CVE-2021-24008
- EPSS 0.23%
- Veröffentlicht 28.03.2025 10:13:32
- Zuletzt bearbeitet 24.07.2025 19:57:26
An exposure of sensitive system information to an unauthorized control sphere vulnerability [CWE-497] in FortiDDoS version 5.4.0, version 5.3.2 and below, version 5.2.0, version 5.1.0, version 5.0.0, version 4.7.0, version 4.6.0, version 4.5.0, versi...
CVE-2022-23439
- EPSS 0.13%
- Veröffentlicht 22.01.2025 10:15:07
- Zuletzt bearbeitet 14.01.2026 14:16:06
A externally controlled reference to a resource in another sphere vulnerability in Fortinet allows attacker to poison web caches via crafted HTTP requests, where the `Host` header points to an arbitrary webserver
CVE-2022-27486
- EPSS 0.5%
- Veröffentlicht 13.08.2024 16:15:07
- Zuletzt bearbeitet 22.08.2024 14:29:44
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiDDoS version 5.5.0 through 5.5.1, 5.4.2 through 5.4.0, 5.3.0 through 5.3.1, 5.2.0, 5.1.0, 5.0.0, 4.7.0, 4.6.0 and 4.5.0 and FortiDDoS-F vers...
CVE-2022-40679
- EPSS 0.12%
- Veröffentlicht 11.04.2023 17:15:07
- Zuletzt bearbeitet 21.11.2024 07:21:50
An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in FortiADC 5.x all versions, 6.0 all versions, 6.1 all versions, 6.2.0 through 6.2.4, 7.0.0 through 7.0.3, 7.1.0; FortiDDoS 4.x all versions, 5.0 all version...
CVE-2022-29060
- EPSS 0.48%
- Veröffentlicht 19.07.2022 14:15:08
- Zuletzt bearbeitet 21.11.2024 06:58:25
A use of hard-coded cryptographic key vulnerability [CWE-321] in FortiDDoS API 5.5.0 through 5.5.1, 5.4.0 through 5.4.2, 5.3.0 through 5.3.1, 5.2.0, 5.1.0 may allow an attacker who managed to retrieve the key from one device to sign JWT tokens for an...