Vulnerabilities > Fortinet > Low
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2022-05-24 | CVE-2022-22306 | Improper Certificate Validation vulnerability in Fortinet Fortios An improper certificate validation vulnerability [CWE-295] in FortiOS 6.0.0 through 6.0.14, 6.2.0 through 6.2.10, 6.4.0 through 6.4.8, 7.0.0 may allow a network adjacent and unauthenticated attacker to man-in-the-middle the communication between the FortiGate and some peers such as private SDNs and external cloud platforms. | 2.9 |
2022-04-06 | CVE-2022-23446 | Unspecified vulnerability in Fortinet Fortiedr A improper control of a resource through its lifetime in Fortinet FortiEDR version 5.0.3 and earlier allows attacker to make the whole application unresponsive via changing its root directory access permission. | 2.1 |
2022-03-02 | CVE-2022-22303 | Information Exposure vulnerability in Fortinet Fortimanager An exposure of sensitive system information to an unauthorized control sphere vulnerability [CWE-497] in FortiManager versions prior to 7.0.2, 6.4.7 and 6.2.9 may allow a low privileged authenticated user to gain access to the FortiGate users credentials via the config conflict file. | 2.1 |
2022-03-02 | CVE-2021-44166 | Unspecified vulnerability in Fortinet Fortitoken Mobile An improper access control vulnerability [CWE-284 ] in FortiToken Mobile (Android) external push notification 5.1.0 and below may allow a remote attacker having already obtained a user's password to access the protected system during the 2FA procedure, even though the deny button is clicked by the legitimate user. network fortinet | 3.5 |
2022-02-02 | CVE-2021-36177 | Unspecified vulnerability in Fortinet Fortiauthenticator An improper access control vulnerability [CWE-284] in FortiAuthenticator HA service 6.3.2 and below, 6.2.x, 6.1.x, 6.0.x may allow an attacker on the same vlan as the HA management interface to make an unauthenticated direct connection to the FAC's database. low complexity fortinet | 3.3 |
2021-12-08 | CVE-2021-42752 | Cross-site Scripting vulnerability in Fortinet Fortiwlm A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiWLM version 8.6.1 and below allows attacker to execute malicious javascript code on victim's host via crafted HTTP requests | 3.5 |
2021-12-08 | CVE-2021-41029 | Cross-site Scripting vulnerability in Fortinet Fortiwlm A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiWLM version 8.6.1 and below allows attacker to store malicious javascript code in the device and trigger it via crafted HTTP requests | 3.5 |
2021-11-17 | CVE-2021-32600 | Unspecified vulnerability in Fortinet Fortios An exposure of sensitive information to an unauthorized actor vulnerability in FortiOS CLI 7.0.0, 6.4.0 through 6.4.6, 6.2.0 through 6.2.9, 6.0.x and 5.6.x may allow a local and authenticated user assigned to a specific VDOM to retrieve other VDOMs information such as the admin account list and the network interface list. | 2.1 |
2021-11-03 | CVE-2021-36192 | Information Exposure vulnerability in Fortinet Fortimanager An exposure of sensitive information to an unauthorized actor [CWE-200] vulnerability in FortiManager 7.0.1 and below, 6.4.6 and below, 6.2.x, 6.0.x, 5.6.0 may allow a FortiGate user to see scripts from other ADOMS. | 2.1 |
2021-11-02 | CVE-2021-42754 | Code Injection vulnerability in Fortinet Forticlient An improper control of generation of code vulnerability [CWE-94] in FortiClientMacOS versions 7.0.0 and below and 6.4.5 and below may allow an authenticated attacker to hijack the MacOS camera without the user permission via the malicious dylib file. | 3.5 |