CVE-2024-21762
- EPSS 92.68%
- Published 09.02.2024 09:15:08
- Last modified 29.11.2024 15:23:32
A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, 6.0.0 through 6.0.17, FortiProxy versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 t...
CVE-2023-44250
- EPSS 0.13%
- Published 10.01.2024 18:15:46
- Last modified 21.11.2024 08:25:31
An improper privilege management vulnerability [CWE-269] in a Fortinet FortiOS HA cluster version 7.4.0 through 7.4.1 and 7.2.5 and in a FortiProxy HA cluster version 7.4.0 through 7.4.1 allows an authenticated attacker to perform elevated actions vi...
CVE-2023-47536
- EPSS 0.05%
- Published 13.12.2023 08:15:50
- Last modified 21.11.2024 08:30:24
An improper access control vulnerability [CWE-284] in FortiOS version 7.2.0, version 7.0.13 and below, version 6.4.14 and below and FortiProxy version 7.2.3 and below, version 7.0.9 and below, version 2.0.12 and below may allow a remote unauthenticat...
CVE-2023-41678
- EPSS 0.28%
- Published 13.12.2023 07:15:17
- Last modified 21.11.2024 08:21:28
A double free in Fortinet FortiOS versions 7.0.0 through 7.0.5, FortiPAM version 1.0.0 through 1.0.3, 1.1.0 through 1.1.1 allows attacker to execute unauthorized code or commands via specifically crafted request.
CVE-2023-36639
- EPSS 0.17%
- Published 13.12.2023 07:15:12
- Last modified 21.11.2024 08:10:09
A use of externally-controlled format string in Fortinet FortiProxy versions 7.2.0 through 7.2.4, 7.0.0 through 7.0.10, FortiOS versions 7.4.0, 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through 6.4.12, 6.2.0 through 6.2.15, 6.0.0 through 6.0.1...
CVE-2023-36641
- EPSS 0.47%
- Published 14.11.2023 18:15:49
- Last modified 21.11.2024 08:10:09
A numeric truncation error in Fortinet FortiProxy version 7.2.0 through 7.2.4, FortiProxy version 7.0.0 through 7.0.10, FortiProxy 2.0 all versions, FortiProxy 1.2 all versions, FortiProxy 1.1, all versions, FortiProxy 1.0 all versions, FortiOS vers...
CVE-2023-28002
- EPSS 0.01%
- Published 14.11.2023 18:15:29
- Last modified 21.11.2024 07:53:54
An improper validation of integrity check value vulnerability [CWE-354] in FortiOS 7.2.0 through 7.2.3, 7.0.0 through 7.0.12, 6.4 all versions, 6.2 all versions, 6.0 all versions and VMs may allow a local attacker with admin privileges to boot a mali...
CVE-2023-36555
- EPSS 0.12%
- Published 10.10.2023 17:15:12
- Last modified 21.11.2024 08:09:55
An improper neutralization of script-related html tags in a web page (basic xss) in Fortinet FortiOS 7.2.0 - 7.2.4 allows an attacker to execute unauthorized code or commands via the SAML and Security Fabric components.
CVE-2023-37935
- EPSS 0.19%
- Published 10.10.2023 17:15:12
- Last modified 21.11.2024 08:12:30
A use of GET request method with sensitive query strings vulnerability in Fortinet FortiOS 7.0.0 - 7.0.12, 7.2.0 - 7.2.5 and 7.4.0 allows an attacker to view plaintext passwords of remote services such as RDP or VNC, if the attacker is able to read t...
CVE-2023-41675
- EPSS 0.4%
- Published 10.10.2023 17:15:12
- Last modified 21.11.2024 08:21:27
A use after free vulnerability [CWE-416] in FortiOS version 7.2.0 through 7.2.4 and version 7.0.0 through 7.0.10 and FortiProxy version 7.2.0 through 7.2.2 and version 7.0.0 through 7.0.8 may allow an unauthenticated remote attacker to crash the WAD ...