Vulnerability index

Browse CVEs

958 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Fortios MEDIUM 5.9
CVE-2016-7541

Long lived sessions in Fortinet FortiGate devices with FortiOS 5.x before 5.4.0 could violate a security policy during IPS signature updates when the…

Mitigation only
Fix from $1,600 2017-03-30
Fortimanager Firmware HIGH 7.4
CVE-2016-8495

An improper certificate validation vulnerability in Fortinet FortiManager 5.0.6 through 5.2.7 and 5.4.0 through 5.4.1 allows remote attacker to spoof…

Mitigation only
Fix from $1,950 2017-02-13
Connect HIGH 7.2
CVE-2016-8494

Insufficient verification of uploaded files allows attackers with webui administrators privileges to perform arbitrary code execution by uploading a …

Mitigation only
Fix from $1,950 2017-02-09
Fortios MEDIUM 5.9
CVE-2016-8492

The implementation of an ANSI X9.31 RNG in Fortinet FortiGate allows attackers to gain unauthorized read access to data handled by the device via IPS…

Fix: after 4.3.18
Fix from $1,600 2017-02-08
Fortiwlc CRITICAL 9.1
CVE-2016-8491

The presence of a hardcoded account named 'core' in Fortinet FortiWLC allows attackers to gain unauthorized read/write access via a remote shell.

Mitigation only
Fix from $2,300 2017-02-01
Fortimanager Firmware MEDIUM 5.4
CVE-2015-7363

Cross-site scripting (XSS) vulnerability in the advanced settings page in Fortinet FortiManager 5.x before 5.0.12 and 5.2.x before 5.2.3, in hardware…

Mitigation only
Fix from $1,600 2016-10-07
Fortiwlc HIGH 7.2
CVE-2016-7561

Fortinet FortiWLC 6.1-2-29 and earlier, 7.0-9-1, 7.0-10-0, 8.0-5-0, 8.1-2-0, and 8.2-4-0 allow administrators to obtain sensitive user credentials by…

Fix: after 6.1-2-29
Fix from $1,950 2016-10-05
Fortiwlc CRITICAL 9.8
CVE-2016-7560

The rsyncd server in Fortinet FortiWLC 6.1-2-29 and earlier, 7.0-9-1, 7.0-10-0, 8.0-5-0, 8.1-2-0, and 8.2-4-0 has a hardcoded rsync account, which al…

Fix: after 6.1-2-29
Fix from $2,300 2016-10-05
Fortiwan MEDIUM 6.1
CVE-2016-4969

Cross-site scripting (XSS) vulnerability in Fortinet FortiWan (formerly AscernLink) before 4.2.5 allows remote attackers to inject arbitrary web scri…

Fix: after 4.2.4
Fix from $1,600 2016-09-21
Fortiwan MEDIUM 6.5
CVE-2016-4968

The linkreport/tmp/admin_global page in Fortinet FortiWan (formerly AscernLink) before 4.2.5 allows remote authenticated users to discover administra…

Fix: after 4.2.4
Fix from $1,600 2016-09-21
Fortiwan MEDIUM 6.5
CVE-2016-4967

Fortinet FortiWan (formerly AscernLink) before 4.2.5 allows remote authenticated users to obtain sensitive information from (1) a backup of the devic…

Fix: after 4.2.4
Fix from $1,600 2016-09-21
Fortiwan MEDIUM 6.5
CVE-2016-4966

The diagnosis_control.php page in Fortinet FortiWan (formerly AscernLink) before 4.2.5 allows remote authenticated users to download PCAP files via v…

Fix: after 4.2.4
Fix from $1,600 2016-09-21
Fortiwan HIGH 8.8
CVE-2016-4965

Fortinet FortiWan (formerly AscernLink) before 4.2.5 allows remote authenticated users with access to the nslookup functionality to execute arbitrary…

Fix: after 4.2.4
Fix from $1,950 2016-09-21
Fortiswitch CRITICAL 9.8
CVE-2016-4573

Fortinet FortiSwitch FSW-108D-POE, FSW-124D, FSW-124D-POE, FSW-224D-POE, FSW-224D-FPOE, FSW-248D-POE, FSW-248D-FPOE, FSW-424D, FSW-424D-POE, FSW-424D…

Mitigation only
Fix from $2,300 2016-09-09
Fortios CRITICAL 9.8
CVE-2016-6909EPSS 50%

Buffer overflow in the Cookie parser in Fortinet FortiOS 4.x before 4.1.11, 4.2.x before 4.2.13, and 4.3.x before 4.3.9 and FortiSwitch before 3.4.3 …

