Fortinet

Fortios

258 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Warnung
  • EPSS 51.23%
  • Veröffentlicht 15.02.2024 14:15:46
  • Zuletzt bearbeitet 24.10.2025 12:54:40

A use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, FortiProxy versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0.14, FortiPAM versions 1.2.0, 1.1...

  • EPSS 0.08%
  • Veröffentlicht 15.02.2024 14:15:45
  • Zuletzt bearbeitet 21.11.2024 08:30:25

An improper certificate validation vulnerability in Fortinet FortiOS 7.0.0 - 7.0.13, 7.2.0 - 7.2.6, 7.4.0 - 7.4.1 and 6.4 all versions allows a remote and unauthenticated attacker to perform a Man-in-the-Middle attack on the FortiLink communication c...

Warnung Medienbericht
  • EPSS 92.73%
  • Veröffentlicht 09.02.2024 09:15:08
  • Zuletzt bearbeitet 24.10.2025 12:54:44

A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, 6.0.0 through 6.0.17, FortiProxy versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 t...

  • EPSS 0.13%
  • Veröffentlicht 10.01.2024 18:15:46
  • Zuletzt bearbeitet 21.11.2024 08:25:31

An improper privilege management vulnerability [CWE-269] in a Fortinet FortiOS HA cluster version 7.4.0 through 7.4.1 and 7.2.5 and in a FortiProxy HA cluster version 7.4.0 through 7.4.1 allows an authenticated attacker to perform elevated actions vi...

  • EPSS 0.05%
  • Veröffentlicht 13.12.2023 08:15:50
  • Zuletzt bearbeitet 21.11.2024 08:30:24

An improper access control vulnerability [CWE-284] in FortiOS version 7.2.0, version 7.0.13 and below, version 6.4.14 and below and FortiProxy version 7.2.3 and below, version 7.0.9 and below, version 2.0.12 and below may allow a remote unauthenticat...

  • EPSS 0.28%
  • Veröffentlicht 13.12.2023 07:15:17
  • Zuletzt bearbeitet 21.11.2024 08:21:28

A double free in Fortinet FortiOS versions 7.0.0 through 7.0.5, FortiPAM version 1.0.0 through 1.0.3, 1.1.0 through 1.1.1 allows attacker to execute unauthorized code or commands via specifically crafted request.

  • EPSS 0.17%
  • Veröffentlicht 13.12.2023 07:15:12
  • Zuletzt bearbeitet 21.11.2024 08:10:09

A use of externally-controlled format string in Fortinet FortiProxy versions 7.2.0 through 7.2.4, 7.0.0 through 7.0.10, FortiOS versions 7.4.0, 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through 6.4.12, 6.2.0 through 6.2.15, 6.0.0 through 6.0.1...

  • EPSS 0.47%
  • Veröffentlicht 14.11.2023 18:15:49
  • Zuletzt bearbeitet 21.11.2024 08:10:09

A numeric truncation error in Fortinet FortiProxy version 7.2.0 through 7.2.4, FortiProxy version 7.0.0 through 7.0.10, FortiProxy 2.0 all versions, FortiProxy 1.2 all versions, FortiProxy 1.1, all versions, FortiProxy 1.0 all versions, FortiOS vers...

  • EPSS 0.01%
  • Veröffentlicht 14.11.2023 18:15:29
  • Zuletzt bearbeitet 21.11.2024 07:53:54

An improper validation of integrity check value vulnerability [CWE-354] in FortiOS 7.2.0 through 7.2.3, 7.0.0 through 7.0.12, 6.4 all versions, 6.2 all versions, 6.0 all versions and VMs may allow a local attacker with admin privileges to boot a mali...

  • EPSS 0.12%
  • Veröffentlicht 10.10.2023 17:15:12
  • Zuletzt bearbeitet 21.11.2024 08:09:55

An improper neutralization of script-related html tags in a web page (basic xss) in Fortinet FortiOS 7.2.0 - 7.2.4 allows an attacker to execute unauthorized code or commands via the SAML and Security Fabric components.