CVE-2022-40684
- EPSS 99.98%
- Veröffentlicht 18.10.2022 14:15:09
- Zuletzt bearbeitet 06.08.2026 05:16:37
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6, FortiProxy version 7.2.0 and version 7.0.0 through 7.0.6 and FortiSwitchManager version 7.2.0 and 7.0.0 all...
- EPSS 1.51%
- Veröffentlicht 10.10.2022 14:15:09
- Zuletzt bearbeitet 21.11.2024 06:30:29
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiOS version 6.0.0 through 6.0.14, FortiOS version 6.2.0 through 6.2.10, FortiOS version 6.4.0 through 6.4.8, FortiOS version 7.0.0 through 7....
CVE-2022-29053
- EPSS 0.26%
- Veröffentlicht 06.09.2022 18:15:13
- Zuletzt bearbeitet 21.11.2024 06:58:24
A missing cryptographic steps vulnerability [CWE-325] in the functions that encrypt the keytab files in FortiOS version 7.2.0, 7.0.0 through 7.0.5 and below 7.0.0 may allow an attacker in possession of the encrypted file to decipher it.
CVE-2022-27491
- EPSS 1.23%
- Veröffentlicht 06.09.2022 18:15:12
- Zuletzt bearbeitet 21.11.2024 06:55:49
A improper verification of source of a communication channel in Fortinet FortiOS with IPS engine version 7.201 through 7.214, 7.001 through 7.113, 6.001 through 6.121, 5.001 through 5.258 and before 4.086 allows a remote and unauthenticated attacker ...
CVE-2021-43080
- EPSS 0.38%
- Veröffentlicht 06.09.2022 16:15:08
- Zuletzt bearbeitet 21.11.2024 06:28:39
An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiOS version 7.2.0, version 6.4.0 through 6.4.9, version 7.0.0 through 7.0.5 may allow an authenticated attacker to perform a stored cross site scripting (XSS...
CVE-2022-22299
- EPSS 0.21%
- Veröffentlicht 05.08.2022 20:15:08
- Zuletzt bearbeitet 21.11.2024 06:46:35
A format string vulnerability [CWE-134] in the command line interpreter of FortiADC version 6.0.0 through 6.0.4, FortiADC version 6.1.0 through 6.1.5, FortiADC version 6.2.0 through 6.2.1, FortiProxy version 1.0.0 through 1.0.7, FortiProxy version 1....
CVE-2022-23442
- EPSS 0.55%
- Veröffentlicht 03.08.2022 14:15:08
- Zuletzt bearbeitet 21.11.2024 06:48:33
An improper access control vulnerability [CWE-284] in FortiOS versions 6.2.0 through 6.2.11, 6.4.0 through 6.4.8 and 7.0.0 through 7.0.5 may allow an authenticated attacker with a restricted user profile to gather the checksum information about the o...
CVE-2022-23438
- EPSS 0.64%
- Veröffentlicht 18.07.2022 18:15:08
- Zuletzt bearbeitet 21.11.2024 06:48:33
An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in FortiOS version 7.0.5 and prior and 6.4.9 and prior may allow an unauthenticated remote attacker to perform a reflected cross site scrip...
CVE-2021-42755
- EPSS 0.38%
- Veröffentlicht 18.07.2022 17:15:08
- Zuletzt bearbeitet 21.11.2024 06:28:06
An integer overflow / wraparound vulnerability [CWE-190] in FortiSwitch 7.0.2 and below, 6.4.9 and below, 6.2.x, 6.0.x; FortiRecorder 6.4.2 and below, 6.0.10 and below; FortiOS 7.0.2 and below, 6.4.8 and below, 6.2.10 and below, 6.0.x; FortiProxy 7.0...
CVE-2021-44170
- EPSS 0.21%
- Veröffentlicht 18.07.2022 17:15:08
- Zuletzt bearbeitet 21.11.2024 06:30:29
A stack-based buffer overflow vulnerability [CWE-121] in the command line interpreter of FortiOS before 7.0.4 and FortiProxy before 2.0.8 may allow an authenticated attacker to execute unauthorized code or commands via specially crafted command line ...