Fortinet

Fortitester

16 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.02%
  • Veröffentlicht 14.10.2025 15:23:03
  • Zuletzt bearbeitet 15.10.2025 17:36:57

A insertion of sensitive information into sent data in Fortinet FortiManager Cloud 7.4.1 through 7.4.3, FortiVoice 7.0.0 through 7.0.4, 6.4.0 through 6.4.9, 6.0.7 through 6.0.12, FortiMail 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.9...

  • EPSS 0.13%
  • Veröffentlicht 22.01.2025 10:15:07
  • Zuletzt bearbeitet 12.02.2025 13:39:42

A externally controlled reference to a resource in another sphere in Fortinet FortiManager before version 7.4.3, FortiMail before version 7.0.3, FortiAnalyzer before version 7.4.3, FortiVoice version 7.0.0, 7.0.1 and before 6.4.8, FortiProxy before v...

  • EPSS 0.07%
  • Veröffentlicht 13.12.2023 07:15:14
  • Zuletzt bearbeitet 21.11.2024 08:20:01

An improper neutralization of special elements used in an OS command vulnerability [CWE-78]  in the command line interpreter of FortiTester 2.3.0 through 7.2.3 may allow an authenticated attacker to execute unauthorized commands via specifically craf...

  • EPSS 0.1%
  • Veröffentlicht 13.09.2023 13:15:09
  • Zuletzt bearbeitet 21.11.2024 08:10:09

An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in the management interface of FortiTester 3.0.0 through 7.2.3 may allow an authenticated attacker to execute unauthorized commands via specifically crafted a...

  • EPSS 0.06%
  • Veröffentlicht 13.09.2023 13:15:09
  • Zuletzt bearbeitet 21.11.2024 08:20:01

A cleartext storage of sensitive information vulnerability [CWE-312] in FortiTester 2.3.0 through 7.2.3 may allow an attacker with access to the DB contents to retrieve the plaintext password of external servers configured in the device.

  • EPSS 0.07%
  • Veröffentlicht 13.09.2023 13:15:09
  • Zuletzt bearbeitet 21.11.2024 08:20:01

A use of hard-coded credentials vulnerability [CWE-798] in FortiTester 2.3.0 through 7.2.3 may allow an attacker who managed to get a shell on the device to access the database via shell commands.

  • EPSS 1.04%
  • Veröffentlicht 03.01.2023 17:15:10
  • Zuletzt bearbeitet 21.11.2024 07:11:48

Multiple improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerabilities [CWE-78] in FortiTester 7.1.0, 7.0 all versions, 4.0.0 through 4.2.0, 2.3.0 through 3.9.1 may allow an authenticated attacker to execu...

  • EPSS 0.28%
  • Veröffentlicht 02.11.2022 12:15:53
  • Zuletzt bearbeitet 21.11.2024 07:08:29

An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in the command line interpreter of FortiTester 3.0.0 through 3.9.1, 4.0.0 through 4.2.0, 7.0.0 through 7.1.0 may allow an authenticated attacker to execute un...

  • EPSS 0.05%
  • Veröffentlicht 02.11.2022 12:15:53
  • Zuletzt bearbeitet 21.11.2024 07:16:20

A hidden functionality vulnerability [CWE-1242] in FortiTester CLI 2.3.0 through 3.9.1, 4.0.0 through 4.2.0, 7.0.0 through 7.1.0 may allow a local, privileged user to obtain a root shell on the device via an undocumented command.

  • EPSS 3.97%
  • Veröffentlicht 18.10.2022 15:15:09
  • Zuletzt bearbeitet 21.11.2024 07:08:29

An improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerabilities [CWE-78] in Telnet login components of FortiTester 2.3.0 through 3.9.1, 4.0.0 through 4.2.0, 7.0.0 through 7.1.0 may allow an unauthenticate...