 0.17%
- Veröffentlicht 13.12.2023 07:15:12
- Zuletzt bearbeitet 21.11.2024 08:10:09
A use of externally-controlled format string in Fortinet FortiProxy versions 7.2.0 through 7.2.4, 7.0.0 through 7.0.10, FortiOS versions 7.4.0, 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through 6.4.12, 6.2.0 through 6.2.15, 6.0.0 through 6.0.1...
CVE-2023-36641
- EPSS 0.47%
- Veröffentlicht 14.11.2023 18:15:49
- Zuletzt bearbeitet 21.11.2024 08:10:09
A numeric truncation error in Fortinet FortiProxy version 7.2.0 through 7.2.4, FortiProxy version 7.0.0 through 7.0.10, FortiProxy 2.0 all versions, FortiProxy 1.2 all versions, FortiProxy 1.1, all versions, FortiProxy 1.0 all versions, FortiOS vers...
CVE-2023-28002
- EPSS 0.01%
- Veröffentlicht 14.11.2023 18:15:29
- Zuletzt bearbeitet 21.11.2024 07:53:54
An improper validation of integrity check value vulnerability [CWE-354] in FortiOS 7.2.0 through 7.2.3, 7.0.0 through 7.0.12, 6.4 all versions, 6.2 all versions, 6.0 all versions and VMs may allow a local attacker with admin privileges to boot a mali...
CVE-2023-36555
- EPSS 0.12%
- Veröffentlicht 10.10.2023 17:15:12
- Zuletzt bearbeitet 21.11.2024 08:09:55
An improper neutralization of script-related html tags in a web page (basic xss) in Fortinet FortiOS 7.2.0 - 7.2.4 allows an attacker to execute unauthorized code or commands via the SAML and Security Fabric components.
CVE-2023-37935
- EPSS 0.19%
- Veröffentlicht 10.10.2023 17:15:12
- Zuletzt bearbeitet 21.11.2024 08:12:30
A use of GET request method with sensitive query strings vulnerability in Fortinet FortiOS 7.0.0 - 7.0.12, 7.2.0 - 7.2.5 and 7.4.0 allows an attacker to view plaintext passwords of remote services such as RDP or VNC, if the attacker is able to read t...
CVE-2023-41675
- EPSS 0.4%
- Veröffentlicht 10.10.2023 17:15:12
- Zuletzt bearbeitet 21.11.2024 08:21:27
A use after free vulnerability [CWE-416] in FortiOS version 7.2.0 through 7.2.4 and version 7.0.0 through 7.0.10 and FortiProxy version 7.2.0 through 7.2.2 and version 7.0.0 through 7.0.8 may allow an unauthenticated remote attacker to crash the WAD ...