CVE-2024-26009
- EPSS 0.13%
- Veröffentlicht 12.08.2025 18:59:47
- Zuletzt bearbeitet 14.08.2025 01:13:14
An authentication bypass using an alternate path or channel [CWE-288] vulnerability in Fortinet FortiOS version 6.4.0 through 6.4.15 and before 6.2.16, FortiProxy version 7.4.0 through 7.4.2, 7.2.0 through 7.2.8 and before 7.0.15 & FortiPAM before ve...
CVE-2025-22252
- EPSS 0.12%
- Veröffentlicht 28.05.2025 07:55:49
- Zuletzt bearbeitet 04.06.2025 14:35:38
A missing authentication for critical function in Fortinet FortiProxy versions 7.6.0 through 7.6.1, FortiSwitchManager version 7.2.5, and FortiOS versions 7.4.4 through 7.4.6 and version 7.6.0 may allow an attacker with knowledge of an existing admin...
CVE-2023-25610
- EPSS 23.08%
- Veröffentlicht 24.03.2025 15:39:48
- Zuletzt bearbeitet 24.07.2025 19:56:34
A buffer underwrite ('buffer underflow') vulnerability in the administrative interface of Fortinet FortiOS version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.6, version 6.4.0 through 6.4.11 and version 6.2.12 and below, FortiProxy version 7.2.0 t...
CVE-2023-40721
- EPSS 0.04%
- Veröffentlicht 11.02.2025 17:15:21
- Zuletzt bearbeitet 24.07.2025 19:04:28
A use of externally-controlled format string vulnerability [CWE-134] in Fortinet FortiOS version 7.4.0 through 7.4.1 and before 7.2.6, FortiProxy version 7.4.0 and before 7.2.7, FortiPAM version 1.1.2 and before 1.0.3, FortiSwitchManager version 7.2....
CVE-2024-26011
- EPSS 0.05%
- Veröffentlicht 12.11.2024 19:15:08
- Zuletzt bearbeitet 12.12.2024 19:33:58
A missing authentication for critical function in Fortinet FortiManager version 7.4.0 through 7.4.2, 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through 6.4.14, FortiPAM version 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiProxy version...
CVE-2022-45862
- EPSS 0.21%
- Veröffentlicht 13.08.2024 16:15:07
- Zuletzt bearbeitet 22.08.2024 14:32:16
An insufficient session expiration vulnerability [CWE-613] vulnerability in FortiOS 7.2.5 and below, 7.0 all versions, 6.4 all versions; FortiProxy 7.2 all versions, 7.0 all versions; FortiPAM 1.3 all versions, 1.2 all versions, 1.1 all versions, 1.0...
CVE-2024-26010
- EPSS 0.17%
- Veröffentlicht 11.06.2024 15:16:04
- Zuletzt bearbeitet 11.12.2024 19:54:35
A stack-based buffer overflow in Fortinet FortiPAM version 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiWeb, FortiAuthenticator, FortiSwitchManager version 7.2.0 through 7.2.3, 7.0.1 through 7.0.3, FortiOS version 7.4.0 through 7.4.3, 7.2.0 ...
CVE-2023-45583
- EPSS 0.21%
- Veröffentlicht 14.05.2024 17:15:22
- Zuletzt bearbeitet 21.11.2024 08:27:00
A use of externally-controlled format string in Fortinet FortiProxy versions 7.2.0 through 7.2.5, 7.0.0 through 7.0.11, 2.0.0 through 2.0.13, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6 FortiPAM versions 1.1.0, 1.0.0 through 1.0.3 FortiOS versions 7.4....
CVE-2024-23113
- EPSS 45.02%
- Veröffentlicht 15.02.2024 14:15:46
- Zuletzt bearbeitet 29.11.2024 15:09:12
A use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, FortiProxy versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0.14, FortiPAM versions 1.2.0, 1.1...
CVE-2023-36635
- EPSS 0.1%
- Veröffentlicht 07.09.2023 13:15:08
- Zuletzt bearbeitet 21.11.2024 08:10:08
An improper access control in Fortinet FortiSwitchManager version 7.2.0 through 7.2.2 7.0.0 through 7.0.1 may allow a remote authenticated read-only user to modify the interface settings via the API.