fortinet

1,122 tracked vulnerabilities.

CVE-2018-1352 CRITICAL
FortiOS 5.6.0 - Remote Code Execution via SSH Username Format String
Feb 08, 2019
CVSS 9.8
EPSS 0.01
CVE-2018-13374 MEDIUM KEV
FortiOS < 6.0.3 and FortiADC 5.4.0-5.4.4 - LDAP Server Credential Exposure via Connectivity Test Request
Jan 22, 2019
CVSS 4.3
EPSS 0.03
CVE-2018-13376 HIGH
Fortinet FortiOS <5.6.3, <5.4.7, <5.2 - Memory Corruption
Nov 27, 2018
CVSS 7.5
EPSS 0.01
CVE-2018-9194 MEDIUM
FortiOS 5.4.6-5.4.9, 6.0.0-6.0.1 - Plaintext Recovery and Man-in-the-Middle Attack via RSA PKCS #1 v1.5 Encryption
Sep 05, 2018
CVSS 5.9
EPSS 0.00
CVE-2018-9192 MEDIUM
FortiOS 5.4.6-5.4.9, 6.0.0-6.0.1 - Plaintext Recovery and Man-in-the-Middle Attack via RSA PKCS #1 v1.5 Encryption
Sep 05, 2018
CVSS 5.9
EPSS 0.00
CVE-2018-1353 MEDIUM
Fortinet FortiManager < 6.0.1 - Unauthorized Interface Settings Exposure via ADOM Assignment
Sep 05, 2018
CVSS 4.3
EPSS 0.00
CVE-2018-9185 HIGH
Fortinet FortiOS < 6.0.0 - Unauthenticated Exposure of Web Portal Credentials via Single Sign-On Bookmark Feature
Jul 05, 2018
CVSS 8.1
EPSS 0.01
CVE-2018-1351 MEDIUM
Fortinet FortiManager < 6.0.0 - Cross-Site Scripting via Remote Device CLI Config Log
Jun 28, 2018
CVSS 4.8
EPSS 0.00
CVE-2018-1355 MEDIUM
FortiAnalyzer and FortiManager < 5.6.5 - Open Redirect via FortiView PDF Conversion
Jun 27, 2018
CVSS 6.1
EPSS 0.00
CVE-2018-1354 MEDIUM
FortiAnalyzer and FortiManager < 6.0.0 - Unauthenticated Arbitrary Avatar Picture Modification
Jun 27, 2018
CVSS 6.5
EPSS 0.00
CVE-2018-9186 MEDIUM
Fortinet FortiAuthenticator 4.0.0-5.2.9 - Cross-Site Scripting via HTTP Referer Header
May 31, 2018
CVSS 6.1
EPSS 0.00
CVE-2017-17544 HIGH
Fortinet FortiOS <5.4.0, 5.6.0-5.6.10, 6.0.0-6.0.6 Privilege Escalation via Config Restore
Apr 09, 2019
CVSS 7.2
EPSS 0.00
CVE-2017-7342 CRITICAL
FortiPortal <= 4.0.0 - Unauthenticated Remote Code Execution via Weak Password Recovery Process
Mar 25, 2019
CVSS 9.8
EPSS 0.00
CVE-2017-7340 MEDIUM
Fortinet FortiPortal < 4.0.0 - Cross-Site Scripting via FortiView applicationSearch Parameter
Mar 25, 2019
CVSS 6.1
EPSS 0.00
CVE-2017-17541 MEDIUM
FortiAnalyzer and FortiManager < 5.6.4 - Stored Cross-Site Scripting via CA and CRL Certificate Import
Jul 16, 2018
CVSS 6.1
EPSS 0.00
CVE-2017-14185 MEDIUM
FortiOS 5.2.0-5.2.12, 5.4.0-5.4.8, 5.6.0-5.6.2 - Information Disclosure via SSL-VPN Web Portal
May 25, 2018
CVSS 5.3
EPSS 0.00
CVE-2017-14187 MEDIUM
Fortinet FortiOS <5.6.3 - Privilege Escalation
May 24, 2018
CVSS 6.2
EPSS 0.00
CVE-2017-17540 CRITICAL
Fortinet FortiWLC 7.0-7.0.10 - Use of Hard-coded Credentials
May 08, 2018
CVSS 9.8
EPSS 0.00
CVE-2017-17539 CRITICAL
FortiWLC < 7.0.11 - Unauthenticated Remote Shell Access via Hardcoded Account
May 08, 2018
CVSS 9.8
EPSS 0.00
CVE-2017-17543 HIGH
FortiClient < 5.6.0 and FortiClient SSLVPN Client < 4.4.2335 - Inadequate Encryption Strength
Apr 26, 2018
CVSS 7.5
EPSS 0.00
CVE-2017-14191 MEDIUM
Fortinet FortiWeb <6.1.0 - Auth Bypass
Mar 20, 2018
CVSS 5.9
EPSS 0.00
CVE-2017-14190 MEDIUM
FortiOS < 5.2.0 - Cross-Site Scripting via Host Header
Jan 29, 2018
CVSS 6.1
EPSS 0.00
CVE-2017-14184 HIGH
Fortinet FortiClient <5.6.0 - Info Disclosure
Dec 15, 2017
CVSS 8.8
EPSS 0.02
CVE-2017-7344 HIGH
Fortinet FortiClient <5.4.3, <5.6.0 - Privilege Escalation
Dec 14, 2017
CVSS 8.1
EPSS 0.01
CVE-2017-7738 HIGH
Fortinet FortiOS <5.6.3 - Info Disclosure
Dec 13, 2017
CVSS 7.2
EPSS 0.00