CVE-2024-50565
- EPSS 0.14%
- Veröffentlicht 08.04.2025 14:15:31
- Zuletzt bearbeitet 25.07.2025 15:22:38
A improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in Fortinet FortiOS version 7.4.0 through 7.4.3, 7.2.0 through 7.2.7, 7.0.0 through 7.0.14, 6.4.0 through 6.4.15 and 6.2.0 through 6.2.16, Fortinet FortiPro...
CVE-2024-26013
- EPSS 0.15%
- Veröffentlicht 08.04.2025 14:15:30
- Zuletzt bearbeitet 25.07.2025 15:22:20
A improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in Fortinet FortiOS version 7.4.0 through 7.4.4, 7.2.0 through 7.2.8, 7.0.0 through 7.0.15, 6.4.0 through 6.4.15 and before 6.2.16, Fortinet FortiProxy vers...
CVE-2021-24008
- EPSS 0.25%
- Veröffentlicht 28.03.2025 10:13:32
- Zuletzt bearbeitet 24.07.2025 19:57:26
An exposure of sensitive system information to an unauthorized control sphere vulnerability [CWE-497] in FortiDDoS version 5.4.0, version 5.3.2 and below, version 5.2.0, version 5.1.0, version 5.0.0, version 4.7.0, version 4.6.0, version 4.5.0, versi...
CVE-2022-23439
- EPSS 0.21%
- Veröffentlicht 22.01.2025 10:15:07
- Zuletzt bearbeitet 14.01.2026 14:16:06
A externally controlled reference to a resource in another sphere vulnerability in Fortinet allows attacker to poison web caches via crafted HTTP requests, where the `Host` header points to an arbitrary webserver
CVE-2024-48885
- EPSS 0.3%
- Veröffentlicht 16.01.2025 09:15:06
- Zuletzt bearbeitet 14.01.2026 13:16:09
A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiRecorder 7.2.0 through 7.2.1, FortiRecorder 7.0.0 through 7.0.4, FortiVoice 7.0.0 through 7.0.4, FortiVoice 6.4.0 through 6.4.9, FortiVoic...
CVE-2024-48884
- EPSS 50.28%
- Veröffentlicht 14.01.2025 14:15:32
- Zuletzt bearbeitet 14.01.2026 13:16:08
A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiManager 7.6.0 through 7.6.1, FortiManager 7.4.1 through 7.4.3, FortiManager Cloud 7.4.1 through 7.4.3, FortiOS 7.6.0, FortiOS 7.4.0 throug...
CVE-2024-40587
- EPSS 0.1%
- Veröffentlicht 14.01.2025 14:15:31
- Zuletzt bearbeitet 31.01.2025 16:34:37
An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiVoice version 7.0.0 through 7.0.4 and before 6.4.9 allows an authenticated privileged attacker to execute unauthoriz...
CVE-2023-37931
- EPSS 0.44%
- Veröffentlicht 14.01.2025 14:15:26
- Zuletzt bearbeitet 22.07.2025 21:25:52
An improper neutralization of special elements used in an sql command ('sql injection') vulnerability [CWE-88] in FortiVoice Entreprise version 7.0.0 through 7.0.1 and before 6.4.8 allows an authenticated attacker to perform a blind sql injection att...
CVE-2023-40720
- EPSS 0.04%
- Veröffentlicht 14.05.2024 17:15:19
- Zuletzt bearbeitet 21.11.2024 08:20:01
An authorization bypass through user-controlled key vulnerability [CWE-639] in FortiVoiceEntreprise version 7.0.0 through 7.0.1 and before 6.4.8 allows an authenticated attacker to read the SIP configuration of other users via crafted HTTP or HTTPS r...
CVE-2023-37932
- EPSS 0.48%
- Veröffentlicht 10.01.2024 18:15:45
- Zuletzt bearbeitet 21.11.2024 08:12:29
An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability [CWE-22] in FortiVoiceEntreprise version 7.0.0 and before 6.4.7 allows an authenticated attacker to read arbitrary files from the system via sending craft...