fortinet
1,122 tracked vulnerabilities.
CVE-2018-1352
CRITICAL
FortiOS 5.6.0 - Remote Code Execution via SSH Username Format String
Feb 08, 2019
CVSS 9.8
EPSS 0.01
CVE-2018-13374
MEDIUM
KEV
FortiOS < 6.0.3 and FortiADC 5.4.0-5.4.4 - LDAP Server Credential Exposure via Connectivity Test Request
Jan 22, 2019
CVSS 4.3
EPSS 0.03
CVE-2018-13376
HIGH
Fortinet FortiOS <5.6.3, <5.4.7, <5.2 - Memory Corruption
Nov 27, 2018
CVSS 7.5
EPSS 0.01
CVE-2018-9194
MEDIUM
FortiOS 5.4.6-5.4.9, 6.0.0-6.0.1 - Plaintext Recovery and Man-in-the-Middle Attack via RSA PKCS #1 v1.5 Encryption
Sep 05, 2018
CVSS 5.9
EPSS 0.00
CVE-2018-9192
MEDIUM
FortiOS 5.4.6-5.4.9, 6.0.0-6.0.1 - Plaintext Recovery and Man-in-the-Middle Attack via RSA PKCS #1 v1.5 Encryption
Sep 05, 2018
CVSS 5.9
EPSS 0.00
CVE-2018-1353
MEDIUM
Fortinet FortiManager < 6.0.1 - Unauthorized Interface Settings Exposure via ADOM Assignment
Sep 05, 2018
CVSS 4.3
EPSS 0.00
CVE-2018-9185
HIGH
Fortinet FortiOS < 6.0.0 - Unauthenticated Exposure of Web Portal Credentials via Single Sign-On Bookmark Feature
Jul 05, 2018
CVSS 8.1
EPSS 0.01
CVE-2018-1351
MEDIUM
Fortinet FortiManager < 6.0.0 - Cross-Site Scripting via Remote Device CLI Config Log
Jun 28, 2018
CVSS 4.8
EPSS 0.00
CVE-2018-1355
MEDIUM
FortiAnalyzer and FortiManager < 5.6.5 - Open Redirect via FortiView PDF Conversion
Jun 27, 2018
CVSS 6.1
EPSS 0.00
CVE-2018-1354
MEDIUM
FortiAnalyzer and FortiManager < 6.0.0 - Unauthenticated Arbitrary Avatar Picture Modification
Jun 27, 2018
CVSS 6.5
EPSS 0.00
CVE-2018-9186
MEDIUM
Fortinet FortiAuthenticator 4.0.0-5.2.9 - Cross-Site Scripting via HTTP Referer Header
May 31, 2018
CVSS 6.1
EPSS 0.00
CVE-2017-17544
HIGH
Fortinet FortiOS <5.4.0, 5.6.0-5.6.10, 6.0.0-6.0.6 Privilege Escalation via Config Restore
Apr 09, 2019
CVSS 7.2
EPSS 0.00
CVE-2017-7342
CRITICAL
FortiPortal <= 4.0.0 - Unauthenticated Remote Code Execution via Weak Password Recovery Process
Mar 25, 2019
CVSS 9.8
EPSS 0.00
CVE-2017-7340
MEDIUM
Fortinet FortiPortal < 4.0.0 - Cross-Site Scripting via FortiView applicationSearch Parameter
Mar 25, 2019
CVSS 6.1
EPSS 0.00
CVE-2017-17541
MEDIUM
FortiAnalyzer and FortiManager < 5.6.4 - Stored Cross-Site Scripting via CA and CRL Certificate Import
Jul 16, 2018
CVSS 6.1
EPSS 0.00
CVE-2017-14185
MEDIUM
FortiOS 5.2.0-5.2.12, 5.4.0-5.4.8, 5.6.0-5.6.2 - Information Disclosure via SSL-VPN Web Portal
May 25, 2018
CVSS 5.3
EPSS 0.00
CVE-2017-14187
MEDIUM
Fortinet FortiOS <5.6.3 - Privilege Escalation
May 24, 2018
CVSS 6.2
EPSS 0.00
CVE-2017-17540
CRITICAL
Fortinet FortiWLC 7.0-7.0.10 - Use of Hard-coded Credentials
May 08, 2018
CVSS 9.8
EPSS 0.00
CVE-2017-17539
CRITICAL
FortiWLC < 7.0.11 - Unauthenticated Remote Shell Access via Hardcoded Account
May 08, 2018
CVSS 9.8
EPSS 0.00
CVE-2017-17543
HIGH
FortiClient < 5.6.0 and FortiClient SSLVPN Client < 4.4.2335 - Inadequate Encryption Strength
Apr 26, 2018
CVSS 7.5
EPSS 0.00
CVE-2017-14191
MEDIUM
Fortinet FortiWeb <6.1.0 - Auth Bypass
Mar 20, 2018
CVSS 5.9
EPSS 0.00
CVE-2017-14190
MEDIUM
FortiOS < 5.2.0 - Cross-Site Scripting via Host Header
Jan 29, 2018
CVSS 6.1
EPSS 0.00
CVE-2017-14184
HIGH
Fortinet FortiClient <5.6.0 - Info Disclosure
Dec 15, 2017
CVSS 8.8
EPSS 0.02
CVE-2017-7344
HIGH
Fortinet FortiClient <5.4.3, <5.6.0 - Privilege Escalation
Dec 14, 2017
CVSS 8.1
EPSS 0.01
CVE-2017-7738
HIGH
Fortinet FortiOS <5.6.3 - Info Disclosure
Dec 13, 2017
CVSS 7.2
EPSS 0.00
Products
fortios 267
fortiweb 124
fortiproxy 117
fortimanager 112
fortianalyzer 92
forticlient 85
fortisandbox 58
fortimail 46
fortiportal 44
fortiadc 43
fortisoar 31
fortinac 30
fortisiem 29
fortimanager_cloud 27
fortipam 25
fortivoice 24
fortiauthenticator 23
fortiwlm 23
fortiswitchmanager 19
fortinet_antivirus 18
fortianalyzer_cloud 17
fortitester 16
fortiwan 16
fortimanager_firmware 15
fortiswitch 14
fortiwlc 14
FortiOS 13
fortianalyzer_big_data 13
forticlientems 13
fortianalyzer_firmware 12
Quick Filters