Loading HuntDB...

fortios

94 Versions 97 CVEs

Versions

6.2..14

OTHER 1 CVE

6.4.*

OTHER 1 CVE

2.0.0

SEMANTIC 1 CVE

2.0.13

SEMANTIC 1 CVE

6.2.*

OTHER 1 CVE

6.4.13

SEMANTIC 4 CVEs

7.2.4

SEMANTIC 16 CVEs

5.0.0

SEMANTIC 3 CVEs

7.0.12

SEMANTIC 13 CVEs

FortiOS 6.0.7 and below

OTHER 1 CVE

6.2.14

SEMANTIC 3 CVEs

7.0.13

SEMANTIC 8 CVEs

7.0.7

SEMANTIC 5 CVEs

6.4.7

SEMANTIC 1 CVE

7.2.10

SEMANTIC 3 CVEs

7.0.5

SEMANTIC 1 CVE

5.4.13

SEMANTIC 3 CVEs

4.2.16

SEMANTIC 1 CVE

5.4.0

SEMANTIC 3 CVEs

7.4.6

SEMANTIC 1 CVE

7.0.6

SEMANTIC 1 CVE

7.2.7

SEMANTIC 8 CVEs

6.2.0 and below

OTHER 1 CVE

6.2.4

SEMANTIC 1 CVE

6.0.16

SEMANTIC 13 CVEs

4.0.0

SEMANTIC 1 CVE

7.0.14

SEMANTIC 3 CVEs

6.4.12

SEMANTIC 13 CVEs

6.4.6

SEMANTIC 1 CVE

5.0.14

SEMANTIC 3 CVEs

4.1.11

SEMANTIC 1 CVE

7.4.2

SEMANTIC 4 CVEs

6.2.3

SEMANTIC 2 CVEs

5.6.12

SEMANTIC 2 CVEs

5.2.0

SEMANTIC 3 CVEs

4.3.19

SEMANTIC 1 CVE

4.3.0

SEMANTIC 1 CVE

6.4.8

SEMANTIC 1 CVE

6.2.15

SEMANTIC 15 CVEs

7.0.16

SEMANTIC 5 CVEs

6.2.13

SEMANTIC 7 CVEs

7.4.1

SEMANTIC 13 CVEs

6.4.1

SEMANTIC 2 CVEs

6.2.2

SEMANTIC 1 CVE

6.0.7

SEMANTIC 1 CVE

7.0.3

SEMANTIC 3 CVEs

6.4.14

SEMANTIC 11 CVEs

7.4.3

SEMANTIC 7 CVEs

6.4.10

SEMANTIC 1 CVE

7.0.15

SEMANTIC 8 CVEs

6.4.0

SEMANTIC 59 CVEs

5.2.15

SEMANTIC 3 CVEs

FortiOS before 7.0.4; FortiProxy before 2.0.8

OTHER 1 CVE

6.2.0

SEMANTIC 42 CVEs

7.2.9

SEMANTIC 2 CVEs

6.4.11

SEMANTIC 10 CVEs

6.0.10

SEMANTIC 2 CVEs

7.2.0

SEMANTIC 75 CVEs

6.0.13

SEMANTIC 2 CVEs

7.0.10

SEMANTIC 9 CVEs

7.2.8

SEMANTIC 7 CVEs

7.4.0

SEMANTIC 39 CVEs

7.0.0

SEMANTIC 73 CVEs

7.0.1

SEMANTIC 1 CVE

4.0.4

SEMANTIC 1 CVE

7.2.5

SEMANTIC 11 CVEs

4.1.1

SEMANTIC 1 CVE

6.2.16

SEMANTIC 8 CVEs

5.0.x, 5.2.x

OTHER 1 CVE

6.0.15

SEMANTIC 3 CVEs

4.2.0

SEMANTIC 1 CVE

5.6.14

SEMANTIC 3 CVEs

7.0.8

SEMANTIC 5 CVEs

6.4.9

SEMANTIC 3 CVEs

6.4.15

SEMANTIC 18 CVEs

< 6.2.0

OTHER 1 CVE

6.2.12

SEMANTIC 10 CVEs

AV Engine version 6.2.168 and below and version 6.4.274 and below.

