CVE-2025-53744
- EPSS 0.61%
- Veröffentlicht 12.08.2025 18:59:22
- Zuletzt bearbeitet 09.06.2026 10:16:38
An incorrect privilege assignment vulnerability [CWE-266] in FortiOS Security Fabric version 7.6.0 through 7.6.2, 7.4.0 through 7.4.7, 7.2 all versions, 7.0 all versions, 6.4 all versions, may allow a remote authenticated attacker with high privilege...
CVE-2025-24477
- EPSS 0.21%
- Veröffentlicht 15.07.2025 08:14:41
- Zuletzt bearbeitet 10.02.2026 08:15:55
A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.2, FortiOS 7.4.0 through 7.4.7, FortiOS 7.2.4 through 7.2.12 allows an attacker to escalate its privileges via a specially crafted CLI command
CVE-2024-52965
- EPSS 0.25%
- Veröffentlicht 08.07.2025 14:41:38
- Zuletzt bearbeitet 22.07.2025 17:25:57
A missing critical step in authentication vulnerability [CWE-304] in Fortinet FortiOS version 7.6.0 through 7.6.1, 7.4.0 through 7.4.5, 7.2.0 through 7.2.10, and before 7.0.16 & FortiProxy version 7.6.0 through 7.6.1, 7.4.0 through 7.4.8, 7.2.0 throu...
CVE-2024-55599
- EPSS 0.35%
- Veröffentlicht 08.07.2025 14:41:34
- Zuletzt bearbeitet 09.06.2026 10:16:32
An Improperly Implemented Security Check for Standard vulnerability [CWE-358] in FortiOS version 7.6.0, version 7.4.7 and below, 7.0 all versions, 6.4 all versions and FortiProxy version 7.6.1 and below, version 7.4.8 and below, 7.2 all versions, 7.0...
CVE-2024-50568
- EPSS 0.37%
- Veröffentlicht 10.06.2025 16:36:21
- Zuletzt bearbeitet 25.07.2025 15:25:35
A channel accessible by non-endpoint vulnerability [CWE-300] in Fortinet FortiOS version 7.4.0 through 7.4.3, 7.2.0 through 7.2.7 and before 7.0.14 & FortiProxy version 7.4.0 through 7.4.3, 7.2.0 through 7.2.9 and before 7.0.16 allows an unauthentica...
CVE-2023-29184
- EPSS 0.18%
- Veröffentlicht 10.06.2025 16:36:19
- Zuletzt bearbeitet 24.07.2025 19:57:52
An incomplete cleanup vulnerability [CWE-459] in FortiOS 7.2 all versions and before & FortiProxy version 7.2.0 through 7.2.2 and before 7.0.8 allows a VDOM privileged attacker to add SSH key files on the system silently via crafted CLI requests.
CVE-2025-25250
- EPSS 0.46%
- Veröffentlicht 10.06.2025 16:36:19
- Zuletzt bearbeitet 23.06.2026 13:16:36
An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7.6.0, FortiOS 7.4.0 through 7.4.7, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiSASE 25.1.c...
CVE-2025-24471
- EPSS 0.32%
- Veröffentlicht 10.06.2025 16:36:18
- Zuletzt bearbeitet 09.06.2026 10:16:34
An Improper Certificate Validation vulnerability [CWE-295] in FortiOS version 7.6.1 and below, version 7.4.7 and below may allow an EAP verified remote user to connect from FortiClient via revoked certificate.
CVE-2025-22254
- EPSS 0.71%
- Veröffentlicht 10.06.2025 16:36:17
- Zuletzt bearbeitet 14.01.2026 14:16:11
An Improper Privilege Management vulnerability [CWE-269] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1, FortiOS 7.4.0 through 7.4.6, FortiOS 7.2.0 through 7.2.10, FortiOS 7.0.0 through 7.0.16, FortiOS 6.4.0 through 6.4.15, FortiProxy 7.6.0 th...
CVE-2025-22251
- EPSS 0.34%
- Veröffentlicht 10.06.2025 16:36:12
- Zuletzt bearbeitet 25.07.2025 15:26:10
An improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in FortiOS 7.6.0, 7.4.0 through 7.4.5, 7.2 all versions, 7.0 all versions, 6.4 all versions may allow an unauthenticated attacker to inject unauthorized se...