Fortinet

FortiOS

260 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.93%
  • Veröffentlicht 05.07.2018 13:29:00
  • Zuletzt bearbeitet 21.11.2024 04:15:08

An information disclosure vulnerability in Fortinet FortiOS 6.0.0 and below versions reveals user's web portal login credentials in a Javascript file sent to client-side when pages bookmarked in web portal use the Single Sign-On feature.

  • EPSS 0.33%
  • Veröffentlicht 25.05.2018 16:29:00
  • Zuletzt bearbeitet 21.11.2024 03:12:19

An Information Disclosure vulnerability in Fortinet FortiOS 5.6.0 to 5.6.2, 5.4.0 to 5.4.8 and 5.2 all versions allows SSL VPN web portal users to access internal FortiOS configuration information (eg:addresses) via specifically crafted URLs inside t...

  • EPSS 0.07%
  • Veröffentlicht 24.05.2018 20:29:00
  • Zuletzt bearbeitet 21.11.2024 03:12:19

A local privilege escalation and local code execution vulnerability in Fortinet FortiOS 5.6.0 to 5.6.2, 5.4.0 to 5.4.8, and 5.2 and below versions allows attacker to execute unauthorized binary program contained on an USB drive plugged into a FortiGa...

Exploit
  • EPSS 0.86%
  • Veröffentlicht 08.02.2018 23:29:00
  • Zuletzt bearbeitet 21.11.2024 01:36:00

Multiple cross-site scripting (XSS) vulnerabilities in Fortinet FortiGate UTM WAF appliances with FortiOS 4.3.x before 4.3.6 allow remote attackers to inject arbitrary web script or HTML via vectors involving the (1) Endpoint Monitor, (2) Dialup List...

  • EPSS 0.39%
  • Veröffentlicht 29.01.2018 16:29:00
  • Zuletzt bearbeitet 21.11.2024 03:12:19

A Cross-site Scripting vulnerability in Fortinet FortiOS 5.6.0 to 5.6.2, 5.4.0 to 5.4.7, 5.2 and earlier, allows attacker to inject arbitrary web script or HTML via maliciously crafted "Host" header in user HTTP requests.

  • EPSS 4.05%
  • Veröffentlicht 29.11.2017 19:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

A Cross-site Scripting (XSS) vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.7, 5.4 and below versions under SSL VPN web portal allows a remote user to inject arbitrary web script or HTML in the context of the victim's browser via the ...

  • EPSS 0.74%
  • Veröffentlicht 13.11.2017 14:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

A reflected Cross-site Scripting (XSS) vulnerability in web proxy disclaimer response web pages in Fortinet FortiOS 5.6.0, 5.4.0 to 5.4.5, 5.2.0 to 5.2.11 allows an unauthenticated attacker to inject arbitrary web script or HTML in the context of the...

  • EPSS 1.46%
  • Veröffentlicht 27.10.2017 13:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

A Denial of Service (DoS) vulnerability in Fortinet FortiOS 5.4.0 to 5.4.5 allows an authenticated user to cause the web GUI to be temporarily unresponsive, via passing a specially crafted payload to the 'params' parameter of the JSON web API.

  • EPSS 0.35%
  • Veröffentlicht 27.10.2017 13:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

A Cross-Site-Scripting (XSS) vulnerability in Fortinet FortiOS 5.4.0 to 5.4.5 and 5.6.0 allows a remote unauthenticated attacker to execute arbitrary javascript code via webUI "Login Disclaimer" redir parameter.

  • EPSS 11.48%
  • Veröffentlicht 12.09.2017 02:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.4.0 through 5.4.4 and 5.6.0 allows attackers to execute unauthorized code or commands via the filter input in "Applications" under FortiView.