Fortinet

Fortiauthenticator

19 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.06%
  • Published 22.01.2025 10:15:07
  • Last modified 12.02.2025 13:39:42

A externally controlled reference to a resource in another sphere in Fortinet FortiManager before version 7.4.3, FortiMail before version 7.0.3, FortiAnalyzer before version 7.4.3, FortiVoice version 7.0.0, 7.0.1 and before 6.4.8, FortiProxy before v...

  • EPSS 0.25%
  • Published 03.06.2024 10:15:12
  • Last modified 21.01.2025 21:53:28

A URL redirection to untrusted site ('open redirect') in Fortinet FortiAuthenticator version 6.6.0, version 6.5.3 and below, version 6.4.9 and below may allow an attacker to to redirect users to an arbitrary website via a crafted URL.

  • EPSS 0.07%
  • Published 11.07.2023 09:15:09
  • Last modified 21.11.2024 06:46:35

A clear text storage of sensitive information (CWE-312) vulnerability in both FortiGate version 6.4.0 through 6.4.1, 6.2.0 through 6.2.9 and 6.0.0 through 6.0.13 and FortiAuthenticator version 5.5.0 and all versions of 6.1 and 6.0 may allow a local u...

  • EPSS 0.17%
  • Published 11.04.2023 17:15:07
  • Last modified 21.11.2024 07:11:49

An improper neutralization of script-related HTML tags in a web page vulnerability [CWE-80] in FortiAuthenticator versions 6.4.0 through 6.4.4, 6.3.0 through 6.3.3, all versions of 6.2 and 6.1 may allow a remote unauthenticated attacker to trigger a ...

  • EPSS 5.07%
  • Published 09.03.2023 15:15:09
  • Last modified 21.11.2024 07:50:55

A improper restriction of excessive authentication attempts vulnerability [CWE-307] in Fortinet FortiAuthenticator 6.4.x and before allows a remote unauthenticated attacker to partially exhaust CPU and memory via sending numerous HTTP requests to th...

  • EPSS 0.33%
  • Published 06.04.2022 16:15:07
  • Last modified 21.11.2024 05:55:53

An improper neutralization of special elements used in an OS command vulnerability in the command line interpreter of FortiAuthenticator before 6.3.1 may allow an authenticated attacker to execute unauthorized commands via specifically crafted argume...

  • EPSS 0.17%
  • Published 02.02.2022 11:15:07
  • Last modified 21.11.2024 06:13:15

An improper access control vulnerability [CWE-284] in FortiAuthenticator HA service 6.3.2 and below, 6.2.x, 6.1.x, 6.0.x may allow an attacker on the same vlan as the HA management interface to make an unauthenticated direct connection to the FAC's d...

  • EPSS 0.22%
  • Published 09.12.2021 10:15:11
  • Last modified 21.11.2024 06:28:38

A improper authentication in Fortinet FortiAuthenticator version 6.4.0 allows user to bypass the second factor of authentication via a RADIUS login portal.

  • EPSS 0.4%
  • Published 08.12.2021 12:15:07
  • Last modified 21.11.2024 06:28:38

A exposure of sensitive information to an unauthorized actor in Fortinet FortiAuthenticator version 6.4.0, version 6.3.2 and below, version 6.2.1 and below, version 6.1.2 and below, version 6.0.7 to 6.0.1 allows attacker to duplicate a target LDAP us...

  • EPSS 1.14%
  • Published 04.08.2021 19:15:08
  • Last modified 21.11.2024 05:49:33

An uncontrolled resource consumption (denial of service) vulnerability in the login modules of FortiSandbox 3.2.0 through 3.2.2, 3.1.0 through 3.1.4, and 3.0.0 through 3.0.6; and FortiAuthenticator before 6.0.6 may allow an unauthenticated attacker t...