CVE-2021-24008
- EPSS 0.07%
- Published 28.03.2025 10:13:32
- Last modified 24.07.2025 19:57:26
An exposure of sensitive system information to an unauthorized control sphere vulnerability [CWE-497] in FortiDDoS version 5.4.0, version 5.3.2 and below, version 5.2.0, version 5.1.0, version 5.0.0, version 4.7.0, version 4.6.0, version 4.5.0, versi...
CVE-2022-23439
- EPSS 0.06%
- Published 22.01.2025 10:15:07
- Last modified 12.02.2025 13:39:42
A externally controlled reference to a resource in another sphere in Fortinet FortiManager before version 7.4.3, FortiMail before version 7.0.3, FortiAnalyzer before version 7.4.3, FortiVoice version 7.0.0, 7.0.1 and before 6.4.8, FortiProxy before v...
CVE-2022-27486
- EPSS 0.37%
- Published 13.08.2024 16:15:07
- Last modified 22.08.2024 14:29:44
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiDDoS version 5.5.0 through 5.5.1, 5.4.2 through 5.4.0, 5.3.0 through 5.3.1, 5.2.0, 5.1.0, 5.0.0, 4.7.0, 4.6.0 and 4.5.0 and FortiDDoS-F vers...
CVE-2022-40679
- EPSS 0.11%
- Published 11.04.2023 17:15:07
- Last modified 21.11.2024 07:21:50
An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in FortiADC 5.x all versions, 6.0 all versions, 6.1 all versions, 6.2.0 through 6.2.4, 7.0.0 through 7.0.3, 7.1.0; FortiDDoS 4.x all versions, 5.0 all version...
CVE-2022-29060
- EPSS 0.48%
- Published 19.07.2022 14:15:08
- Last modified 21.11.2024 06:58:25
A use of hard-coded cryptographic key vulnerability [CWE-321] in FortiDDoS API 5.5.0 through 5.5.1, 5.4.0 through 5.4.2, 5.3.0 through 5.3.1, 5.2.0, 5.1.0 may allow an attacker who managed to retrieve the key from one device to sign JWT tokens for an...