CVE-2022-26121
- EPSS 0.18%
- Veröffentlicht 10.10.2022 14:15:09
- Zuletzt bearbeitet 21.11.2024 06:53:28
An exposure of resource to wrong sphere vulnerability [CWE-668] in FortiAnalyzer and FortiManager GUI 7.0.0 through 7.0.3, 6.4.0 through 6.4.8, 6.2.0 through 6.2.9, 6.0.0 through 6.0.11, 5.6.0 through 5.6.11 may allow an unauthenticated and remote at...
CVE-2022-27483
- EPSS 5.37%
- Veröffentlicht 19.07.2022 14:15:08
- Zuletzt bearbeitet 21.11.2024 06:55:48
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiManager version 7.0.0 through 7.0.3, 6.4.0 through 6.4.7, 6.2.x and 6.0.x and FortiAnalyzer version 7.0.0 through 7.0.3, version 6.4.0 throu...
CVE-2022-26118
- EPSS 0.03%
- Veröffentlicht 18.07.2022 18:15:09
- Zuletzt bearbeitet 21.11.2024 06:53:28
A privilege chaining vulnerability [CWE-268] in FortiManager and FortiAnalyzer 6.0.x, 6.2.x, 6.4.0 through 6.4.7, 7.0.0 through 7.0.3 may allow a local and authenticated attacker with a restricted shell to escalate their privileges to root due to inc...
CVE-2021-26104
- EPSS 1.35%
- Veröffentlicht 06.04.2022 16:15:07
- Zuletzt bearbeitet 21.11.2024 05:55:52
Multiple OS command injection (CWE-78) vulnerabilities in the command line interface of FortiManager 6.2.7 and below, 6.4.5 and below and all versions of 6.2.x, 6.0.x and 5.6.x, FortiAnalyzer 6.2.7 and below, 6.4.5 and below and all versions of 6.2.x...
CVE-2022-22303
- EPSS 0.06%
- Veröffentlicht 02.03.2022 10:15:08
- Zuletzt bearbeitet 21.11.2024 06:46:36
An exposure of sensitive system information to an unauthorized control sphere vulnerability [CWE-497] in FortiManager versions prior to 7.0.2, 6.4.7 and 6.2.9 may allow a low privileged authenticated user to gain access to the FortiGate users credent...
CVE-2022-22300
- EPSS 0.14%
- Veröffentlicht 01.03.2022 19:15:08
- Zuletzt bearbeitet 21.11.2024 06:46:35
A improper handling of insufficient permissions or privileges in Fortinet FortiAnalyzer version 5.6.0 through 5.6.11, FortiAnalyzer version 6.0.0 through 6.0.11, FortiAnalyzer version 6.2.0 through 6.2.9, FortiAnalyzer version 6.4.0 through 6.4.7, Fo...
CVE-2021-42757
- EPSS 0.07%
- Veröffentlicht 08.12.2021 11:15:11
- Zuletzt bearbeitet 16.10.2025 10:15:36
A buffer overflow [CWE-121] in the TFTP client library of FortiOS before 6.4.7 and FortiOS 7.0.0 through 7.0.2, may allow an authenticated local attacker to achieve arbitrary code execution via specially crafted command line arguments.
CVE-2021-36192
- EPSS 0.05%
- Veröffentlicht 03.11.2021 11:15:08
- Zuletzt bearbeitet 21.11.2024 06:13:17
An exposure of sensitive information to an unauthorized actor [CWE-200] vulnerability in FortiManager 7.0.1 and below, 6.4.6 and below, 6.2.x, 6.0.x, 5.6.0 may allow a FortiGate user to see scripts from other ADOMS.
CVE-2021-26107
- EPSS 0.22%
- Veröffentlicht 02.11.2021 18:15:08
- Zuletzt bearbeitet 21.11.2024 05:55:52
An improper access control vulnerability [CWE-284] in FortiManager versions 6.4.4 and 6.4.5 may allow an authenticated attacker with a restricted user profile to modify the VPN tunnel status of other VDOMs using VPN Manager.
CVE-2021-36170
- EPSS 0.11%
- Veröffentlicht 06.10.2021 10:15:07
- Zuletzt bearbeitet 21.11.2024 06:13:14
An information disclosure vulnerability [CWE-200] in FortiAnalyzerVM and FortiManagerVM versions 7.0.0 and 6.4.6 and below may allow an authenticated attacker to read the FortiCloud credentials which were used to activate the trial license in clearte...