CVE-2021-26109
- EPSS 1.82%
- Veröffentlicht 08.12.2021 13:15:07
- Zuletzt bearbeitet 21.11.2024 05:55:52
An integer overflow or wraparound vulnerability in the memory allocator of SSLVPN in FortiOS before 7.0.1 may allow an unauthenticated attacker to corrupt control data on the heap via specifically crafted requests to SSLVPN, resulting in potentially ...
CVE-2021-41024
- EPSS 1.55%
- Veröffentlicht 08.12.2021 13:15:07
- Zuletzt bearbeitet 21.11.2024 06:25:17
A relative path traversal [CWE-23] vulnerabiltiy in FortiOS versions 7.0.0 and 7.0.1 and FortiProxy verison 7.0.0 may allow an unauthenticated, unauthorized attacker to inject path traversal character sequences to disclose sensitive information of th...
CVE-2021-26103
- EPSS 0.42%
- Veröffentlicht 08.12.2021 12:15:07
- Zuletzt bearbeitet 21.11.2024 05:55:52
An insufficient verification of data authenticity vulnerability (CWE-345) in the user interface of FortiProxy verison 2.0.3 and below, 1.2.11 and below and FortiGate verison 7.0.0, 6.4.6 and below, 6.2.9 and below of SSL VPN portal may allow a remote...
CVE-2021-26110
- EPSS 0.25%
- Veröffentlicht 08.12.2021 11:15:11
- Zuletzt bearbeitet 21.11.2024 05:55:53
An improper access control vulnerability [CWE-284] in FortiOS autod daemon 7.0.0, 6.4.6 and below, 6.2.9 and below, 6.0.12 and below and FortiProxy 2.0.1 and below, 1.2.9 and below may allow an authenticated low-privileged attacker to escalate their ...
CVE-2021-42757
- EPSS 0.48%
- Veröffentlicht 08.12.2021 11:15:11
- Zuletzt bearbeitet 16.10.2025 10:15:36
A buffer overflow [CWE-121] in the TFTP client library of FortiOS before 6.4.7 and FortiOS 7.0.0 through 7.0.2, may allow an authenticated local attacker to achieve arbitrary code execution via specially crafted command line arguments.
CVE-2021-32600
- EPSS 0.57%
- Veröffentlicht 17.11.2021 12:15:16
- Zuletzt bearbeitet 21.11.2024 06:07:21
An exposure of sensitive information to an unauthorized actor vulnerability in FortiOS CLI 7.0.0, 6.4.0 through 6.4.6, 6.2.0 through 6.2.9, 6.0.x and 5.6.x may allow a local and authenticated user assigned to a specific VDOM to retrieve other VDOMs i...
CVE-2021-41019
- EPSS 0.55%
- Veröffentlicht 02.11.2021 18:15:08
- Zuletzt bearbeitet 21.11.2024 06:25:16
An improper validation of certificate with host mismatch [CWE-297] vulnerability in FortiOS versions 6.4.6 and below may allow the connection to a malicious LDAP server via options in GUI, leading to disclosure of sensitive information, such as AD cr...
CVE-2021-24018
- EPSS 0.76%
- Veröffentlicht 04.08.2021 15:15:08
- Zuletzt bearbeitet 21.11.2024 05:52:13
A buffer underwrite vulnerability in the firmware verification routine of FortiOS before 7.0.1 may allow an attacker located in the adjacent network to potentially execute arbitrary code via a specifically crafted firmware image.
CVE-2021-24012
- EPSS 0.48%
- Veröffentlicht 02.06.2021 13:15:12
- Zuletzt bearbeitet 21.11.2024 05:52:12
An improper following of a certificate's chain of trust vulnerability in FortiGate versions 6.4.0 to 6.4.4 may allow an LDAP user to connect to SSLVPN with any certificate that is signed by a trusted Certificate Authority.
CVE-2019-17656
- EPSS 1.57%
- Veröffentlicht 12.04.2021 15:15:13
- Zuletzt bearbeitet 21.11.2024 04:32:42
A Stack-based Buffer Overflow vulnerability in the HTTPD daemon of FortiOS 6.0.10 and below, 6.2.2 and below and FortiProxy 1.0.x, 1.1.x, 1.2.9 and below, 2.0.0 and below may allow an authenticated remote attacker to crash the service by sending a ma...