Fortinet

Fortivoice

21 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.13%
  • Veröffentlicht 22.01.2025 10:15:07
  • Zuletzt bearbeitet 12.02.2025 13:39:42

A externally controlled reference to a resource in another sphere in Fortinet FortiManager before version 7.4.3, FortiMail before version 7.0.3, FortiAnalyzer before version 7.4.3, FortiVoice version 7.0.0, 7.0.1 and before 6.4.8, FortiProxy before v...

  • EPSS 0.08%
  • Veröffentlicht 16.01.2025 09:15:06
  • Zuletzt bearbeitet 24.09.2025 15:25:58

A improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiRecorder versions 7.2.0 through 7.2.1, 7.0.0 through 7.0.4, FortiWeb versions 7.6.0, 7.4.0 through 7.4.4, 7.2.0 through 7.2.10, 7.0.0 through 7.0.10, 6....

  • EPSS 0.57%
  • Veröffentlicht 14.01.2025 14:15:32
  • Zuletzt bearbeitet 08.08.2025 16:00:27

A improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiManager versions 7.6.0 through 7.6.1, 7.4.1 through 7.4.3, FortiOS versions 7.6.0, 7.4.0 through 7.4.4, 7.2.5 through 7.2.9, 7.0.0 through 7.0.15, 6.4.0...

  • EPSS 0.3%
  • Veröffentlicht 14.01.2025 14:15:31
  • Zuletzt bearbeitet 31.01.2025 16:34:37

An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiVoice version 7.0.0 through 7.0.4 and before 6.4.9 allows an authenticated privileged attacker to execute unauthoriz...

  • EPSS 0.2%
  • Veröffentlicht 14.01.2025 14:15:26
  • Zuletzt bearbeitet 22.07.2025 21:25:52

An improper neutralization of special elements used in an sql command ('sql injection') vulnerability [CWE-88] in FortiVoice Entreprise version 7.0.0 through 7.0.1 and before 6.4.8 allows an authenticated attacker to perform a blind sql injection att...

  • EPSS 0.04%
  • Veröffentlicht 14.05.2024 17:15:19
  • Zuletzt bearbeitet 21.11.2024 08:20:01

An authorization bypass through user-controlled key vulnerability [CWE-639] in FortiVoiceEntreprise version 7.0.0 through 7.0.1 and before 6.4.8 allows an authenticated attacker to read the SIP configuration of other users via crafted HTTP or HTTPS r...

  • EPSS 0.48%
  • Veröffentlicht 10.01.2024 18:15:45
  • Zuletzt bearbeitet 21.11.2024 08:12:29

An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability [CWE-22] in FortiVoiceEntreprise version 7.0.0 and before 6.4.7 allows an authenticated attacker to read arbitrary files from the system via sending craft...

  • EPSS 0.44%
  • Veröffentlicht 13.12.2023 07:15:10
  • Zuletzt bearbeitet 21.11.2024 06:55:49

A cross-site request forgery (CSRF) in Fortinet FortiVoiceEnterprise version 6.4.x, 6.0.x, FortiSwitch version 7.0.0 through 7.0.4, 6.4.0 through 6.4.10, 6.2.0 through 6.2.7, 6.0.x, FortiMail version 7.0.0 through 7.0.3, 6.4.0 through 6.4.6, 6.2.x, 6...

  • EPSS 0.09%
  • Veröffentlicht 18.07.2022 17:15:08
  • Zuletzt bearbeitet 21.11.2024 06:28:06

An integer overflow / wraparound vulnerability [CWE-190] in FortiSwitch 7.0.2 and below, 6.4.9 and below, 6.2.x, 6.0.x; FortiRecorder 6.4.2 and below, 6.0.10 and below; FortiOS 7.0.2 and below, 6.4.8 and below, 6.2.10 and below, 6.0.x; FortiProxy 7.0...

  • EPSS 0.07%
  • Veröffentlicht 08.12.2021 11:15:11
  • Zuletzt bearbeitet 16.10.2025 10:15:36

A buffer overflow [CWE-121] in the TFTP client library of FortiOS before 6.4.7 and FortiOS 7.0.0 through 7.0.2, may allow an authenticated local attacker to achieve arbitrary code execution via specially crafted command line arguments.