Vulnerabilities > Fortinet > Fortitester > Critical

DATE CVE VULNERABILITY TITLE RISK
2022-10-18 CVE-2022-33874 OS Command Injection vulnerability in Fortinet Fortitester
An improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerabilities [CWE-78] in SSH login components of FortiTester 2.3.0 through 3.9.1, 4.0.0 through 4.2.0, 7.0.0 through 7.1.0 may allow an unauthenticated remote attacker to execute arbitrary command in the underlying shell.
network
low complexity
fortinet CWE-78
critical
9.8
2022-10-18 CVE-2022-33873 OS Command Injection vulnerability in Fortinet Fortitester
An improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerabilities [CWE-78] in Console login components of FortiTester 2.3.0 through 3.9.1, 4.0.0 through 4.2.0, 7.0.0 through 7.1.0 may allow an unauthenticated attacker to execute arbitrary command in the underlying shell.
network
low complexity
fortinet CWE-78
critical
9.8
2022-10-18 CVE-2022-33872 OS Command Injection vulnerability in Fortinet Fortitester
An improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerabilities [CWE-78] in Telnet login components of FortiTester 2.3.0 through 3.9.1, 4.0.0 through 4.2.0, 7.0.0 through 7.1.0 may allow an unauthenticated remote attacker to execute arbitrary command in the underlying shell.
network
low complexity
fortinet CWE-78
critical
9.8
2022-10-18 CVE-2022-35846 Improper Restriction of Excessive Authentication Attempts vulnerability in Fortinet Fortitester
An improper restriction of excessive authentication attempts vulnerability [CWE-307] in FortiTester Telnet port 2.3.0 through 3.9.1, 4.0.0 through 4.2.0, 7.0.0 through 7.1.0 may allow an unauthenticated attacker to guess the credentials of an admin user via a brute force attack.
network
low complexity
fortinet CWE-307
critical
9.8