CVE-2023-50178
- EPSS 0.16%
- Veröffentlicht 09.07.2024 16:15:03
- Zuletzt bearbeitet 21.11.2024 08:36:36
An improper certificate validation vulnerability [CWE-295] in FortiADC 7.4.0, 7.2.0 through 7.2.3, 7.1 all versions, 7.0 all versions, 6.2 all versions, 6.1 all versions and 6.0 all versions may allow a remote and unauthenticated attacker to perform ...
CVE-2023-50181
- EPSS 0.16%
- Veröffentlicht 09.07.2024 16:15:03
- Zuletzt bearbeitet 21.11.2024 08:36:36
An improper access control vulnerability [CWE-284] in Fortinet FortiADC version 7.4.0 through 7.4.1 and before 7.2.4 allows a read only authenticated attacker to perform some write actions via crafted HTTP or HTTPS requests.
CVE-2023-50180
- EPSS 0.14%
- Veröffentlicht 14.05.2024 17:15:27
- Zuletzt bearbeitet 21.11.2024 08:36:36
An exposure of sensitive system information to an unauthorized control sphere vulnerability [CWE-497] in FortiADC version 7.4.1 and below, version 7.2.3 and below, version 7.1.4 and below, version 7.0.5 and below, version 6.2.6 and below may allow a ...
CVE-2023-41673
- EPSS 0.16%
- Veröffentlicht 13.12.2023 07:15:15
- Zuletzt bearbeitet 21.11.2024 08:21:27
An improper authorization vulnerability [CWE-285] in Fortinet FortiADC version 7.4.0 and before 7.2.2 may allow a low privileged user to read or backup the full system configuration via HTTP or HTTPS requests.
CVE-2023-29177
- EPSS 0.06%
- Veröffentlicht 14.11.2023 19:15:24
- Zuletzt bearbeitet 21.11.2024 07:56:39
Multiple buffer copy without checking size of input ('classic buffer overflow') vulnerabilities [CWE-120] in FortiADC version 7.2.0 and before 7.1.2 & FortiDDoS-F version 6.5.0 and before 6.4.1 allows a privileged attacker to execute arbitrary code o...
CVE-2023-25603
- EPSS 0.2%
- Veröffentlicht 14.11.2023 19:15:19
- Zuletzt bearbeitet 21.11.2024 07:49:48
A permissive cross-domain policy with untrusted domains vulnerability in Fortinet FortiADC 7.1.0 - 7.1.1, FortiDDoS-F 6.3.0 - 6.3.4 and 6.4.0 - 6.4.1 allow an unauthorized attacker to carry out privileged actions and retrieve sensitive information vi...
CVE-2023-26205
- EPSS 0.2%
- Veröffentlicht 14.11.2023 18:15:28
- Zuletzt bearbeitet 21.11.2024 07:50:54
An improper access control vulnerability [CWE-284] in FortiADC automation feature 7.1.0 through 7.1.2, 7.0 all versions, 6.2 all versions, 6.1 all versions may allow an authenticated low-privileged attacker to escalate their privileges to super_admin...
CVE-2023-25607
- EPSS 0.15%
- Veröffentlicht 10.10.2023 17:15:11
- Zuletzt bearbeitet 21.11.2024 07:49:49
An improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78 ] in FortiManager 7.2.0 through 7.2.2, 7.0.0 through 7.0.7, 6.4.0 through 6.4.11, 6.2 all versions, 6.0 all versions, FortiAnalyzer 7....
CVE-2022-35849
- EPSS 0.31%
- Veröffentlicht 13.09.2023 13:15:07
- Zuletzt bearbeitet 21.11.2024 07:11:48
An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in the management interface of FortiADC 7.1.0 through 7.1.1, 7.0.0 through 7.0.3, 6.2.0 through 6.2.5 and 6.1.0 all versions may allow an authenticated attac...
CVE-2023-28000
- EPSS 0.08%
- Veröffentlicht 13.06.2023 09:15:16
- Zuletzt bearbeitet 21.11.2024 07:53:54
An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in FortiADC CLI 7.1.0, 7.0.0 through 7.0.3, 6.2.0 through 6.2.4, 6.1 all versions, 6.0 all versions may allow a local and authenticated attacker to execute un...