Vulnerabilities > Fortinet > Fortigate 5060

DATE CVE VULNERABILITY TITLE RISK
2013-07-08 CVE-2013-1414 Cross-Site Request Forgery (CSRF) vulnerability in Fortinet products
Multiple cross-site request forgery (CSRF) vulnerabilities in Fortinet FortiOS on FortiGate firewall devices before 4.3.13 and 5.x before 5.0.2 allow remote attackers to hijack the authentication of administrators for requests that modify (1) settings or (2) policies, or (3) restart the device via a rebootme action to system/maintenance/shutdown.
network
high complexity
fortinet CWE-352
5.1
2012-11-14 CVE-2012-4948 Improper Certificate Validation vulnerability in Fortinet products
The default configuration of Fortinet Fortigate UTM appliances uses the same Certification Authority certificate and same private key across different customers' installations, which makes it easier for man-in-the-middle attackers to spoof SSL servers by leveraging the presence of the Fortinet_CA_SSLProxy certificate in a list of trusted root certification authorities.
high complexity
fortinet CWE-295
5.3