CVE-2017-3130
- EPSS 0.29%
- Published 10.08.2017 21:29:00
- Last modified 20.04.2025 01:37:25
An information disclosure vulnerability in Fortinet FortiOS 5.6.0, 5.4.4 and below versions allows attacker to get FortiOS version info by inspecting FortiOS IKE VendorID packets.
CVE-2017-3127
- EPSS 0.31%
- Published 01.06.2017 14:29:00
- Last modified 20.04.2025 01:37:25
A Cross-Site Scripting vulnerability in Fortinet FortiGate 5.2.0 through 5.2.10 allows attacker to execute unauthorized code or commands via the srcintf parameter during Firewall Policy Creation.
CVE-2017-3128
- EPSS 0.31%
- Published 23.05.2017 17:29:00
- Last modified 20.04.2025 01:37:25
A stored XSS (Cross-Site-Scripting) vulnerability in Fortinet FortiOS allows attackers to execute unauthorized code or commands via the policy global-label parameter.
CVE-2016-7541
- EPSS 0.23%
- Published 30.03.2017 14:59:00
- Last modified 20.04.2025 01:37:25
Long lived sessions in Fortinet FortiGate devices with FortiOS 5.x before 5.4.0 could violate a security policy during IPS signature updates when the FortiGate's IPSengine is configured in flow mode. All FortiGate versions with IPS configured in prox...
CVE-2016-7542
- EPSS 0.32%
- Published 30.03.2017 14:59:00
- Last modified 20.04.2025 01:37:25
A read-only administrator on Fortinet devices with FortiOS 5.2.x before 5.2.10 GA and 5.4.x before 5.4.2 GA may have access to read-write administrators password hashes (not including super-admins) stored on the appliance via the webui REST API, and ...
CVE-2016-8492
- EPSS 0.38%
- Published 08.02.2017 16:59:00
- Last modified 20.04.2025 01:37:25
The implementation of an ANSI X9.31 RNG in Fortinet FortiGate allows attackers to gain unauthorized read access to data handled by the device via IPSec/TLS decryption.
- EPSS 71.56%
- Published 24.08.2016 16:30:00
- Last modified 12.04.2025 10:46:40
Buffer overflow in the Cookie parser in Fortinet FortiOS 4.x before 4.1.11, 4.2.x before 4.2.13, and 4.3.x before 4.3.9 and FortiSwitch before 3.4.3 allows remote attackers to execute arbitrary code via a crafted HTTP request, aka EGREGIOUSBLUNDER.
CVE-2016-3978
- EPSS 5.55%
- Published 08.04.2016 14:59:07
- Last modified 12.04.2025 10:46:40
The Web User Interface (WebUI) in FortiOS 5.0.x before 5.0.13, 5.2.x before 5.2.3, and 5.4.x before 5.4.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks or cross-site scripting (XSS) attacks via the "red...
- EPSS 81.81%
- Published 15.01.2016 20:59:00
- Last modified 12.04.2025 10:46:40
Fortinet FortiAnalyzer before 5.0.12 and 5.2.x before 5.2.5; FortiSwitch 3.3.x before 3.3.3; FortiCache 3.0.x before 3.0.8; and FortiOS 4.1.x before 4.1.11, 4.2.x before 4.2.16, 4.3.x before 4.3.17 and 5.0.x before 5.0.8 have a hardcoded passphrase f...
CVE-2015-7361
- EPSS 0.74%
- Published 15.10.2015 20:59:01
- Last modified 12.04.2025 10:46:40
FortiOS 5.2.3, when configured to use High Availability (HA) and the dedicated management interface is enabled, does not require authentication for access to the ZebOS shell on the HA dedicated management interface, which allows remote attackers to o...