CVE-2022-39948
- EPSS 0.28%
- Veröffentlicht 16.02.2023 19:15:12
- Zuletzt bearbeitet 21.11.2024 07:18:32
An improper certificate validation vulnerability [CWE-295] in FortiOS 7.2.0 through 7.2.3, 7.0.0 through 7.0.7, 6.4 all versions, 6.2 all versions, 6.0 all versions and FortiProxy 7.0.0 through 7.0.6, 2.0 all versions, 1.2 all versions may allow a re...
CVE-2021-43074
- EPSS 0.29%
- Veröffentlicht 16.02.2023 19:15:11
- Zuletzt bearbeitet 21.11.2024 06:28:38
An improper verification of cryptographic signature vulnerability [CWE-347] in FortiWeb 6.4 all versions, 6.3.16 and below, 6.2 all versions, 6.1 all versions, 6.0 all versions; FortiOS 7.0.3 and below, 6.4.8 and below, 6.2 all versions, 6.0 all vers...
CVE-2022-42475
- EPSS 99.47%
- Veröffentlicht 02.01.2023 09:15:09
- Zuletzt bearbeitet 24.10.2025 12:54:20
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0 through 6.4.10, 6.2.0 through 6.2.11, 6.0.15 and earlier and FortiProxy SSL-VPN 7.2.0 through 7.2.1, 7.0.7 and earlier may allow ...
CVE-2022-35843
- EPSS 0.89%
- Veröffentlicht 06.12.2022 17:15:10
- Zuletzt bearbeitet 21.11.2024 07:11:48
An authentication bypass by assumed-immutable data vulnerability [CWE-302] in the FortiOS SSH login component 7.2.0, 7.0.0 through 7.0.7, 6.4.0 through 6.4.9, 6.2 all versions, 6.0 all versions and FortiProxy SSH login component 7.0.0 through 7.0.5...
CVE-2022-40680
- EPSS 0.38%
- Veröffentlicht 06.12.2022 17:15:10
- Zuletzt bearbeitet 21.11.2024 07:21:50
A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiOS 6.0.7 - 6.0.15, 6.2.2 - 6.2.12, 6.4.0 - 6.4.9 and 7.0.0 - 7.0.3 allows a privileged attacker to execute unauthorized code or commands via stori...
CVE-2022-38380
- EPSS 22.99%
- Veröffentlicht 02.11.2022 12:15:54
- Zuletzt bearbeitet 21.11.2024 07:16:21
An improper access control [CWE-284] vulnerability in FortiOS version 7.2.0 and versions 7.0.0 through 7.0.7 may allow a remote authenticated read-only user to modify the interface settings via the API.
CVE-2022-35842
- EPSS 0.63%
- Veröffentlicht 02.11.2022 12:15:53
- Zuletzt bearbeitet 21.11.2024 07:11:48
An exposure of sensitive information to an unauthorized actor vulnerabiltiy [CWE-200] in FortiOS SSL-VPN versions 7.2.0, versions 7.0.0 through 7.0.6 and versions 6.4.0 through 6.4.9 may allow a remote unauthenticated attacker to gain information abo...
CVE-2022-26122
- EPSS 0.46%
- Veröffentlicht 02.11.2022 12:15:52
- Zuletzt bearbeitet 21.11.2024 06:53:28
An insufficient verification of data authenticity vulnerability [CWE-345] in FortiClient, FortiMail and FortiOS AV engines version 6.2.168 and below and version 6.4.274 and below may allow an attacker to bypass the AV engine via manipulating MIME att...
CVE-2022-30307
- EPSS 0.46%
- Veröffentlicht 02.11.2022 12:15:52
- Zuletzt bearbeitet 21.11.2024 07:02:32
A key management error vulnerability [CWE-320] affecting the RSA SSH host key in FortiOS 7.2.0 and below, 7.0.6 and below, 6.4.9 and below may allow an unauthenticated attacker to perform a man in the middle attack.
CVE-2022-29055
- EPSS 0.93%
- Veröffentlicht 18.10.2022 15:15:09
- Zuletzt bearbeitet 21.11.2024 06:58:25
A access of uninitialized pointer in Fortinet FortiOS version 7.2.0, 7.0.0 through 7.0.5, 6.4.0 through 6.4.8, 6.2.0 through 6.2.10, 6.0.x, FortiProxy version 7.0.0 through 7.0.4, 2.0.0 through 2.0.9, 1.2.x allows a remote unauthenticated or authenti...