Vulnerabilities > Fortinet > Fortimail > 7.2.3

DATE CVE VULNERABILITY TITLE RISK
2025-01-14 CVE-2024-56497 OS Command Injection vulnerability in Fortinet Fortimail and Fortirecorder
An improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiMail versions 7.2.0 through 7.2.4 and 7.0.0 through 7.0.6 and 6.4.0 through 6.4.7, FortiRecorder versions 7.0.0 and 6.4.0 through 6.4.4 allows attacker to execute unauthorized code or commands via the CLI.
local
low complexity
fortinet CWE-78
6.7
2023-11-14 CVE-2023-45582 Unspecified vulnerability in Fortinet Fortimail
An improper restriction of excessive authentication attempts vulnerability [CWE-307] in FortiMail webmail version 7.2.0 through 7.2.4, 7.0.0 through 7.0.6 and before 6.4.8 may allow an unauthenticated attacker to  perform a brute force attack on the affected endpoints via repeated login attempts.
network
low complexity
fortinet
7.3