CVE-2021-43081
- EPSS 0.92%
- Veröffentlicht 11.05.2022 15:15:08
- Zuletzt bearbeitet 21.11.2024 06:28:39
An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiOS version 7.0.3 and below, 6.4.8 and below, 6.2.10 and below, 6.0.14 to 6.0.0. and in FortiProxy version 7.0.1 and below, 2.0.7 to 2.0.0 web filter overrid...
CVE-2021-43206
- EPSS 0.39%
- Veröffentlicht 04.05.2022 16:15:08
- Zuletzt bearbeitet 21.11.2024 06:28:50
A server-generated error message containing sensitive information in Fortinet FortiOS 7.0.0 through 7.0.3, 6.4.0 through 6.4.8, 6.2.x, 6.0.x and FortiProxy 7.0.0 through 7.0.1, 2.0.x allows malicious webservers to retrieve a web proxy's client userna...
CVE-2021-26092
- EPSS 0.53%
- Veröffentlicht 24.02.2022 03:15:43
- Zuletzt bearbeitet 21.11.2024 05:55:51
Failure to sanitize input in the SSL VPN web portal of FortiOS 5.2.10 through 5.2.15, 5.4.0 through 5.4.13, 5.6.0 through 5.6.14, 6.0.0 through 6.0.12, 6.2.0 through 6.2.7, 6.4.0 through 6.4.4; and FortiProxy 1.2.0 through 1.2.9, 2.0.0 through 2.0.1 ...
CVE-2021-41024
- EPSS 1%
- Veröffentlicht 08.12.2021 13:15:07
- Zuletzt bearbeitet 21.11.2024 06:25:17
A relative path traversal [CWE-23] vulnerabiltiy in FortiOS versions 7.0.0 and 7.0.1 and FortiProxy verison 7.0.0 may allow an unauthenticated, unauthorized attacker to inject path traversal character sequences to disclose sensitive information of th...
CVE-2021-26103
- EPSS 0.29%
- Veröffentlicht 08.12.2021 12:15:07
- Zuletzt bearbeitet 21.11.2024 05:55:52
An insufficient verification of data authenticity vulnerability (CWE-345) in the user interface of FortiProxy verison 2.0.3 and below, 1.2.11 and below and FortiGate verison 7.0.0, 6.4.6 and below, 6.2.9 and below of SSL VPN portal may allow a remote...
CVE-2021-26110
- EPSS 0.15%
- Veröffentlicht 08.12.2021 11:15:11
- Zuletzt bearbeitet 21.11.2024 05:55:53
An improper access control vulnerability [CWE-284] in FortiOS autod daemon 7.0.0, 6.4.6 and below, 6.2.9 and below, 6.0.12 and below and FortiProxy 2.0.1 and below, 1.2.9 and below may allow an authenticated low-privileged attacker to escalate their ...
CVE-2021-42757
- EPSS 0.07%
- Veröffentlicht 08.12.2021 11:15:11
- Zuletzt bearbeitet 16.10.2025 10:15:36
A buffer overflow [CWE-121] in the TFTP client library of FortiOS before 6.4.7 and FortiOS 7.0.0 through 7.0.2, may allow an authenticated local attacker to achieve arbitrary code execution via specially crafted command line arguments.
CVE-2021-22130
- EPSS 0.62%
- Veröffentlicht 03.06.2021 11:15:08
- Zuletzt bearbeitet 21.11.2024 05:49:33
A stack-based buffer overflow vulnerability in FortiProxy physical appliance CLI 2.0.0 to 2.0.1, 1.2.0 to 1.2.9, 1.1.0 to 1.1.6, 1.0.0 to 1.0.7 may allow an authenticated, remote attacker to perform a Denial of Service attack by running the `diagnose...
CVE-2019-17656
- EPSS 2.8%
- Veröffentlicht 12.04.2021 15:15:13
- Zuletzt bearbeitet 21.11.2024 04:32:42
A Stack-based Buffer Overflow vulnerability in the HTTPD daemon of FortiOS 6.0.10 and below, 6.2.2 and below and FortiProxy 1.0.x, 1.1.x, 1.2.9 and below, 2.0.0 and below may allow an authenticated remote attacker to crash the service by sending a ma...
CVE-2021-22128
- EPSS 0.39%
- Veröffentlicht 04.03.2021 18:15:13
- Zuletzt bearbeitet 21.11.2024 05:49:33
An improper access control vulnerability in FortiProxy SSL VPN portal 2.0.0, 1.2.9 and below versions may allow an authenticated, remote attacker to access internal service such as the ZebOS Shell on the FortiProxy appliance through the Quick Connect...