Vulnerabilities > Fortinet > Fortios

DATE CVE VULNERABILITY TITLE RISK
2015-10-15 CVE-2015-7361 Improper Authentication vulnerability in Fortinet Fortios 5.2.3
FortiOS 5.2.3, when configured to use High Availability (HA) and the dedicated management interface is enabled, does not require authentication for access to the ZebOS shell on the HA dedicated management interface, which allows remote attackers to obtain shell access via unspecified vectors.
network
fortinet CWE-287
critical
9.3
2015-08-11 CVE-2015-5965 Improper Input Validation vulnerability in Fortinet Fortios
The SSL-VPN feature in Fortinet FortiOS before 4.3.13 only checks the first byte of the TLS MAC in finished messages, which makes it easier for remote attackers to spoof encrypted content via a crafted MAC field.
network
low complexity
fortinet CWE-20
5.0
2015-08-11 CVE-2015-3626 Cross-site Scripting vulnerability in Fortinet Fortios
Cross-site scripting (XSS) vulnerability in the DHCP Monitor page in the Web User Interface (WebUI) in Fortinet FortiOS before 5.2.4 on FortiGate devices allows remote attackers to inject arbitrary web script or HTML via a crafted hostname.
network
fortinet CWE-79
4.3
2015-08-11 CVE-2015-2323 Cryptographic Issues vulnerability in Fortinet Fortios
FortiOS 5.0.x before 5.0.12 and 5.2.x before 5.2.4 supports anonymous, export, RC4, and possibly other weak ciphers when using TLS to connect to FortiGuard servers, which allows man-in-the-middle attackers to spoof TLS content by modifying packets.
network
low complexity
fortinet CWE-310
6.4
2015-05-12 CVE-2015-1880 Cross-site Scripting vulnerability in Fortinet Fortios 5.2.0/5.2.1/5.2.2
Cross-site scripting (XSS) vulnerability in the sslvpn login page in Fortinet FortiOS 5.2.x before 5.2.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
network
fortinet CWE-79
4.3
2015-05-12 CVE-2014-8616 Cross-site Scripting vulnerability in Fortinet Fortios 5.2.0/5.2.1/5.2.2
Multiple cross-site scripting (XSS) vulnerabilities in Fortinet FortiOS 5.2.x before 5.2.3 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors to the (1) user group or (2) vpn template menus.
network
fortinet CWE-79
4.3
2015-02-02 CVE-2015-1452 Code vulnerability in Fortinet Fortios 5.0.7
The Control and Provisioning of Wireless Access Points (CAPWAP) daemon in Fortinet FortiOS 5.0 Patch 7 build 4457 allows remote attackers to cause a denial of service (locked CAPWAP Access Controller) via a large number of ClientHello DTLS messages.
network
low complexity
fortinet CWE-17
7.8
2015-02-02 CVE-2015-1451 Cross-site Scripting vulnerability in Fortinet Fortios 5.0.7
Multiple cross-site scripting (XSS) vulnerabilities in Fortinet FortiOS 5.0 Patch 7 build 4457 allow remote authenticated users to inject arbitrary web script or HTML via the (1) WTP Name or (2) WTP Active Software Version field in a CAPWAP Join request.
network
fortinet CWE-79
3.5
2014-09-10 CVE-2014-0351 Cryptographic Issues vulnerability in Fortinet Fortios
The FortiManager protocol service in Fortinet FortiOS before 4.3.16 and 5.x before 5.0.8 on FortiGate devices does not prevent use of anonymous ciphersuites, which makes it easier for man-in-the-middle attackers to obtain sensitive information or interfere with communications by modifying the client-server data stream.
5.4
2014-08-25 CVE-2014-2216 Denial of Service vulnerability in Fortinet FortiOS
The FortiManager protocol service in Fortinet FortiOS before 4.3.16 and 5.0.0 before 5.0.8 on FortiGate devices allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted request.
network
low complexity
fortinet
7.5