Vulnerabilities > Fortinet > High

DATE CVE VULNERABILITY TITLE RISK
2021-07-09 CVE-2021-26106 OS Command Injection vulnerability in Fortinet Fortiap, Fortiap-S and Fortiap-W2
An improper neutralization of special elements used in an OS Command vulnerability in FortiAP's console 6.4.1 through 6.4.5 and 6.2.4 through 6.2.5 may allow an authenticated attacker to execute unauthorized commands by running the kdbg CLI command with specifically crafted arguments.
local
low complexity
fortinet CWE-78
7.8
2021-07-06 CVE-2021-24005 Use of Hard-coded Credentials vulnerability in Fortinet Fortiauthenticator
Usage of hard-coded cryptographic keys to encrypt configuration files and debug logs in FortiAuthenticator versions before 6.3.0 may allow an attacker with access to the files or the CLI configuration to decrypt the sensitive data, via knowledge of the hard-coded key.
network
low complexity
fortinet CWE-798
7.5
2021-06-03 CVE-2021-24023 OS Command Injection vulnerability in Fortinet Fortiai Firmware
An improper input validation in FortiAI v1.4.0 and earlier may allow an authenticated user to gain system shell access via a malicious payload in the "diagnose" command.
network
low complexity
fortinet CWE-78
8.8
2021-06-02 CVE-2021-24012 Improper Certificate Validation vulnerability in Fortinet Fortios
An improper following of a certificate's chain of trust vulnerability in FortiGate versions 6.4.0 to 6.4.4 may allow an LDAP user to connect to SSLVPN with any certificate that is signed by a trusted Certificate Authority.
network
low complexity
fortinet CWE-295
7.3
2021-06-01 CVE-2021-22123 OS Command Injection vulnerability in Fortinet Fortiweb
An OS command injection vulnerability in FortiWeb's management interface 6.3.7 and below, 6.2.3 and below, 6.1.x, 6.0.x, 5.9.x may allow a remote authenticated attacker to execute arbitrary commands on the system via the SAML server configuration page.
network
low complexity
fortinet CWE-78
8.8
2021-05-10 CVE-2021-24011 Unspecified vulnerability in Fortinet Fortinac
A privilege escalation vulnerability in FortiNAC version below 8.8.2 may allow an admin user to escalate the privileges to root by abusing the sudo privileges.
network
low complexity
fortinet
7.2
2021-03-04 CVE-2020-15938 Unspecified vulnerability in Fortinet Fortios
When traffic other than HTTP/S (eg: SSH traffic, etc...) traverses the FortiGate in version below 6.2.5 and below 6.4.2 on port 80/443, it is not redirected to the transparent proxy policy for processing, as it doesn't have a valid HTTP header.
network
low complexity
fortinet
7.5
2021-01-14 CVE-2020-29018 Use of Externally-Controlled Format String vulnerability in Fortinet Fortiweb
A format string vulnerability in FortiWeb 6.3.0 through 6.3.5 may allow an authenticated, remote attacker to read the content of memory and retrieve sensitive data via the redir parameter.
network
low complexity
fortinet CWE-134
8.8
2021-01-14 CVE-2020-29017 OS Command Injection vulnerability in Fortinet Fortideceptor 3.0.0/3.0.1/3.1.0
An OS command injection vulnerability in FortiDeceptor 3.1.0, 3.0.1, 3.0.0 may allow a remote authenticated attacker to execute arbitrary commands on the system by exploiting a command injection vulnerability on the Customization page.
network
low complexity
fortinet CWE-78
8.8
2020-09-24 CVE-2020-12817 Cross-site Scripting vulnerability in Fortinet Fortianalyzer and Fortitester
An improper neutralization of input vulnerability in FortiAnalyzer before 6.4.1 and 6.2.5 may allow a remote authenticated attacker to inject script related HTML tags via Name parameter of Storage Connectors.
network
low complexity
fortinet CWE-79
8.8