Vulnerabilities > Fortinet > Low

DATE CVE VULNERABILITY TITLE RISK
2022-03-02 CVE-2022-22303 Information Exposure vulnerability in Fortinet Fortimanager
An exposure of sensitive system information to an unauthorized control sphere vulnerability [CWE-497] in FortiManager versions prior to 7.0.2, 6.4.7 and 6.2.9 may allow a low privileged authenticated user to gain access to the FortiGate users credentials via the config conflict file.
local
low complexity
fortinet CWE-200
2.1
2022-03-02 CVE-2021-44166 Unspecified vulnerability in Fortinet Fortitoken Mobile
An improper access control vulnerability [CWE-284 ] in FortiToken Mobile (Android) external push notification 5.1.0 and below may allow a remote attacker having already obtained a user's password to access the protected system during the 2FA procedure, even though the deny button is clicked by the legitimate user.
network
fortinet
3.5
2022-02-02 CVE-2021-36177 Unspecified vulnerability in Fortinet Fortiauthenticator
An improper access control vulnerability [CWE-284] in FortiAuthenticator HA service 6.3.2 and below, 6.2.x, 6.1.x, 6.0.x may allow an attacker on the same vlan as the HA management interface to make an unauthenticated direct connection to the FAC's database.
low complexity
fortinet
3.3
2021-12-08 CVE-2021-42752 Cross-site Scripting vulnerability in Fortinet Fortiwlm
A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiWLM version 8.6.1 and below allows attacker to execute malicious javascript code on victim's host via crafted HTTP requests
network
fortinet CWE-79
3.5
2021-12-08 CVE-2021-41029 Cross-site Scripting vulnerability in Fortinet Fortiwlm
A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiWLM version 8.6.1 and below allows attacker to store malicious javascript code in the device and trigger it via crafted HTTP requests
network
fortinet CWE-79
3.5
2021-11-17 CVE-2021-32600 Unspecified vulnerability in Fortinet Fortios
An exposure of sensitive information to an unauthorized actor vulnerability in FortiOS CLI 7.0.0, 6.4.0 through 6.4.6, 6.2.0 through 6.2.9, 6.0.x and 5.6.x may allow a local and authenticated user assigned to a specific VDOM to retrieve other VDOMs information such as the admin account list and the network interface list.
local
low complexity
fortinet
2.1
2021-11-03 CVE-2021-36192 Information Exposure vulnerability in Fortinet Fortimanager
An exposure of sensitive information to an unauthorized actor [CWE-200] vulnerability in FortiManager 7.0.1 and below, 6.4.6 and below, 6.2.x, 6.0.x, 5.6.0 may allow a FortiGate user to see scripts from other ADOMS.
local
low complexity
fortinet CWE-200
2.1
2021-11-02 CVE-2021-42754 Code Injection vulnerability in Fortinet Forticlient
An improper control of generation of code vulnerability [CWE-94] in FortiClientMacOS versions 7.0.0 and below and 6.4.5 and below may allow an authenticated attacker to hijack the MacOS camera without the user permission via the malicious dylib file.
network
fortinet CWE-94
3.5
2021-11-02 CVE-2021-41023 Insufficiently Protected Credentials vulnerability in Fortinet Fortisiem
A unprotected storage of credentials in Fortinet FortiSIEM Windows Agent version 4.1.4 and below allows an authenticated user to disclosure agent password due to plaintext credential storage in log files
local
low complexity
fortinet CWE-522
2.1
2021-11-02 CVE-2021-36181 Race Condition vulnerability in Fortinet Fortiportal
A concurrent execution using shared resource with improper Synchronization vulnerability ('Race Condition') in the customer database interface of FortiPortal before 6.0.6 may allow an authenticated, low-privilege user to bring the underlying database data into an inconsistent state via specific coordination of web requests.
network
fortinet CWE-362
3.5