Fortinet

FortiOS

282 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1%
  • Veröffentlicht 14.01.2025 14:15:31
  • Zuletzt bearbeitet 31.01.2025 16:10:13

An allocation of resources without limits or throttling vulnerability [CWE-770] in FortiOS versions 7.4.0 through 7.4.4, versions 7.2.0 through 7.2.8, versions 7.0.0 through 7.0.15, and versions 6.4.0 through 6.4.15 may allow an unauthenticated remot...

  • EPSS 0.72%
  • Veröffentlicht 14.01.2025 14:15:30
  • Zuletzt bearbeitet 22.07.2025 21:26:23

An out-of-bounds read vulnerability [CWE-125] in FortiOS SSLVPN web portal versions 7.4.0 through 7.4.4, versions 7.2.0 through 7.2.8, 7.0 all verisons, and 6.4 all versions may allow an authenticated attacker to perform a denial of service on the SS...

  • EPSS 0.71%
  • Veröffentlicht 14.01.2025 14:15:27
  • Zuletzt bearbeitet 17.01.2025 20:42:36

A null pointer dereference in FortiOS versions 7.4.0 through 7.4.1, 7.2.0 through 7.2.5, 7.0 all versions, 6.4 all versions , 6.2 all versions and 6.0 all versions allows attacker to trigger a denial of service via a crafted http request.

  • EPSS 0.87%
  • Veröffentlicht 14.01.2025 14:15:27
  • Zuletzt bearbeitet 17.01.2025 20:42:31

A null pointer dereference in FortiOS versions 7.4.0 through 7.4.1, 7.2.0 through 7.2.5, 7.0 all versions, 6.4 all versions , 6.2 all versions and 6.0 all versions allows attacker to trigger a denial of service via a crafted http request.

  • EPSS 0.95%
  • Veröffentlicht 14.01.2025 14:15:27
  • Zuletzt bearbeitet 31.01.2025 17:20:44

An origin validation error [CWE-346] vulnerability in Fortinet FortiOS IPSec VPN version 7.4.0 through 7.4.1 and version 7.2.6 and below allows an authenticated IPSec VPN user with dynamic IP addressing to send (but not receive) packets spoofing the...

  • EPSS 0.86%
  • Veröffentlicht 19.12.2024 11:15:05
  • Zuletzt bearbeitet 21.01.2025 20:42:17

Under non-default configuration, a stack-based buffer overflow in FortiOS version 6.0.10 and below, version 5.6.12 and below may allow a remote attacker authenticated to the SSL VPN to crash the FortiClient NAC daemon (fcnacd) and potentially execute...

  • EPSS 0.77%
  • Veröffentlicht 19.12.2024 08:15:11
  • Zuletzt bearbeitet 21.01.2025 20:58:57

A heap-based buffer overflow vulnerability in the processing of Link Control Protocol messages in FortiGate versions 5.6.12, 6.0.10, 6.2.4 and 6.4.1 and earlier may allow a remote attacker with valid SSL VPN credentials to crash the SSL VPN daemon by...

  • EPSS 0.57%
  • Veröffentlicht 12.11.2024 19:15:09
  • Zuletzt bearbeitet 17.01.2025 20:35:31

An improper neutralization of special elements in output used by a downstream component ('Injection') vulnerability [CWE-74] in FortiOS version 7.4.3 and below, version 7.2.8 and below, version 7.0.16 and below; FortiProxy version 7.4.3 and below, ve...

  • EPSS 0.6%
  • Veröffentlicht 12.11.2024 19:15:08
  • Zuletzt bearbeitet 12.12.2024 19:33:58

A missing authentication for critical function in Fortinet FortiManager version 7.4.0 through 7.4.2, 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through 6.4.14, FortiPAM version 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiProxy version...

  • EPSS 0.57%
  • Veröffentlicht 12.11.2024 19:15:07
  • Zuletzt bearbeitet 24.08.2026 13:16:45

A session fixation vulnerability in Fortinet FortiOS 7.4.0 through 7.4.3, FortiOS 7.2.0 through 7.2.7, FortiOS 7.0.0 through 7.0.13 allows attacker to execute unauthorized code or commands via phishing SAML authentication link.