Fix: 4.1.11 / 4.2.13+
Fix from $2,300 2016-08-24
Fortimanager Firmware MEDIUM 6.1
CVE-2016-3195

Cross-site scripting (XSS) vulnerability in the Web-UI in Fortinet FortiManager 5.x before 5.0.12 and 5.2.x before 5.2.6 and FortiAnalyzer 5.x before…

Mitigation only
Fix from $1,600 2016-08-19
Fortimanager Firmware MEDIUM 6.1
CVE-2016-3194

Cross-site scripting (XSS) vulnerability in the address added page in Fortinet FortiManager 5.x before 5.0.12 and 5.2.x before 5.2.6 and FortiAnalyze…

Mitigation only
Fix from $1,600 2016-08-19
Fortimanager Firmware MEDIUM 5.4
CVE-2016-3193

Cross-site scripting (XSS) vulnerability in the appliance web-application in Fortinet FortiManager 5.x before 5.0.12, 5.2.x before 5.2.6, and 5.4.x b…

Mitigation only
Fix from $1,600 2016-08-19
Fortimanager Firmware MEDIUM 5.4
CVE-2016-3196

Cross-site scripting (XSS) vulnerability in Fortinet FortiAnalyzer 5.x before 5.0.12 and 5.2.x before 5.2.6 and FortiManager 5.x before 5.0.12 and 5.…

Mitigation only
Fix from $1,600 2016-08-05
Fortiweb HIGH 8.8
CVE-2016-4066

Cross-site request forgery (CSRF) vulnerability in Fortinet FortiWeb before 5.5.3 allows remote attackers to hijack the authentication of administrat…

Fix: after 5.5.2
Fix from $1,950 2016-07-13
Fortisandbox Firmware MEDIUM 6.1
CVE-2015-7360

Multiple cross-site scripting (XSS) vulnerabilities in the Web User Interface (WebUI) in Fortinet FortiSandbox before 2.1 allow remote attackers to i…

Fix: after 2.0.4
Fix from $1,600 2016-05-26
Fortios MEDIUM 6.1
CVE-2016-3978EPSS 7%

The Web User Interface (WebUI) in FortiOS 5.0.x before 5.0.13, 5.2.x before 5.2.3, and 5.4.x before 5.4.0 allows remote attackers to redirect users t…

Mitigation only
Fix from $1,600 2016-04-08
Fortios CRITICAL 9.8
CVE-2016-1909EPSS 71%

Fortinet FortiAnalyzer before 5.0.12 and 5.2.x before 5.2.5; FortiSwitch 3.3.x before 3.3.3; FortiCache 3.0.x before 3.0.8; and FortiOS 4.1.x before …

Fix: after 4.3.16
Fix from $2,300 2016-01-15
Forticlient HIGH 7.8
CVE-2015-7362

Fortinet FortiClient Linux SSLVPN before build 2313, when installed on Linux in a home directory that is world readable and executable, allows local …

Mitigation only
Fix from $1,950 2016-01-08
Fortios HIGH 9.3
CVE-2015-7361

FortiOS 5.2.3, when configured to use High Availability (HA) and the dedicated management interface is enabled, does not require authentication for a…

Mitigation only
Fix from $1,950 2015-10-15
Forticlient HIGH 7.2
CVE-2015-5737

The (1) mdare64_48.sys, (2) mdare32_48.sys, (3) mdare32_52.sys, (4) mdare64_52.sys, and (5) Fortishield.sys drivers in Fortinet FortiClient before 5.…

Fix: after 5.2.3
Fix from $1,950 2015-09-03
Forticlient HIGH 7.2
CVE-2015-5736

The Fortishield.sys driver in Fortinet FortiClient before 5.2.4 allows local users to execute arbitrary code with kernel privileges by setting the ca…

Fix: after 5.2.3
Fix from $1,950 2015-09-03
Forticlient HIGH 7.2
CVE-2015-5735

The (1) mdare64_48.sys, (2) mdare32_48.sys, (3) mdare32_52.sys, and (4) mdare64_52.sys drivers in Fortinet FortiClient before 5.2.4 allow local users…

Fix: after 5.2.3
Fix from $1,950 2015-09-03
Fortios MEDIUM 5.0
CVE-2015-5965

The SSL-VPN feature in Fortinet FortiOS before 4.3.13 only checks the first byte of the TLS MAC in finished messages, which makes it easier for remot…

Fix: after 4.3.12
Fix from $1,600 2015-08-11
Fortios MEDIUM 6.4
CVE-2015-2323

FortiOS 5.0.x before 5.0.12 and 5.2.x before 5.2.4 supports anonymous, export, RC4, and possibly other weak ciphers when using TLS to connect to Fort…

Mitigation only
Fix from $1,600 2015-08-11