CVE-2022-23439
- EPSS 0.06%
- Veröffentlicht 22.01.2025 10:15:07
- Zuletzt bearbeitet 12.02.2025 13:39:42
A externally controlled reference to a resource in another sphere in Fortinet FortiManager before version 7.4.3, FortiMail before version 7.0.3, FortiAnalyzer before version 7.4.3, FortiVoice version 7.0.0, 7.0.1 and before 6.4.8, FortiProxy before v...
CVE-2024-23664
- EPSS 0.25%
- Veröffentlicht 03.06.2024 10:15:12
- Zuletzt bearbeitet 21.01.2025 21:53:28
A URL redirection to untrusted site ('open redirect') in Fortinet FortiAuthenticator version 6.6.0, version 6.5.3 and below, version 6.4.9 and below may allow an attacker to to redirect users to an arbitrary website via a crafted URL.
CVE-2022-22302
- EPSS 0.07%
- Veröffentlicht 11.07.2023 09:15:09
- Zuletzt bearbeitet 21.11.2024 06:46:35
A clear text storage of sensitive information (CWE-312) vulnerability in both FortiGate version 6.4.0 through 6.4.1, 6.2.0 through 6.2.9 and 6.0.0 through 6.0.13 and FortiAuthenticator version 5.5.0 and all versions of 6.1 and 6.0 may allow a local u...
CVE-2022-35850
- EPSS 0.17%
- Veröffentlicht 11.04.2023 17:15:07
- Zuletzt bearbeitet 21.11.2024 07:11:49
An improper neutralization of script-related HTML tags in a web page vulnerability [CWE-80] in FortiAuthenticator versions 6.4.0 through 6.4.4, 6.3.0 through 6.3.3, all versions of 6.2 and 6.1 may allow a remote unauthenticated attacker to trigger a ...
CVE-2023-26208
- EPSS 5.07%
- Veröffentlicht 09.03.2023 15:15:09
- Zuletzt bearbeitet 21.11.2024 07:50:55
A improper restriction of excessive authentication attempts vulnerability [CWE-307] in Fortinet FortiAuthenticator 6.4.x and before allows a remote unauthenticated attacker to partially exhaust CPU and memory via sending numerous HTTP requests to th...
CVE-2021-26116
- EPSS 0.33%
- Veröffentlicht 06.04.2022 16:15:07
- Zuletzt bearbeitet 21.11.2024 05:55:53
An improper neutralization of special elements used in an OS command vulnerability in the command line interpreter of FortiAuthenticator before 6.3.1 may allow an authenticated attacker to execute unauthorized commands via specifically crafted argume...
CVE-2021-36177
- EPSS 0.17%
- Veröffentlicht 02.02.2022 11:15:07
- Zuletzt bearbeitet 21.11.2024 06:13:15
An improper access control vulnerability [CWE-284] in FortiAuthenticator HA service 6.3.2 and below, 6.2.x, 6.1.x, 6.0.x may allow an attacker on the same vlan as the HA management interface to make an unauthenticated direct connection to the FAC's d...
CVE-2021-43068
- EPSS 0.22%
- Veröffentlicht 09.12.2021 10:15:11
- Zuletzt bearbeitet 21.11.2024 06:28:38
A improper authentication in Fortinet FortiAuthenticator version 6.4.0 allows user to bypass the second factor of authentication via a RADIUS login portal.
CVE-2021-43067
- EPSS 0.4%
- Veröffentlicht 08.12.2021 12:15:07
- Zuletzt bearbeitet 21.11.2024 06:28:38
A exposure of sensitive information to an unauthorized actor in Fortinet FortiAuthenticator version 6.4.0, version 6.3.2 and below, version 6.2.1 and below, version 6.1.2 and below, version 6.0.7 to 6.0.1 allows attacker to duplicate a target LDAP us...
CVE-2021-22124
- EPSS 1.14%
- Veröffentlicht 04.08.2021 19:15:08
- Zuletzt bearbeitet 21.11.2024 05:49:33
An uncontrolled resource consumption (denial of service) vulnerability in the login modules of FortiSandbox 3.2.0 through 3.2.2, 3.1.0 through 3.1.4, and 3.0.0 through 3.0.6; and FortiAuthenticator before 6.0.6 may allow an unauthenticated attacker t...