Fortinet

FortiOS

260 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.17%
  • Veröffentlicht 17.03.2025 13:06:16
  • Zuletzt bearbeitet 24.07.2025 20:15:46

An exposure of sensitive information to an unauthorized actor vulnerability in FortiOS version 6.2.4 and below, version 6.0.10 and belowmay allow remote authenticated actors to read the SSL VPN events log entries of users in other VDOMs by executing...

  • EPSS 0.06%
  • Veröffentlicht 17.03.2025 13:05:08
  • Zuletzt bearbeitet 24.07.2025 20:15:24

An improper neutralization of input during web page generation in the SSL VPN portal of FortiProxy version 2.0.0, version 1.2.9 and below and FortiOS version 6.2.1 and below, version 6.0.8 and below, version 5.6.12 may allow a remote authenticated at...

  • EPSS 0.55%
  • Veröffentlicht 14.03.2025 10:15:14
  • Zuletzt bearbeitet 24.07.2025 20:00:45

An improper neutralization of input during web page Generation vulnerability [CWE-79] in FortiOS version 7.4.3 and below, version 7.2.7 and below, version 7.0.13 and below and FortiProxy version 7.4.3 and below, version 7.2.9 and below, version 7.0.1...

  • EPSS 0.1%
  • Veröffentlicht 11.03.2025 14:54:33
  • Zuletzt bearbeitet 24.07.2025 19:06:14

A use of externally-controlled format string vulnerability [CWE-134] in FortiOS version 7.4.0 through 7.4.4, version 7.2.0 through 7.2.9, version 7.0.0 through 7.0.15 and before 6.4.15, FortiProxy version 7.4.0 through 7.4.6, version 7.2.0 through 7....

Warnung
  • EPSS 4.37%
  • Veröffentlicht 11.02.2025 17:15:34
  • Zuletzt bearbeitet 24.10.2025 12:53:29

An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS 7.0.0 through 7.0.16 and FortiProxy 7.2.0 through 7.2.12, 7.0.0 through 7.0.19 may allow a remote unauthenticated attacker with prior knowledge of u...

  • EPSS 0.23%
  • Veröffentlicht 11.02.2025 17:15:22
  • Zuletzt bearbeitet 17.07.2025 20:13:41

A stack-based buffer overflow [CWE-121] vulnerability in Fortinet FortiOS version 7.2.4 through 7.2.8 and version 7.4.0 through 7.4.4 allows a remote unauthenticated attacker to execute arbitrary code or commands via crafted UDP packets through the C...

  • EPSS 0.18%
  • Veröffentlicht 11.02.2025 17:15:22
  • Zuletzt bearbeitet 17.07.2025 20:12:01

An incorrect privilege assignment vulnerability [CWE-266] in Fortinet FortiOS version 7.6.0, 7.4.0 through 7.4.4, 7.2.0 through 7.2.9 and before 7.0.15 allows an authenticated admin whose access profile has the Security Fabric permission to escalate ...

  • EPSS 0.04%
  • Veröffentlicht 11.02.2025 17:15:21
  • Zuletzt bearbeitet 14.01.2026 15:15:54

A use of externally-controlled format string vulnerability [CWE-134] vulnerability in Fortinet allows a privileged attacker to execute arbitrary code or commands via specially crafted requests.

  • EPSS 0.13%
  • Veröffentlicht 22.01.2025 10:15:07
  • Zuletzt bearbeitet 14.01.2026 14:16:06

A externally controlled reference to a resource in another sphere vulnerability in Fortinet allows attacker to poison web caches via crafted HTTP requests, where the `Host` header points to an arbitrary webserver

  • EPSS 0.09%
  • Veröffentlicht 14.01.2025 14:15:34
  • Zuletzt bearbeitet 08.08.2025 16:03:42

An Improper Neutralization of CRLF Sequences in HTTP Headers ('http response splitting') vulnerability [CWE-113] in Fortinet FortiOS 7.2.0 through 7.6.0, FortiProxy 7.2.0 through 7.4.5 may allow a remote unauthenticated attacker to bypass the file fi...