OTHER 1 CVE

5.6.0

SEMANTIC 5 CVEs

6.2.9

SEMANTIC 2 CVEs

7.4.4

SEMANTIC 9 CVEs

7.2.1

SEMANTIC 1 CVE

7.2.2

SEMANTIC 3 CVEs

FortiProxy 1.0.x, 1.1.x, 1.2.9 and below, 2.0.0 and below; FortiOS 6.0.10 and below, 6.2.2 and below

OTHER 1 CVE

7.2.6

SEMANTIC 9 CVEs

7.0.9

SEMANTIC 7 CVEs

7.2.3

SEMANTIC 16 CVEs

7.0.11

SEMANTIC 9 CVEs

6.0.18

SEMANTIC 6 CVEs

6.2.11

SEMANTIC 1 CVE

6.0.17

SEMANTIC 8 CVEs

6.0.0

SEMANTIC 30 CVEs

7.6.0

SEMANTIC 6 CVEs

5.2.0-5.2.9, 5.4.1

OTHER 1 CVE

Recent CVEs

CVE-2020-12819

A heap-based buffer overflow vulnerability in the processing of Link Control Protocol messages in FortiGate versions 5.6.12, 6.0.10, 6.2.4 and 6.4.1 and earlier may allow a remote attacker with valid SSL VPN credentials to crash the SSL VPN daemon by sending a large LCP packet, when tunnel mode is enabled. Arbitrary code execution may be theoretically possible, albeit practically very difficult to achieve in this context

MEDIUM Dec 19, 2024

CVE-2022-43953

A use of externally-controlled format string in Fortinet FortiOS version 7.2.0 through 7.2.4, FortiOS all versions 7.0, FortiOS all versions 6.4, FortiOS all versions 6.2, FortiProxy version 7.2.0 through 7.2.1, FortiProxy version 7.0.0 through 7.0.7 allows attacker to execute unauthorized code or commands via specially crafted commands.

MEDIUM Jun 13, 2023

CVE-2022-41327

A cleartext transmission of sensitive information vulnerability [CWE-319] in Fortinet FortiOS version 7.2.0 through 7.2.4, 7.0.0 through 7.0.8, FortiProxy version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.8 allows an authenticated attacker with readonly superadmin privileges to intercept traffic in order to obtain other adminstrators cookies via diagnose CLI commands.

HIGH Jun 13, 2023

CVE-2022-41330

An improper neutralization of input during web page generation vulnerability ('Cross-site Scripting') [CWE-79] in Fortinet FortiOS version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.9, version 6.4.0 through 6.4.11 and before 6.2.12 and FortiProxy version 7.2.0 through 7.2.1 and before 7.0.7 allows an unauthenticated attacker to perform an XSS attack via crafted HTTP GET requests.

HIGH Apr 11, 2023

CVE-2022-41329

An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in Fortinet FortiProxy version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.7, FortiOS version 7.2.0 through 7.2.3 and 7.0.0 through 7.0.9 allows an unauthenticated attackers to obtain sensitive logging informations on the device via crafted HTTP GET requests.

MEDIUM Mar 07, 2023

CVE-2022-41328

A improper limitation of a pathname to a restricted directory vulnerability ('path traversal') [CWE-22] in Fortinet FortiOS version 7.2.0 through 7.2.3, 7.0.0 through 7.0.9 and before 6.4.11 allows a privileged attacker to read and write files on the underlying Linux system via crafted CLI commands.

MEDIUM Mar 07, 2023

CVE-2022-41334

An improper neutralization of input during web page generation [CWE-79] vulnerability in FortiOS versions 7.0.0 to 7.0.7 and 7.2.0 to 7.2.3 may allow a remote, unauthenticated attacker to launch a cross site scripting (XSS) attack via the "redir" parameter of the URL seen when the "Sign in with FortiCloud" button is clicked.

HIGH Feb 16, 2023

CVE-2021-43074

An improper verification of cryptographic signature vulnerability [CWE-347] in FortiWeb 6.4 all versions, 6.3.16 and below, 6.2 all versions, 6.1 all versions, 6.0 all versions; FortiOS 7.0.3 and below, 6.4.8 and below, 6.2 all versions, 6.0 all versions; FortiSwitch 7.0.3 and below, 6.4.10 and below, 6.2 all versions, 6.0 all versions; FortiProxy 7.0.1 and below, 2.0.7 and below, 1.2 all versions, 1.1 all versions, 1.0 all versions may allow an attacker to decrypt portions of the administrative session management cookie if able to intercept the latter.

MEDIUM Feb 16, 2023

CVE-2022-41335

A relative path traversal vulnerability [CWE-23] in Fortinet FortiOS version 7.2.0 through 7.2.2, 7.0.0 through 7.0.8 and before 6.4.10, FortiProxy version 7.2.0 through 7.2.1, 7.0.0 through 7.0.7 and before 2.0.10, FortiSwitchManager 7.2.0 and before 7.0.0 allows an authenticated attacker to read and write files on the underlying Linux system via crafted HTTP requests.

HIGH Feb 16, 2023

CVE-2022-40680

A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiOS 6.0.7 - 6.0.15, 6.2.2 - 6.2.12, 6.4.0 - 6.4.9 and 7.0.0 - 7.0.3 allows a privileged attacker to execute unauthorized code or commands via storing malicious payloads in replacement messages.

LOW Dec 06, 2022