Vulnerabilities > Fortinet > Fortios

DATE CVE VULNERABILITY TITLE RISK
2014-02-04 CVE-2013-7182 Cross-Site Scripting vulnerability in Fortinet Fortios 5.0.5
Cross-site scripting (XSS) vulnerability in firewall/schedule/recurrdlg in Fortinet FortiOS 5.0.5 allows remote attackers to inject arbitrary web script or HTML via the mkey parameter.
network
fortinet CWE-79
4.3
2013-07-08 CVE-2013-1414 Cross-Site Request Forgery (CSRF) vulnerability in Fortinet products
Multiple cross-site request forgery (CSRF) vulnerabilities in Fortinet FortiOS on FortiGate firewall devices before 4.3.13 and 5.x before 5.0.2 allow remote attackers to hijack the authentication of administrators for requests that modify (1) settings or (2) policies, or (3) restart the device via a rebootme action to system/maintenance/shutdown.
network
high complexity
fortinet CWE-352
5.1
2013-06-25 CVE-2013-4604 Permissions, Privileges, and Access Controls vulnerability in Fortinet Fortios
Fortinet FortiOS before 5.0.3 on FortiGate devices does not properly restrict Guest capabilities, which allows remote authenticated users to read, modify, or delete the records of arbitrary users by leveraging the Guest role.
network
low complexity
fortinet CWE-264
6.5
2006-06-24 CVE-2006-3222 Unspecified vulnerability in Fortinet Fortios
The FTP proxy module in Fortinet FortiOS (FortiGate) before 2.80 MR12 and 3.0 MR2 allows remote attackers to bypass anti-virus scanning via the Enhanced Passive (EPSV) FTP mode.
network
low complexity
fortinet
5.0
2005-12-31 CVE-2005-3058 Permissions, Privileges, and Access Controls vulnerability in Fortinet Fortigate and Fortios
Interpretation conflict in Fortinet FortiGate 2.8, running FortiOS 2.8MR10 and v3beta, allows remote attackers to bypass the URL blocker via an (1) HTTP request terminated with a line feed (LF) and not carriage return line feed (CRLF) or (2) HTTP request with no Host field, which is still processed by most web servers without violating RFC2616.
network
low complexity
fortinet CWE-264
7.5
2005-12-31 CVE-2005-3057 Unspecified vulnerability in Fortinet Fortigate and Fortios
The FTP component in FortiGate 2.8 running FortiOS 2.8MR10 and v3beta, and other versions before 3.0 MR1, allows remote attackers to bypass the Fortinet FTP anti-virus engine by sending a STOR command and uploading a file before the FTP server response has been sent, as demonstrated using LFTP.
network
low complexity
fortinet
critical
10.0
2005-12-29 CVE-2005-4570 Denial Of Service vulnerability in Multiple Fortinet Products IKE Exchange
The Internet Key Exchange version 1 (IKEv1) implementations in Fortinet FortiOS 2.50, 2.80 and 3.0, FortiClient 2.0,; and FortiManager 2.80 and 3.0 allow remote attackers to cause a denial of service (termination of a process that is automatically restarted) via IKE packets with invalid values of certain IPSec attributes, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1.
network
low complexity
fortinet
7.8