Fortinet

FortiOS

282 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.61%
  • Veröffentlicht 12.08.2025 18:59:22
  • Zuletzt bearbeitet 09.06.2026 10:16:38

An incorrect privilege assignment vulnerability [CWE-266] in FortiOS Security Fabric version 7.6.0 through 7.6.2, 7.4.0 through 7.4.7, 7.2 all versions, 7.0 all versions, 6.4 all versions, may allow a remote authenticated attacker with high privilege...

  • EPSS 0.21%
  • Veröffentlicht 15.07.2025 08:14:41
  • Zuletzt bearbeitet 10.02.2026 08:15:55

A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.2, FortiOS 7.4.0 through 7.4.7, FortiOS 7.2.4 through 7.2.12 allows an attacker to escalate its privileges via a specially crafted CLI command

Medienbericht
  • EPSS 0.25%
  • Veröffentlicht 08.07.2025 14:41:38
  • Zuletzt bearbeitet 22.07.2025 17:25:57

A missing critical step in authentication vulnerability [CWE-304] in Fortinet FortiOS version 7.6.0 through 7.6.1, 7.4.0 through 7.4.5, 7.2.0 through 7.2.10, and before 7.0.16 & FortiProxy version 7.6.0 through 7.6.1, 7.4.0 through 7.4.8, 7.2.0 throu...

Medienbericht
  • EPSS 0.35%
  • Veröffentlicht 08.07.2025 14:41:34
  • Zuletzt bearbeitet 09.06.2026 10:16:32

An Improperly Implemented Security Check for Standard vulnerability [CWE-358] in FortiOS version 7.6.0, version 7.4.7 and below, 7.0 all versions, 6.4 all versions and FortiProxy version 7.6.1 and below, version 7.4.8 and below, 7.2 all versions, 7.0...

  • EPSS 0.37%
  • Veröffentlicht 10.06.2025 16:36:21
  • Zuletzt bearbeitet 25.07.2025 15:25:35

A channel accessible by non-endpoint vulnerability [CWE-300] in Fortinet FortiOS version 7.4.0 through 7.4.3, 7.2.0 through 7.2.7 and before 7.0.14 & FortiProxy version 7.4.0 through 7.4.3, 7.2.0 through 7.2.9 and before 7.0.16 allows an unauthentica...

  • EPSS 0.18%
  • Veröffentlicht 10.06.2025 16:36:19
  • Zuletzt bearbeitet 24.07.2025 19:57:52

An incomplete cleanup vulnerability [CWE-459] in FortiOS 7.2 all versions and before & FortiProxy version 7.2.0 through 7.2.2 and before 7.0.8 allows a VDOM privileged attacker to add SSH key files on the system silently via crafted CLI requests.

  • EPSS 0.46%
  • Veröffentlicht 10.06.2025 16:36:19
  • Zuletzt bearbeitet 23.06.2026 13:16:36

An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7.6.0, FortiOS 7.4.0 through 7.4.7, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiSASE 25.1.c...

  • EPSS 0.32%
  • Veröffentlicht 10.06.2025 16:36:18
  • Zuletzt bearbeitet 09.06.2026 10:16:34

An Improper Certificate Validation vulnerability [CWE-295] in FortiOS version 7.6.1 and below, version 7.4.7 and below may allow an EAP verified remote user to connect from FortiClient via revoked certificate.

  • EPSS 0.71%
  • Veröffentlicht 10.06.2025 16:36:17
  • Zuletzt bearbeitet 14.01.2026 14:16:11

An Improper Privilege Management vulnerability [CWE-269] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1, FortiOS 7.4.0 through 7.4.6, FortiOS 7.2.0 through 7.2.10, FortiOS 7.0.0 through 7.0.16, FortiOS 6.4.0 through 6.4.15, FortiProxy 7.6.0 th...

  • EPSS 0.34%
  • Veröffentlicht 10.06.2025 16:36:12
  • Zuletzt bearbeitet 25.07.2025 15:26:10

An improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in FortiOS 7.6.0, 7.4.0 through 7.4.5, 7.2 all versions, 7.0 all versions, 6.4 all versions may allow an unauthenticated attacker to inject unauthorized se...