Fortinet

Fortiauthenticator

21 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.4%
  • Veröffentlicht 08.12.2021 12:15:07
  • Zuletzt bearbeitet 21.11.2024 06:28:38

A exposure of sensitive information to an unauthorized actor in Fortinet FortiAuthenticator version 6.4.0, version 6.3.2 and below, version 6.2.1 and below, version 6.1.2 and below, version 6.0.7 to 6.0.1 allows attacker to duplicate a target LDAP us...

  • EPSS 1.14%
  • Veröffentlicht 04.08.2021 19:15:08
  • Zuletzt bearbeitet 21.11.2024 05:49:33

An uncontrolled resource consumption (denial of service) vulnerability in the login modules of FortiSandbox 3.2.0 through 3.2.2, 3.1.0 through 3.1.4, and 3.0.0 through 3.0.6; and FortiAuthenticator before 6.0.6 may allow an unauthenticated attacker t...

  • EPSS 0.13%
  • Veröffentlicht 06.07.2021 11:15:08
  • Zuletzt bearbeitet 21.11.2024 05:52:11

Usage of hard-coded cryptographic keys to encrypt configuration files and debug logs in FortiAuthenticator versions before 6.3.0 may allow an attacker with access to the files or the CLI configuration to decrypt the sensitive data, via knowledge of t...

  • EPSS 0.53%
  • Veröffentlicht 07.01.2020 19:15:10
  • Zuletzt bearbeitet 21.11.2024 04:30:09

An improper neutralization of input during web page generation in FortiAuthenticator WEB UI 6.0.0 may allow an unauthenticated user to perform a cross-site scripting attack (XSS) via a parameter of the logon page.

  • EPSS 0.27%
  • Veröffentlicht 31.05.2018 22:29:00
  • Zuletzt bearbeitet 21.11.2024 04:15:08

A cross-site scripting (XSS) vulnerability in Fortinet FortiAuthenticator in versions 4.0.0 to before 5.3.0 "CSRF validation failure" page allows attacker to execute unauthorized script code via inject malicious scripts in HTTP referer header.

Exploit
  • EPSS 0.42%
  • Veröffentlicht 03.02.2015 16:59:31
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Cross-site scripting (XSS) vulnerability in Fortinet FortiAuthenticator 3.0.0 allows remote attackers to inject arbitrary web script or HTML via the operation parameter to cert/scep/.

Exploit
  • EPSS 0.06%
  • Veröffentlicht 03.02.2015 16:59:30
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Fortinet FortiAuthenticator 3.0.0 allows local users to bypass intended restrictions and gain privileges by creating /tmp/privexec/dbgcore_enable_shell_access and executing the "shell" command.

Exploit
  • EPSS 0.08%
  • Veröffentlicht 03.02.2015 16:59:29
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Fortinet FortiAuthenticator 3.0.0 allows local users to read arbitrary files via the -f flag to the dig command.

  • EPSS 0.27%
  • Veröffentlicht 03.02.2015 16:59:28
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Fortinet FortiAuthenticator 3.0.0 logs the PostgreSQL usernames and passwords in cleartext, which allows remote administrators to obtain sensitive information by reading the log at debug/startup/.

  • EPSS 0.71%
  • Veröffentlicht 03.02.2015 16:59:27
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Fortinet FortiAuthenticator 3.0.0 has a password of (1) slony for the slony PostgreSQL user and (2) www-data for the www-data PostgreSQL user, which makes it easier for remote attackers to obtain access via unspecified vectors.