Vulnerabilities > Fortinet > Fortiextender Firmware > 5.3.2

DATE CVE VULNERABILITY TITLE RISK
2024-07-09 CVE-2024-23663 Unspecified vulnerability in Fortinet Fortiextender Firmware
An improper access control in Fortinet FortiExtender 4.1.1 - 4.1.9, 4.2.0 - 4.2.6, 5.3.2, 7.0.0 - 7.0.4, 7.2.0 - 7.2.4 and 7.4.0 - 7.4.2 allows an attacker to create users with elevated privileges via a crafted HTTP request.
network
low complexity
fortinet
8.8
2023-07-11 CVE-2022-23447 Path Traversal vulnerability in Fortinet Fortiextender Firmware
An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in FortiExtender management interface 7.0.0 through 7.0.3, 4.2.0 through 4.2.4, 4.1.1 through 4.1.8, 4.0.0 through 4.0.2, 3.3.0 through 3.3.2, 3.2.1 through 3.2.3, 5.3 all versions may allow an unauthenticated and remote attacker to retrieve arbitrary files from the underlying filesystem via specially crafted web requests.
network
low complexity
fortinet CWE-22
7.5
2023-02-16 CVE-2022-27489 OS Command Injection vulnerability in Fortinet Fortiextender Firmware
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiExtender 7.0.0 through 7.0.3, 5.3.2, 4.2.4 and below allows attacker to execute unauthorized code or commands via crafted HTTP requests.
network
low complexity
fortinet CWE-78
7.2