Fortinet

FortiOS

282 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.28%
  • Veröffentlicht 16.02.2023 19:15:12
  • Zuletzt bearbeitet 21.11.2024 07:18:32

An improper certificate validation vulnerability [CWE-295] in FortiOS 7.2.0 through 7.2.3, 7.0.0 through 7.0.7, 6.4 all versions, 6.2 all versions, 6.0 all versions and FortiProxy 7.0.0 through 7.0.6, 2.0 all versions, 1.2 all versions may allow a re...

  • EPSS 0.29%
  • Veröffentlicht 16.02.2023 19:15:11
  • Zuletzt bearbeitet 21.11.2024 06:28:38

An improper verification of cryptographic signature vulnerability [CWE-347] in FortiWeb 6.4 all versions, 6.3.16 and below, 6.2 all versions, 6.1 all versions, 6.0 all versions; FortiOS 7.0.3 and below, 6.4.8 and below, 6.2 all versions, 6.0 all vers...

Warnung Medienbericht Exploit
  • EPSS 99.47%
  • Veröffentlicht 02.01.2023 09:15:09
  • Zuletzt bearbeitet 24.10.2025 12:54:20

A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0 through 6.4.10, 6.2.0 through 6.2.11, 6.0.15 and earlier and FortiProxy SSL-VPN 7.2.0 through 7.2.1, 7.0.7 and earlier may allow ...

  • EPSS 0.89%
  • Veröffentlicht 06.12.2022 17:15:10
  • Zuletzt bearbeitet 21.11.2024 07:11:48

An authentication bypass by assumed-immutable data vulnerability [CWE-302] in the FortiOS SSH login component 7.2.0, 7.0.0 through 7.0.7, 6.4.0 through 6.4.9, 6.2 all versions, 6.0 all versions and FortiProxy SSH login component 7.0.0 through 7.0.5...

  • EPSS 0.38%
  • Veröffentlicht 06.12.2022 17:15:10
  • Zuletzt bearbeitet 21.11.2024 07:21:50

A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiOS 6.0.7 - 6.0.15, 6.2.2 - 6.2.12, 6.4.0 - 6.4.9 and 7.0.0 - 7.0.3 allows a privileged attacker to execute unauthorized code or commands via stori...

  • EPSS 22.99%
  • Veröffentlicht 02.11.2022 12:15:54
  • Zuletzt bearbeitet 21.11.2024 07:16:21

An improper access control [CWE-284] vulnerability in FortiOS version 7.2.0 and versions 7.0.0 through 7.0.7 may allow a remote authenticated read-only user to modify the interface settings via the API.

  • EPSS 0.63%
  • Veröffentlicht 02.11.2022 12:15:53
  • Zuletzt bearbeitet 21.11.2024 07:11:48

An exposure of sensitive information to an unauthorized actor vulnerabiltiy [CWE-200] in FortiOS SSL-VPN versions 7.2.0, versions 7.0.0 through 7.0.6 and versions 6.4.0 through 6.4.9 may allow a remote unauthenticated attacker to gain information abo...

  • EPSS 0.46%
  • Veröffentlicht 02.11.2022 12:15:52
  • Zuletzt bearbeitet 21.11.2024 06:53:28

An insufficient verification of data authenticity vulnerability [CWE-345] in FortiClient, FortiMail and FortiOS AV engines version 6.2.168 and below and version 6.4.274 and below may allow an attacker to bypass the AV engine via manipulating MIME att...

  • EPSS 0.46%
  • Veröffentlicht 02.11.2022 12:15:52
  • Zuletzt bearbeitet 21.11.2024 07:02:32

A key management error vulnerability [CWE-320] affecting the RSA SSH host key in FortiOS 7.2.0 and below, 7.0.6 and below, 6.4.9 and below may allow an unauthenticated attacker to perform a man in the middle attack.

  • EPSS 0.93%
  • Veröffentlicht 18.10.2022 15:15:09
  • Zuletzt bearbeitet 21.11.2024 06:58:25

A access of uninitialized pointer in Fortinet FortiOS version 7.2.0, 7.0.0 through 7.0.5, 6.4.0 through 6.4.8, 6.2.0 through 6.2.10, 6.0.x, FortiProxy version 7.0.0 through 7.0.4, 2.0.0 through 2.0.9, 1.2.x allows a remote unauthenticated or authenti...