CVE-2022-23439
- EPSS 0.07%
- Veröffentlicht 22.01.2025 10:15:07
- Zuletzt bearbeitet 12.02.2025 13:39:42
A externally controlled reference to a resource in another sphere in Fortinet FortiManager before version 7.4.3, FortiMail before version 7.0.3, FortiAnalyzer before version 7.4.3, FortiVoice version 7.0.0, 7.0.1 and before 6.4.8, FortiProxy before v...
CVE-2024-54021
- EPSS 0.09%
- Veröffentlicht 14.01.2025 14:15:34
- Zuletzt bearbeitet 08.08.2025 16:03:42
An Improper Neutralization of CRLF Sequences in HTTP Headers ('http response splitting') vulnerability [CWE-113] in Fortinet FortiOS 7.2.0 through 7.6.0, FortiProxy 7.2.0 through 7.4.5 may allow a remote unauthenticated attacker to bypass the file fi...
CVE-2024-55591
- EPSS 94.18%
- Veröffentlicht 14.01.2025 14:15:34
- Zuletzt bearbeitet 23.01.2025 02:00:02
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy version 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12 allows a remote attacker to gain super-admin privi...
CVE-2024-48886
- EPSS 0.13%
- Veröffentlicht 14.01.2025 14:15:33
- Zuletzt bearbeitet 03.02.2025 22:16:04
A weak authentication in Fortinet FortiOS versions 7.4.0 through 7.4.4, 7.2.0 through 7.2.8, 7.0.0 through 7.0.15, 6.4.0 through 6.4.15, FortiProxy versions 7.4.0 through 7.4.4, 7.2.0 through 7.2.10, 7.0.0 through 7.0.17, 2.0.0 through 2.0.14, FortiM...
CVE-2024-48884
- EPSS 0.54%
- Veröffentlicht 14.01.2025 14:15:32
- Zuletzt bearbeitet 08.08.2025 16:00:27
A improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiManager versions 7.6.0 through 7.6.1, 7.4.1 through 7.4.3, FortiOS versions 7.6.0, 7.4.0 through 7.4.4, 7.2.5 through 7.2.9, 7.0.0 through 7.0.15, 6.4.0...
CVE-2024-33510
- EPSS 0.1%
- Veröffentlicht 12.11.2024 19:15:09
- Zuletzt bearbeitet 17.01.2025 20:35:31
An improper neutralization of special elements in output used by a downstream component ('Injection') vulnerability [CWE-74] in FortiOS version 7.4.3 and below, version 7.2.8 and below, version 7.0.16 and below; FortiProxy version 7.4.3 and below, ve...
CVE-2024-26011
- EPSS 0.05%
- Veröffentlicht 12.11.2024 19:15:08
- Zuletzt bearbeitet 12.12.2024 19:33:58
A missing authentication for critical function in Fortinet FortiManager version 7.4.0 through 7.4.2, 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through 6.4.14, FortiPAM version 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiProxy version...
CVE-2022-45862
- EPSS 0.21%
- Veröffentlicht 13.08.2024 16:15:07
- Zuletzt bearbeitet 22.08.2024 14:32:16
An insufficient session expiration vulnerability [CWE-613] vulnerability in FortiOS 7.2.5 and below, 7.0 all versions, 6.4 all versions; FortiProxy 7.2 all versions, 7.0 all versions; FortiPAM 1.3 all versions, 1.2 all versions, 1.1 all versions, 1.0...
CVE-2024-26015
- EPSS 0.05%
- Veröffentlicht 09.07.2024 16:15:04
- Zuletzt bearbeitet 21.11.2024 09:01:45
An incorrect parsing of numbers with different radices vulnerability [CWE-1389] in FortiProxy version 7.4.3 and below, version 7.2.10 and below, version 7.0.17 and below and FortiOS version 7.4.3 and below, version 7.2.8 and below, version 7.0.15 and...
CVE-2024-26010
- EPSS 0.17%
- Veröffentlicht 11.06.2024 15:16:04
- Zuletzt bearbeitet 11.12.2024 19:54:35
A stack-based buffer overflow in Fortinet FortiPAM version 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiWeb, FortiAuthenticator, FortiSwitchManager version 7.2.0 through 7.2.3, 7.0.1 through 7.0.3, FortiOS version 7.4.0 through 7.4.3, 7.2.0 ...