CVE-2022-42475
- EPSS 94.06%
- Veröffentlicht 02.01.2023 09:15:09
- Zuletzt bearbeitet 24.10.2025 12:54:20
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0 through 6.4.10, 6.2.0 through 6.2.11, 6.0.15 and earlier and FortiProxy SSL-VPN 7.2.0 through 7.2.1, 7.0.7 and earlier may allow ...
CVE-2022-35843
- EPSS 0.51%
- Veröffentlicht 06.12.2022 17:15:10
- Zuletzt bearbeitet 21.11.2024 07:11:48
An authentication bypass by assumed-immutable data vulnerability [CWE-302] in the FortiOS SSH login component 7.2.0, 7.0.0 through 7.0.7, 6.4.0 through 6.4.9, 6.2 all versions, 6.0 all versions and FortiProxy SSH login component 7.0.0 through 7.0.5...
CVE-2022-40680
- EPSS 0.58%
- Veröffentlicht 06.12.2022 17:15:10
- Zuletzt bearbeitet 21.11.2024 07:21:50
A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiOS 6.0.7 - 6.0.15, 6.2.2 - 6.2.12, 6.4.0 - 6.4.9 and 7.0.0 - 7.0.3 allows a privileged attacker to execute unauthorized code or commands via stori...
CVE-2022-38380
- EPSS 0.2%
- Veröffentlicht 02.11.2022 12:15:54
- Zuletzt bearbeitet 21.11.2024 07:16:21
An improper access control [CWE-284] vulnerability in FortiOS version 7.2.0 and versions 7.0.0 through 7.0.7 may allow a remote authenticated read-only user to modify the interface settings via the API.
CVE-2022-35842
- EPSS 0.49%
- Veröffentlicht 02.11.2022 12:15:53
- Zuletzt bearbeitet 21.11.2024 07:11:48
An exposure of sensitive information to an unauthorized actor vulnerabiltiy [CWE-200] in FortiOS SSL-VPN versions 7.2.0, versions 7.0.0 through 7.0.6 and versions 6.4.0 through 6.4.9 may allow a remote unauthenticated attacker to gain information abo...
CVE-2022-26122
- EPSS 0.12%
- Veröffentlicht 02.11.2022 12:15:52
- Zuletzt bearbeitet 21.11.2024 06:53:28
An insufficient verification of data authenticity vulnerability [CWE-345] in FortiClient, FortiMail and FortiOS AV engines version 6.2.168 and below and version 6.4.274 and below may allow an attacker to bypass the AV engine via manipulating MIME att...
CVE-2022-30307
- EPSS 0.97%
- Veröffentlicht 02.11.2022 12:15:52
- Zuletzt bearbeitet 21.11.2024 07:02:32
A key management error vulnerability [CWE-320] affecting the RSA SSH host key in FortiOS 7.2.0 and below, 7.0.6 and below, 6.4.9 and below may allow an unauthenticated attacker to perform a man in the middle attack.
CVE-2022-29055
- EPSS 0.62%
- Veröffentlicht 18.10.2022 15:15:09
- Zuletzt bearbeitet 21.11.2024 06:58:25
A access of uninitialized pointer in Fortinet FortiOS version 7.2.0, 7.0.0 through 7.0.5, 6.4.0 through 6.4.8, 6.2.0 through 6.2.10, 6.0.x, FortiProxy version 7.0.0 through 7.0.4, 2.0.0 through 2.0.9, 1.2.x allows a remote unauthenticated or authenti...
CVE-2022-40684
- EPSS 94.43%
- Veröffentlicht 18.10.2022 14:15:09
- Zuletzt bearbeitet 14.01.2026 19:19:58
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6, FortiProxy version 7.2.0 and version 7.0.0 through 7.0.6 and FortiSwitchManager version 7.2.0 and 7.0.0 all...
- EPSS 0.82%
- Veröffentlicht 10.10.2022 14:15:09
- Zuletzt bearbeitet 21.11.2024 06:30:29
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiOS version 6.0.0 through 6.0.14, FortiOS version 6.2.0 through 6.2.10, FortiOS version 6.4.0 through 6.4.8, FortiOS version 7.0.0 through 7....