Vulnerability index

Browse CVEs

958 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Forticlient MEDIUM 5.9
CVE-2018-9195

Use of a hardcoded cryptographic key in the FortiGuard services communication protocol may allow a Man in the middle with knowledge of the key to eav…

Fix: after 6.2.1
Fix from $1,600 2019-11-21
Forticlient HIGH 7.8
CVE-2019-6692

A malicious DLL preload vulnerability in Fortinet FortiClient for Windows 6.2.0 and below allows a privileged attacker to perform arbitrary code exec…

Fix: after 6.2.0
Fix from $1,950 2019-10-24
Fortios HIGH 7.5
CVE-2019-15703

An Insufficient Entropy in PRNG vulnerability in Fortinet FortiOS 6.2.1, 6.2.0, 6.0.8 and below for device not enable hardware TRNG token and models …

Fix: 6.0.9 / 6.2.3+
Fix from $1,950 2019-10-24
Fortiweb MEDIUM 6.1
CVE-2019-5590

The URL part of the report message is not encoded in Fortinet FortiWeb 6.0.2 and below which may allow an attacker to execute unauthorized code or co…

Fix: after 6.0.2
Fix from $1,600 2019-08-28
Fortimanager CRITICAL 9.8
CVE-2019-6695

Lack of root file system integrity checking in Fortinet FortiManager VM application images of 6.2.0, 6.0.6 and below may allow an attacker to implant…

Fix: after 6.0.6
Fix from $2,300 2019-08-23
Fortinac MEDIUM 6.1
CVE-2019-5594

An Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") in Fortinet FortiNAC 8.3.0 to 8.3.6 and 8.5.0 admin webUI may…

Fix: after 8.3.6
Fix from $1,600 2019-08-23
Fortios MEDIUM 5.3
CVE-2018-13367

An information exposure vulnerability in FortiOS 6.2.3, 6.2.0 and below may allow an unauthenticated attacker to gain platform information such as ve…

Fix: after 6.2.0
Fix from $1,600 2019-08-23
Fortirecorder Firmware CRITICAL 9.8
CVE-2019-6698

Use of Hard-coded Credentials vulnerability in FortiRecorder all versions below 2.7.4 may allow an unauthenticated attacker with knowledge of the afo…

Fix: 2.7.4+
Fix from $2,300 2019-08-23
Fortios Ips Engine MEDIUM 5.9
CVE-2019-5592

Multiple padding oracle vulnerabilities (Zombie POODLE, GOLDENDOODLE, OpenSSL 0-length) in the CBC padding implementation of FortiOS IPS engine versi…

Fix: after 5.00006
Fix from $1,600 2019-08-23
Fcm Mb40 Firmware CRITICAL 9.8
CVE-2019-13400

Dynacolor FCM-MB40 v1.2.0.0 use /etc/appWeb/appweb.pass to store administrative web-interface credentials in cleartext. These credentials can be retr…

No fix yet
Fix from $2,300 2019-07-08
Fcm Mb40 Firmware HIGH 8.8
CVE-2019-13401

Dynacolor FCM-MB40 v1.2.0.0 devices have CSRF in all scripts under cgi-bin/.

No fix yet
Fix from $1,950 2019-07-08
Fcm Mb40 Firmware HIGH 8.8
CVE-2019-13402

/usr/sbin/default.sh and /usr/apache/htdocs/cgi-bin/admin/hardfactorydefault.cgi on Dynacolor FCM-MB40 v1.2.0.0 devices implement an incomplete facto…

No fix yet
Fix from $1,950 2019-07-08
Fcm Mb40 Firmware HIGH 7.2
CVE-2019-13398

Dynacolor FCM-MB40 v1.2.0.0 devices allow remote attackers to execute arbitrary commands via a crafted parameter to a CGI script, as demonstrated by …

No fix yet
Fix from $1,950 2019-07-08
Fcm Mb40 Firmware MEDIUM 5.9
CVE-2019-13399

Dynacolor FCM-MB40 v1.2.0.0 devices have a hard-coded SSL/TLS key that is used during an administrator's SSL conversation.

