- EPSS 71.56%
- Veröffentlicht 24.08.2016 16:30:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
Buffer overflow in the Cookie parser in Fortinet FortiOS 4.x before 4.1.11, 4.2.x before 4.2.13, and 4.3.x before 4.3.9 and FortiSwitch before 3.4.3 allows remote attackers to execute arbitrary code via a crafted HTTP request, aka EGREGIOUSBLUNDER.
CVE-2016-3978
- EPSS 5.55%
- Veröffentlicht 08.04.2016 14:59:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
The Web User Interface (WebUI) in FortiOS 5.0.x before 5.0.13, 5.2.x before 5.2.3, and 5.4.x before 5.4.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks or cross-site scripting (XSS) attacks via the "red...
- EPSS 79.71%
- Veröffentlicht 15.01.2016 20:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
Fortinet FortiAnalyzer before 5.0.12 and 5.2.x before 5.2.5; FortiSwitch 3.3.x before 3.3.3; FortiCache 3.0.x before 3.0.8; and FortiOS 4.1.x before 4.1.11, 4.2.x before 4.2.16, 4.3.x before 4.3.17 and 5.0.x before 5.0.8 have a hardcoded passphrase f...
CVE-2015-7361
- EPSS 0.74%
- Veröffentlicht 15.10.2015 20:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
FortiOS 5.2.3, when configured to use High Availability (HA) and the dedicated management interface is enabled, does not require authentication for access to the ZebOS shell on the HA dedicated management interface, which allows remote attackers to o...
- EPSS 0.35%
- Veröffentlicht 11.08.2015 14:59:16
- Zuletzt bearbeitet 12.04.2025 10:46:40
The SSL-VPN feature in Fortinet FortiOS before 4.3.13 only checks the first byte of the TLS MAC in finished messages, which makes it easier for remote attackers to spoof encrypted content via a crafted MAC field.
CVE-2015-3626
- EPSS 0.29%
- Veröffentlicht 11.08.2015 14:59:09
- Zuletzt bearbeitet 12.04.2025 10:46:40
Cross-site scripting (XSS) vulnerability in the DHCP Monitor page in the Web User Interface (WebUI) in Fortinet FortiOS before 5.2.4 on FortiGate devices allows remote attackers to inject arbitrary web script or HTML via a crafted hostname.
CVE-2015-2323
- EPSS 0.29%
- Veröffentlicht 11.08.2015 14:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
FortiOS 5.0.x before 5.0.12 and 5.2.x before 5.2.4 supports anonymous, export, RC4, and possibly other weak ciphers when using TLS to connect to FortiGuard servers, which allows man-in-the-middle attackers to spoof TLS content by modifying packets.
CVE-2015-1880
- EPSS 59.36%
- Veröffentlicht 12.05.2015 19:59:08
- Zuletzt bearbeitet 12.04.2025 10:46:40
Cross-site scripting (XSS) vulnerability in the sslvpn login page in Fortinet FortiOS 5.2.x before 5.2.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2014-8616
- EPSS 0.32%
- Veröffentlicht 12.05.2015 19:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
Multiple cross-site scripting (XSS) vulnerabilities in Fortinet FortiOS 5.2.x before 5.2.3 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors to the (1) user group or (2) vpn template menus.
CVE-2015-1571
- EPSS 0.16%
- Veröffentlicht 10.02.2015 20:59:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
The CAPWAP DTLS protocol implementation in Fortinet FortiOS 5.0 Patch 7 build 4457 uses the same certificate and private key across different customers' installations, which makes it easier for man-in-the-middle attackers to spoof SSL servers by leve...