Fortinet

FortiOS

282 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.34%
  • Veröffentlicht 17.03.2025 13:40:57
  • Zuletzt bearbeitet 24.07.2025 20:15:34

An Improper Neutralization of Input vulnerability affecting FortiGate version 6.2.0 through 6.2.1, 6.0.0 through 6.0.6 in the hostname parameter of a DHCP packet under DHCP monitor page may allow an unauthenticated attacker in the same network as the...

  • EPSS 0.31%
  • Veröffentlicht 17.03.2025 13:40:48
  • Zuletzt bearbeitet 14.08.2025 21:11:34

FortiOS 6.2 running AV engine version 6.00142 and below, FortiOS 6.4 running AV engine version 6.00144 and below and FortiClient 6.2 running AV engine version 6.00137 and below may not immediately detect certain types of malformed or non-standard RAR...

  • EPSS 0.56%
  • Veröffentlicht 17.03.2025 13:06:16
  • Zuletzt bearbeitet 24.07.2025 20:15:46

An exposure of sensitive information to an unauthorized actor vulnerability in FortiOS version 6.2.4 and below, version 6.0.10 and belowmay allow remote authenticated actors to read the SSL VPN events log entries of users in other VDOMs by executing...

  • EPSS 0.43%
  • Veröffentlicht 17.03.2025 13:05:08
  • Zuletzt bearbeitet 24.07.2025 20:15:24

An improper neutralization of input during web page generation in the SSL VPN portal of FortiProxy version 2.0.0, version 1.2.9 and below and FortiOS version 6.2.1 and below, version 6.0.8 and below, version 5.6.12 may allow a remote authenticated at...

  • EPSS 0.59%
  • Veröffentlicht 14.03.2025 10:15:14
  • Zuletzt bearbeitet 24.07.2025 20:00:45

An improper neutralization of input during web page Generation vulnerability [CWE-79] in FortiOS version 7.4.3 and below, version 7.2.7 and below, version 7.0.13 and below and FortiProxy version 7.4.3 and below, version 7.2.9 and below, version 7.0.1...

  • EPSS 0.7%
  • Veröffentlicht 11.03.2025 14:54:33
  • Zuletzt bearbeitet 24.07.2025 19:06:14

A use of externally-controlled format string vulnerability [CWE-134] in FortiOS version 7.4.0 through 7.4.4, version 7.2.0 through 7.2.9, version 7.0.0 through 7.0.15 and before 6.4.15, FortiProxy version 7.4.0 through 7.4.6, version 7.2.0 through 7....

Warnung Medienbericht
  • EPSS 3.58%
  • Veröffentlicht 11.02.2025 17:15:34
  • Zuletzt bearbeitet 05.08.2026 05:16:43

An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS 7.0.0 through 7.0.16 and FortiProxy 7.2.0 through 7.2.12, 7.0.0 through 7.0.19 may allow a remote unauthenticated attacker with prior knowledge of u...

  • EPSS 1.02%
  • Veröffentlicht 11.02.2025 17:15:22
  • Zuletzt bearbeitet 17.07.2025 20:13:41

A stack-based buffer overflow [CWE-121] vulnerability in Fortinet FortiOS version 7.2.4 through 7.2.8 and version 7.4.0 through 7.4.4 allows a remote unauthenticated attacker to execute arbitrary code or commands via crafted UDP packets through the C...

  • EPSS 0.61%
  • Veröffentlicht 11.02.2025 17:15:22
  • Zuletzt bearbeitet 17.07.2025 20:12:01

An incorrect privilege assignment vulnerability [CWE-266] in Fortinet FortiOS version 7.6.0, 7.4.0 through 7.4.4, 7.2.0 through 7.2.9 and before 7.0.15 allows an authenticated admin whose access profile has the Security Fabric permission to escalate ...

  • EPSS 0.24%
  • Veröffentlicht 11.02.2025 17:15:21
  • Zuletzt bearbeitet 14.01.2026 15:15:54

A use of externally-controlled format string vulnerability [CWE-134] vulnerability in Fortinet allows a privileged attacker to execute arbitrary code or commands via specially crafted requests.