Fortinet

Fortiproxy

101 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.04%
  • Veröffentlicht 08.12.2021 11:15:11
  • Zuletzt bearbeitet 21.11.2024 05:55:53

An improper access control vulnerability [CWE-284] in FortiOS autod daemon 7.0.0, 6.4.6 and below, 6.2.9 and below, 6.0.12 and below and FortiProxy 2.0.1 and below, 1.2.9 and below may allow an authenticated low-privileged attacker to escalate their ...

  • EPSS 0.08%
  • Veröffentlicht 08.12.2021 11:15:11
  • Zuletzt bearbeitet 21.11.2024 06:28:06

A buffer overflow [CWE-121] in the TFTP client library of FortiOS before 6.4.7 and FortiOS 7.0.0 through 7.0.2, may allow an authenticated local attacker to achieve arbitrary code execution via specially crafted command line arguments.

  • EPSS 0.62%
  • Veröffentlicht 03.06.2021 11:15:08
  • Zuletzt bearbeitet 21.11.2024 05:49:33

A stack-based buffer overflow vulnerability in FortiProxy physical appliance CLI 2.0.0 to 2.0.1, 1.2.0 to 1.2.9, 1.1.0 to 1.1.6, 1.0.0 to 1.0.7 may allow an authenticated, remote attacker to perform a Denial of Service attack by running the `diagnose...

  • EPSS 2.8%
  • Veröffentlicht 12.04.2021 15:15:13
  • Zuletzt bearbeitet 21.11.2024 04:32:42

A Stack-based Buffer Overflow vulnerability in the HTTPD daemon of FortiOS 6.0.10 and below, 6.2.2 and below and FortiProxy 1.0.x, 1.1.x, 1.2.9 and below, 2.0.0 and below may allow an authenticated remote attacker to crash the service by sending a ma...

  • EPSS 0.39%
  • Veröffentlicht 04.03.2021 18:15:13
  • Zuletzt bearbeitet 21.11.2024 05:49:33

An improper access control vulnerability in FortiProxy SSL VPN portal 2.0.0, 1.2.9 and below versions may allow an authenticated, remote attacker to access internal service such as the ZebOS Shell on the FortiProxy appliance through the Quick Connect...

  • EPSS 0.15%
  • Veröffentlicht 21.10.2020 14:15:20
  • Zuletzt bearbeitet 21.11.2024 05:36:05

A cleartext storage of sensitive information vulnerability in FortiOS command line interface in versions 6.2.4 and earlier and FortiProxy 2.0.0, 1.2.9 and earlier may allow an authenticated attacker to obtain sensitive information such as users passw...

Warnung
  • EPSS 94.47%
  • Veröffentlicht 04.06.2019 21:29:00
  • Zuletzt bearbeitet 27.01.2025 21:30:45

An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.3 to 5.6.7 and 5.4.6 to 5.4.12 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 to 1.1.6, 1.0.0 to 1.0.7 under SSL VPN web portal all...

  • EPSS 37.93%
  • Veröffentlicht 04.06.2019 21:29:00
  • Zuletzt bearbeitet 21.11.2024 03:46:59

A Cross-site Scripting (XSS) vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.7, 5.4.0 to 5.4.12, 5.2 and below and Fortinet FortiProxy 2.0.0, 1.2.8 and below under SSL VPN web portal allows attacker to execute unauthorized malicious sc...

  • EPSS 0.54%
  • Veröffentlicht 04.06.2019 21:29:00
  • Zuletzt bearbeitet 21.11.2024 03:46:59

A buffer overflow vulnerability in Fortinet FortiOS 6.0.0 through 6.0.4, 5.6.0 through 5.6.7, 5.4 and earlier versions and FortiProxy 2.0.0, 1.2.8 and earlier versions under SSL VPN web portal allows a non-authenticated attacker to perform a Denial-o...

Warnung
  • EPSS 87.79%
  • Veröffentlicht 04.06.2019 21:29:00
  • Zuletzt bearbeitet 27.01.2025 21:30:41

An Improper Authorization vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.8 and 5.4.1 to 5.4.10 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 to 1.1.6, 1.0.0 to 1.0.7 under SSL VPN web portal allows an unauthenticated attacker to modify ...