No fix yet
Fix from $1,600 2019-07-08
Fortios MEDIUM 6.5
CVE-2019-5587

Lack of root file system integrity checking in Fortinet FortiOS VM application images all versions below 6.0.5 may allow attacker to implant maliciou…

Fix: 6.0.5+
Fix from $1,600 2019-06-04
Fortios MEDIUM 6.1
CVE-2019-5586

A reflected Cross-Site-Scripting (XSS) vulnerability in Fortinet FortiOS 5.2.0 to 5.6.10, 6.0.0 to 6.0.4 under SSL VPN web portal may allow an attack…

Fix: after 6.0.4
Fix from $1,600 2019-06-04
Fortios MEDIUM 6.1
CVE-2019-5588

A reflected Cross-Site-Scripting (XSS) vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4 under SSL VPN web portal may allow an attacker to execute una…

Fix: after 6.0.4
Fix from $1,600 2019-06-04
Fortiproxy CRITICAL 9.8
CVE-2018-13379 KEVEPSS 100%

An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.3 to 5.6.7 and 5.4.6 to 5.4…

Fix: 1.2.9 / 5.4.13+
Fix from $2,300 2019-06-04
Fortiproxy HIGH 7.5
CVE-2018-13381

A buffer overflow vulnerability in Fortinet FortiOS 6.0.0 through 6.0.4, 5.6.0 through 5.6.7, 5.4 and earlier versions and FortiProxy 2.0.0, 1.2.8 an…

Fix: after 6.0.4
Fix from $1,950 2019-06-04
Fortiproxy HIGH 7.5
CVE-2018-13382 KEVEPSS 82%

An Improper Authorization vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.8 and 5.4.1 to 5.4.10 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, …

Fix: 1.2.9 / 5.4.11+
Fix from $1,950 2019-06-04
Fortios MEDIUM 6.1
CVE-2018-13380EPSS 62%

A Cross-site Scripting (XSS) vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.7, 5.4.0 to 5.4.12, 5.2 and below and Fortinet FortiProxy…

Fix: after 6.0.4
Fix from $1,600 2019-06-04
Fortios MEDIUM 6.1
CVE-2018-13384

A Host Header Redirection vulnerability in Fortinet FortiOS all versions below 6.0.5 under SSL VPN web portal allows a remote attacker to potentially…

Fix: 6.0.5+
Fix from $1,600 2019-06-04
Forticlient HIGH 7.8
CVE-2018-13368

A local privilege escalation in Fortinet FortiClient for Windows 6.0.4 and earlier allows attacker to execute unauthorized code or commands via the c…

Fix: after 6.0.4
Fix from $1,950 2019-05-30
Forticlient HIGH 7.8
CVE-2018-9191

A local privilege escalation in Fortinet FortiClient for Windows 6.0.4 and earlier allows attackers to execute unauthorized code or commands via the …

Fix: after 6.0.4
Fix from $1,950 2019-05-30
Forticlient HIGH 7.8
CVE-2018-9193

A researcher has disclosed several vulnerabilities against FortiClient for Windows version 6.0.5 and below, version 5.6.6, the combination of these v…

Fix: after 6.0.4
Fix from $1,950 2019-05-30
Fortios MEDIUM 5.3
CVE-2018-13365

An Information Exposure vulnerability in Fortinet FortiOS 6.0.1, 5.6.5 and below, allow attackers to learn private IP as well as the hostname of Fort…

Fix: after 6.0.1
Fix from $1,600 2019-05-29
Fortiproxy MEDIUM 6.5
CVE-2018-13383 KEVEPSS 34%

A heap buffer overflow in Fortinet FortiOS 6.0.0 through 6.0.4, 5.6.0 through 5.6.10, 5.4.0 through 5.4.12, 5.2.14 and earlier and FortiProxy 2.0.0, …

Fix: 1.2.9 / 5.2.15+
Fix from $1,600 2019-05-29
Forticlient HIGH 7.8
CVE-2019-5589

An Unsafe Search Path vulnerability in FortiClient Online Installer (Windows version before 6.0.6) may allow an unauthenticated, remote attacker with…

Fix: 6.0.6+
Fix from $1,950 2019-05-28
Fortianalyzer MEDIUM 6.1
CVE-2018-13375

An Improper Neutralization of Script-Related HTML Tags in Fortinet FortiAnalyzer 5.6.0 and below and FortiManager 5.6.0 and below allows an attacker …

Fix: after 5.6.0
Fix from $1,600 2019-05-28
Fortimanager HIGH 8.1
CVE-2018-1360

A cleartext transmission of sensitive information vulnerability in Fortinet FortiManager 5.2.0 through 5.2.7, 5.4.0 and 5.4.1 may allow an unauthenti…

Fix: after 5.2.7
Fix from $1,950 2019-04-25