CVE-2022-23442
- EPSS 0.24%
- Published 03.08.2022 14:15:08
- Last modified 21.11.2024 06:48:33
An improper access control vulnerability [CWE-284] in FortiOS versions 6.2.0 through 6.2.11, 6.4.0 through 6.4.8 and 7.0.0 through 7.0.5 may allow an authenticated attacker with a restricted user profile to gather the checksum information about the o...
CVE-2022-23438
- EPSS 0.18%
- Published 18.07.2022 18:15:08
- Last modified 21.11.2024 06:48:33
An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in FortiOS version 7.0.5 and prior and 6.4.9 and prior may allow an unauthenticated remote attacker to perform a reflected cross site scrip...
CVE-2021-42755
- EPSS 0.16%
- Published 18.07.2022 17:15:08
- Last modified 21.11.2024 06:28:06
An integer overflow / wraparound vulnerability [CWE-190] in FortiSwitch 7.0.2 and below, 6.4.9 and below, 6.2.x, 6.0.x; FortiRecorder 6.4.2 and below, 6.0.10 and below; FortiOS 7.0.2 and below, 6.4.8 and below, 6.2.10 and below, 6.0.x; FortiProxy 7.0...
CVE-2021-44170
- EPSS 0.05%
- Published 18.07.2022 17:15:08
- Last modified 21.11.2024 06:30:29
A stack-based buffer overflow vulnerability [CWE-121] in the command line interpreter of FortiOS before 7.0.4 and FortiProxy before 2.0.8 may allow an authenticated attacker to execute unauthorized code or commands via specially crafted command line ...
CVE-2022-22306
- EPSS 0.05%
- Published 24.05.2022 15:15:07
- Last modified 21.11.2024 06:46:36
An improper certificate validation vulnerability [CWE-295] in FortiOS 6.0.0 through 6.0.14, 6.2.0 through 6.2.10, 6.4.0 through 6.4.8, 7.0.0 may allow a network adjacent and unauthenticated attacker to man-in-the-middle the communication between the ...
CVE-2021-43081
- EPSS 0.42%
- Published 11.05.2022 15:15:08
- Last modified 21.11.2024 06:28:39
An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiOS version 7.0.3 and below, 6.4.8 and below, 6.2.10 and below, 6.0.14 to 6.0.0. and in FortiProxy version 7.0.1 and below, 2.0.7 to 2.0.0 web filter overrid...
CVE-2021-41032
- EPSS 0.21%
- Published 04.05.2022 16:15:08
- Last modified 21.11.2024 06:25:18
An improper access control vulnerability [CWE-284] in FortiOS versions 6.4.8 and prior and 7.0.3 and prior may allow an authenticated attacker with a restricted user profile to gather sensitive information and modify the SSL-VPN tunnel status of othe...
CVE-2021-43206
- EPSS 0.2%
- Published 04.05.2022 16:15:08
- Last modified 21.11.2024 06:28:50
A server-generated error message containing sensitive information in Fortinet FortiOS 7.0.0 through 7.0.3, 6.4.0 through 6.4.8, 6.2.x, 6.0.x and FortiProxy 7.0.0 through 7.0.1, 2.0.x allows malicious webservers to retrieve a web proxy's client userna...
CVE-2020-15936
- EPSS 0.34%
- Published 01.03.2022 19:15:08
- Last modified 21.11.2024 05:06:29
A improper input validation in Fortinet FortiGate version 6.4.3 and below, version 6.2.5 and below, version 6.0.11 and below, version 5.6.13 and below allows attacker to disclose sensitive information via SNI Client Hello TLS packets.
CVE-2021-26092
- EPSS 0.53%
- Published 24.02.2022 03:15:43
- Last modified 21.11.2024 05:55:51
Failure to sanitize input in the SSL VPN web portal of FortiOS 5.2.10 through 5.2.15, 5.4.0 through 5.4.13, 5.6.0 through 5.6.14, 6.0.0 through 6.0.12, 6.2.0 through 6.2.7, 6.4.0 through 6.4.4; and FortiProxy 1.2.0 through 1.2.9, 2.0.0 through 2.0.1 ...