Fortinet

Fortivoice

22 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.23%
  • Veröffentlicht 28.03.2025 10:13:32
  • Zuletzt bearbeitet 24.07.2025 19:57:26

An exposure of sensitive system information to an unauthorized control sphere vulnerability [CWE-497] in FortiDDoS version 5.4.0, version 5.3.2 and below, version 5.2.0, version 5.1.0, version 5.0.0, version 4.7.0, version 4.6.0, version 4.5.0, versi...

  • EPSS 0.13%
  • Veröffentlicht 22.01.2025 10:15:07
  • Zuletzt bearbeitet 14.01.2026 14:16:06

A externally controlled reference to a resource in another sphere vulnerability in Fortinet allows attacker to poison web caches via crafted HTTP requests, where the `Host` header points to an arbitrary webserver

  • EPSS 0.08%
  • Veröffentlicht 16.01.2025 09:15:06
  • Zuletzt bearbeitet 14.01.2026 13:16:09

A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiRecorder 7.2.0 through 7.2.1, FortiRecorder 7.0.0 through 7.0.4, FortiVoice 7.0.0 through 7.0.4, FortiVoice 6.4.0 through 6.4.9, FortiVoic...

  • EPSS 0.57%
  • Veröffentlicht 14.01.2025 14:15:32
  • Zuletzt bearbeitet 14.01.2026 13:16:08

A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiManager 7.6.0 through 7.6.1, FortiManager 7.4.1 through 7.4.3, FortiManager Cloud 7.4.1 through 7.4.3, FortiOS 7.6.0, FortiOS 7.4.0 throug...

  • EPSS 0.24%
  • Veröffentlicht 14.01.2025 14:15:31
  • Zuletzt bearbeitet 31.01.2025 16:34:37

An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiVoice version 7.0.0 through 7.0.4 and before 6.4.9 allows an authenticated privileged attacker to execute unauthoriz...

  • EPSS 0.27%
  • Veröffentlicht 14.01.2025 14:15:26
  • Zuletzt bearbeitet 22.07.2025 21:25:52

An improper neutralization of special elements used in an sql command ('sql injection') vulnerability [CWE-88] in FortiVoice Entreprise version 7.0.0 through 7.0.1 and before 6.4.8 allows an authenticated attacker to perform a blind sql injection att...

  • EPSS 0.04%
  • Veröffentlicht 14.05.2024 17:15:19
  • Zuletzt bearbeitet 21.11.2024 08:20:01

An authorization bypass through user-controlled key vulnerability [CWE-639] in FortiVoiceEntreprise version 7.0.0 through 7.0.1 and before 6.4.8 allows an authenticated attacker to read the SIP configuration of other users via crafted HTTP or HTTPS r...

  • EPSS 0.48%
  • Veröffentlicht 10.01.2024 18:15:45
  • Zuletzt bearbeitet 21.11.2024 08:12:29

An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability [CWE-22] in FortiVoiceEntreprise version 7.0.0 and before 6.4.7 allows an authenticated attacker to read arbitrary files from the system via sending craft...

  • EPSS 0.44%
  • Veröffentlicht 13.12.2023 07:15:10
  • Zuletzt bearbeitet 21.11.2024 06:55:49

A cross-site request forgery (CSRF) in Fortinet FortiVoiceEnterprise version 6.4.x, 6.0.x, FortiSwitch version 7.0.0 through 7.0.4, 6.4.0 through 6.4.10, 6.2.0 through 6.2.7, 6.0.x, FortiMail version 7.0.0 through 7.0.3, 6.4.0 through 6.4.6, 6.2.x, 6...

  • EPSS 0.1%
  • Veröffentlicht 18.07.2022 17:15:08
  • Zuletzt bearbeitet 21.11.2024 06:28:06

An integer overflow / wraparound vulnerability [CWE-190] in FortiSwitch 7.0.2 and below, 6.4.9 and below, 6.2.x, 6.0.x; FortiRecorder 6.4.2 and below, 6.0.10 and below; FortiOS 7.0.2 and below, 6.4.8 and below, 6.2.10 and below, 6.0.x; FortiProxy 7.0...