Fortinet

FortiOS

282 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Medienbericht
  • EPSS 1.08%
  • Veröffentlicht 10.06.2025 16:36:10
  • Zuletzt bearbeitet 09.06.2026 10:16:32

An Insufficient Session Expiration vulnerability [CWE-613] in FortiOS SSL-VPN version 7.6.0, version 7.4.6 and below, version 7.2.10 and below, 7.0 all versions, 6.4 all versions may allow an attacker in possession of a cookie used to log in the SSL-...

  • EPSS 0.89%
  • Veröffentlicht 28.05.2025 07:55:49
  • Zuletzt bearbeitet 04.06.2025 14:35:38

A missing authentication for critical function in Fortinet FortiProxy versions 7.6.0 through 7.6.1, FortiSwitchManager version 7.2.5, and FortiOS versions 7.4.4 through 7.4.6 and version 7.6.0 may allow an attacker with knowledge of an existing admin...

  • EPSS 0.76%
  • Veröffentlicht 28.05.2025 07:55:39
  • Zuletzt bearbeitet 04.06.2025 15:37:29

A integer overflow or wraparound in Fortinet FortiOS versions 7.2.0 through 7.2.7, versions 7.0.0 through 7.0.14 may allow a remote unauthenticated attacker to crash the csfd daemon via a specially crafted request.

  • EPSS 0.72%
  • Veröffentlicht 28.05.2025 07:54:05
  • Zuletzt bearbeitet 04.06.2025 15:37:21

A buffer over-read in Fortinet FortiOS versions 7.4.0 through 7.4.3, versions 7.2.0 through 7.2.7, and versions 7.0.0 through 7.0.14 may allow a remote unauthenticated attacker to crash the FGFM daemon via a specially crafted request, under rare cond...

Medienbericht
  • EPSS 0.21%
  • Veröffentlicht 08.04.2025 14:15:31
  • Zuletzt bearbeitet 09.06.2026 10:16:30

A storing passwords in a recoverable format in Fortinet FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions allows attacker to information disclosure via modification of LDAP server IP to point to...

Medienbericht
  • EPSS 0.38%
  • Veröffentlicht 08.04.2025 14:15:31
  • Zuletzt bearbeitet 25.07.2025 15:22:38

A improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in Fortinet FortiOS version 7.4.0 through 7.4.3, 7.2.0 through 7.2.7, 7.0.0 through 7.0.14, 6.4.0 through 6.4.15 and 6.2.0 through 6.2.16, Fortinet FortiPro...

  • EPSS 0.59%
  • Veröffentlicht 08.04.2025 14:15:30
  • Zuletzt bearbeitet 14.01.2026 14:16:08

Multiple issues including the use of uninitialized ressources [CWE-908] and excessive iteration [CWE-834] vulnerabilities vulnerability in Fortinet allows a VPN user to corrupt memory potentially leading to code or commands execution via specificall...

Medienbericht
  • EPSS 0.48%
  • Veröffentlicht 08.04.2025 14:15:30
  • Zuletzt bearbeitet 25.07.2025 15:22:20

A improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in Fortinet FortiOS version 7.4.0 through 7.4.4, 7.2.0 through 7.2.8, 7.0.0 through 7.0.15, 6.4.0 through 6.4.15 and before 6.2.16, Fortinet FortiProxy vers...

Warnung
  • EPSS 18.18%
  • Veröffentlicht 24.03.2025 15:39:48
  • Zuletzt bearbeitet 24.07.2025 19:56:34

A buffer underwrite ('buffer underflow') vulnerability in the administrative interface of Fortinet FortiOS version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.6, version 6.4.0 through 6.4.11 and version 6.2.12 and below, FortiProxy version 7.2.0 t...

  • EPSS 0.37%
  • Veröffentlicht 21.03.2025 16:15:13
  • Zuletzt bearbeitet 23.07.2025 15:48:43

An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiOS 6.4.1 and below, 6.2.9 and below may allow a remote unauthenticated attacker to either redirect users to malicious websites via a crafted "Host" header o...