Vulnerabilities > Fortinet > Fortitester > Medium

DATE CVE VULNERABILITY TITLE RISK
2023-09-13 CVE-2023-40715 Cleartext Storage of Sensitive Information vulnerability in Fortinet Fortitester
A cleartext storage of sensitive information vulnerability [CWE-312] in FortiTester 2.3.0 through 7.2.3 may allow an attacker with access to the DB contents to retrieve the plaintext password of external servers configured in the device.
local
low complexity
fortinet CWE-312
5.5
2022-11-02 CVE-2022-38372 Unspecified vulnerability in Fortinet Fortitester
A hidden functionality vulnerability [CWE-1242] in FortiTester CLI 2.3.0 through 3.9.1, 4.0.0 through 4.2.0, 7.0.0 through 7.1.0 may allow a local, privileged user to obtain a root shell on the device via an undocumented command.
local
low complexity
fortinet
6.7
2020-09-24 CVE-2020-12815 Cross-site Scripting vulnerability in Fortinet Fortianalyzer and Fortitester
An improper neutralization of input vulnerability in FortiTester before 3.9.0 may allow a remote authenticated attacker to inject script related HTML tags via IPv4/IPv6 address fields.
network
low complexity
fortinet CWE-79
5.4