CVE-2022-41329
- EPSS 0.68%
- Veröffentlicht 07.03.2023 17:15:12
- Zuletzt bearbeitet 21.11.2024 07:23:03
An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in Fortinet FortiProxy version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.7, FortiOS version 7.2.0 through 7.2.3 and 7.0.0 through 7.0.9 allows an unauthenticated at...
CVE-2022-42476
- EPSS 0.07%
- Veröffentlicht 07.03.2023 17:15:12
- Zuletzt bearbeitet 21.11.2024 07:25:02
A relative path traversal vulnerability [CWE-23] in Fortinet FortiOS version 7.2.0 through 7.2.2, 7.0.0 through 7.0.8 and before 6.4.11, FortiProxy version 7.2.0 through 7.2.2 and 7.0.0 through 7.0.8 allows privileged VDOM administrators to escalate ...
CVE-2022-45861
- EPSS 1.01%
- Veröffentlicht 07.03.2023 17:15:12
- Zuletzt bearbeitet 21.11.2024 07:29:51
An access of uninitialized pointer vulnerability [CWE-824] in the SSL VPN portal of Fortinet FortiOS version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.9 and before 6.4.11 and FortiProxy version 7.2.0 through 7.2.1, version 7.0.0 through 7.0.7 an...
CVE-2022-41334
- EPSS 0.55%
- Veröffentlicht 16.02.2023 19:15:13
- Zuletzt bearbeitet 21.11.2024 07:23:04
An improper neutralization of input during web page generation [CWE-79] vulnerability in FortiOS versions 7.0.0 to 7.0.7 and 7.2.0 to 7.2.3 may allow a remote, unauthenticated attacker to launch a cross site scripting (XSS) attack via the "redir" par...
CVE-2022-41335
- EPSS 0.63%
- Veröffentlicht 16.02.2023 19:15:13
- Zuletzt bearbeitet 21.11.2024 07:23:04
A relative path traversal vulnerability [CWE-23] in Fortinet FortiOS version 7.2.0 through 7.2.2, 7.0.0 through 7.0.8 and before 6.4.10, FortiProxy version 7.2.0 through 7.2.1, 7.0.0 through 7.0.7 and before 2.0.10, FortiSwitchManager 7.2.0 and befor...
CVE-2022-42472
- EPSS 0.51%
- Veröffentlicht 16.02.2023 19:15:13
- Zuletzt bearbeitet 21.11.2024 07:25:02
A improper neutralization of crlf sequences in http headers ('http response splitting') in Fortinet FortiOS versions 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0 through 6.4.11, 6.2.0 through 6.2.12, 6.0.0 through 6.0.16, FortiProxy 7.2.0 through ...
CVE-2022-29054
- EPSS 0.08%
- Veröffentlicht 16.02.2023 19:15:12
- Zuletzt bearbeitet 21.11.2024 06:58:25
A missing cryptographic steps vulnerability [CWE-325] in the functions that encrypt the DHCP and DNS keys in Fortinet FortiOS version 7.2.0, 7.0.0 through 7.0.5, 6.4.0 through 6.4.9, 6.2.x and 6.0.x may allow an attacker in possession of the encrypte...
- EPSS 0.04%
- Veröffentlicht 16.02.2023 19:15:12
- Zuletzt bearbeitet 21.11.2024 07:16:21
An improper privilege management vulnerability [CWE-269] in Fortinet FortiOS version 7.2.0 and before 7.0.7 and FortiProxy version 7.2.0 through 7.2.1 and before 7.0.7 allows an attacker that has access to the admin profile section (System subsection...
CVE-2022-39948
- EPSS 0.16%
- Veröffentlicht 16.02.2023 19:15:12
- Zuletzt bearbeitet 21.11.2024 07:18:32
An improper certificate validation vulnerability [CWE-295] in FortiOS 7.2.0 through 7.2.3, 7.0.0 through 7.0.7, 6.4 all versions, 6.2 all versions, 6.0 all versions and FortiProxy 7.0.0 through 7.0.6, 2.0 all versions, 1.2 all versions may allow a re...
CVE-2021-43074
- EPSS 0.12%
- Veröffentlicht 16.02.2023 19:15:11
- Zuletzt bearbeitet 21.11.2024 06:28:38
An improper verification of cryptographic signature vulnerability [CWE-347] in FortiWeb 6.4 all versions, 6.3.16 and below, 6.2 all versions, 6.1 all versions, 6.0 all versions; FortiOS 7.0.3 and below, 6.4.8 and below, 6.2 all versions, 6.0 all vers...