Vulnerabilities > Fortinet

DATE CVE VULNERABILITY TITLE RISK
2024-06-03 CVE-2024-23668 Unspecified vulnerability in Fortinet Fortiwebmanager
An improper authorization in Fortinet FortiWebManager version 7.2.0 and 7.0.0 through 7.0.4 and 6.3.0 and 6.2.3 through 6.2.4 and 6.0.2 allows attacker to execute unauthorized code or commands via HTTP requests or CLI.
network
low complexity
fortinet
8.8
2024-06-03 CVE-2024-23670 Unspecified vulnerability in Fortinet Fortiwebmanager
An improper authorization in Fortinet FortiWebManager version 7.2.0 and 7.0.0 through 7.0.4 and 6.3.0 and 6.2.3 through 6.2.4 and 6.0.2 allows attacker to execute unauthorized code or commands via HTTP requests or CLI.
network
low complexity
fortinet
8.8
2024-06-03 CVE-2023-48789 Unspecified vulnerability in Fortinet Fortiportal
A client-side enforcement of server-side security in Fortinet FortiPortal version 6.0.0 through 6.0.14 allows attacker to improper access control via crafted HTTP requests.
network
low complexity
fortinet
6.5
2024-06-03 CVE-2024-23107 Unspecified vulnerability in Fortinet Fortiweb
An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiWeb version 7.4.0, version 7.2.4 and below, version 7.0.8 and below, 6.3 all versions may allow an authenticated attacker to read password hashes of other administrators via CLI commands.
local
low complexity
fortinet
5.5
2024-06-03 CVE-2024-31493 Unspecified vulnerability in Fortinet Fortisoar
An improper removal of sensitive information before storage or transfer vulnerability [CWE-212] in FortiSOAR version 7.3.0, version 7.2.2 and below, version 7.0.3 and below may allow an authenticated low privileged user to read Connector passwords in plain-text via HTTP responses.
network
low complexity
fortinet
6.5
2024-05-14 CVE-2024-31488 Unspecified vulnerability in Fortinet Fortinac
An improper neutralization of inputs during web page generation vulnerability [CWE-79] in FortiNAC version 9.4.0 through 9.4.4, 9.2.0 through 9.2.8, 9.1.0 through 9.1.10, 8.8.0 through 8.8.11, 8.7.0 through 8.7.6, 7.2.0 through 7.2.3 may allow a remote authenticated attacker to perform stored and reflected cross site scripting (XSS) attack via crafted HTTP requests.
network
low complexity
fortinet
critical
9.0
2024-05-14 CVE-2024-31491 Unspecified vulnerability in Fortinet Fortisandbox
A client-side enforcement of server-side security in Fortinet FortiSandbox version 4.4.0 through 4.4.4 and 4.2.0 through 4.2.6 allows attacker to execute unauthorized code or commands via HTTP requests.
network
low complexity
fortinet
8.8
2024-05-14 CVE-2023-36640 Unspecified vulnerability in Fortinet Fortiproxy
A use of externally-controlled format string in Fortinet FortiProxy versions 7.2.0 through 7.2.4, 7.0.0 through 7.0.10, 2.0.0 through 2.0.13, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6, 1.0.0 through 1.0.7, FortiPAM versions 1.0.0 through 1.0.3, FortiOS versions 7.2.0, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, 6.0.0 through 6.0.16 allows attacker to execute unauthorized code or commands via specially crafted commands
local
low complexity
fortinet
6.7
2024-05-14 CVE-2023-40720 Unspecified vulnerability in Fortinet Fortivoice
An authorization bypass through user-controlled key vulnerability [CWE-639] in FortiVoiceEntreprise version 7.0.0 through 7.0.1 and before 6.4.8 allows an authenticated attacker to read the SIP configuration of other users via crafted HTTP or HTTPS requests.
network
low complexity
fortinet
7.1
2024-05-14 CVE-2023-44247 Unspecified vulnerability in Fortinet Fortios
A double free vulnerability [CWE-415] in Fortinet FortiOS before 7.0.0 may allow a privileged attacker to execute code or commands via crafted HTTP or HTTPs requests.
network
low complexity
fortinet
7.2