Vulnerabilities > Fortinet > Fortios > Medium

DATE CVE VULNERABILITY TITLE RISK
2015-08-11 CVE-2015-3626 Cross-site Scripting vulnerability in Fortinet Fortios
Cross-site scripting (XSS) vulnerability in the DHCP Monitor page in the Web User Interface (WebUI) in Fortinet FortiOS before 5.2.4 on FortiGate devices allows remote attackers to inject arbitrary web script or HTML via a crafted hostname.
network
fortinet CWE-79
4.3
2015-08-11 CVE-2015-2323 Cryptographic Issues vulnerability in Fortinet Fortios
FortiOS 5.0.x before 5.0.12 and 5.2.x before 5.2.4 supports anonymous, export, RC4, and possibly other weak ciphers when using TLS to connect to FortiGuard servers, which allows man-in-the-middle attackers to spoof TLS content by modifying packets.
network
low complexity
fortinet CWE-310
6.4
2015-05-12 CVE-2015-1880 Cross-site Scripting vulnerability in Fortinet Fortios 5.2.0/5.2.1/5.2.2
Cross-site scripting (XSS) vulnerability in the sslvpn login page in Fortinet FortiOS 5.2.x before 5.2.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
network
fortinet CWE-79
4.3
2015-05-12 CVE-2014-8616 Cross-site Scripting vulnerability in Fortinet Fortios 5.2.0/5.2.1/5.2.2
Multiple cross-site scripting (XSS) vulnerabilities in Fortinet FortiOS 5.2.x before 5.2.3 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors to the (1) user group or (2) vpn template menus.
network
fortinet CWE-79
4.3
2014-09-10 CVE-2014-0351 Cryptographic Issues vulnerability in Fortinet Fortios
The FortiManager protocol service in Fortinet FortiOS before 4.3.16 and 5.x before 5.0.8 on FortiGate devices does not prevent use of anonymous ciphersuites, which makes it easier for man-in-the-middle attackers to obtain sensitive information or interfere with communications by modifying the client-server data stream.
5.4
2014-02-04 CVE-2013-7182 Cross-Site Scripting vulnerability in Fortinet Fortios 5.0.5
Cross-site scripting (XSS) vulnerability in firewall/schedule/recurrdlg in Fortinet FortiOS 5.0.5 allows remote attackers to inject arbitrary web script or HTML via the mkey parameter.
network
fortinet CWE-79
4.3
2013-07-08 CVE-2013-1414 Cross-Site Request Forgery (CSRF) vulnerability in Fortinet products
Multiple cross-site request forgery (CSRF) vulnerabilities in Fortinet FortiOS on FortiGate firewall devices before 4.3.13 and 5.x before 5.0.2 allow remote attackers to hijack the authentication of administrators for requests that modify (1) settings or (2) policies, or (3) restart the device via a rebootme action to system/maintenance/shutdown.
network
high complexity
fortinet CWE-352
5.1
2013-06-25 CVE-2013-4604 Permissions, Privileges, and Access Controls vulnerability in Fortinet Fortios
Fortinet FortiOS before 5.0.3 on FortiGate devices does not properly restrict Guest capabilities, which allows remote authenticated users to read, modify, or delete the records of arbitrary users by leveraging the Guest role.
network
low complexity
fortinet CWE-264
6.5
2006-06-24 CVE-2006-3222 Unspecified vulnerability in Fortinet Fortios
The FTP proxy module in Fortinet FortiOS (FortiGate) before 2.80 MR12 and 3.0 MR2 allows remote attackers to bypass anti-virus scanning via the Enhanced Passive (EPSV) FTP mode.
network
low complexity
fortinet
5.0