Show filters
20 Total Results
Displaying 11-20 of 20
Sort by:
Attacker Value
Unknown
CVE-2021-22124
Disclosure Date: August 04, 2021 (last updated February 23, 2025)
An uncontrolled resource consumption (denial of service) vulnerability in the login modules of FortiSandbox 3.2.0 through 3.2.2, 3.1.0 through 3.1.4, and 3.0.0 through 3.0.6; and FortiAuthenticator before 6.0.6 may allow an unauthenticated attacker to bring the device into an unresponsive state via specifically-crafted long request parameters.
0
Attacker Value
Unknown
CVE-2021-24005
Disclosure Date: July 06, 2021 (last updated February 22, 2025)
Usage of hard-coded cryptographic keys to encrypt configuration files and debug logs in FortiAuthenticator versions before 6.3.0 may allow an attacker with access to the files or the CLI configuration to decrypt the sensitive data, via knowledge of the hard-coded key.
0
Attacker Value
Unknown
CVE-2019-16154
Disclosure Date: January 07, 2020 (last updated February 21, 2025)
An improper neutralization of input during web page generation in FortiAuthenticator WEB UI 6.0.0 may allow an unauthenticated user to perform a cross-site scripting attack (XSS) via a parameter of the logon page.
0
Attacker Value
Unknown
CVE-2018-9186
Disclosure Date: May 31, 2018 (last updated November 26, 2024)
A cross-site scripting (XSS) vulnerability in Fortinet FortiAuthenticator in versions 4.0.0 to before 5.3.0 "CSRF validation failure" page allows attacker to execute unauthorized script code via inject malicious scripts in HTTP referer header.
0
Attacker Value
Unknown
CVE-2015-1457
Disclosure Date: February 03, 2015 (last updated October 05, 2023)
Fortinet FortiAuthenticator 3.0.0 allows local users to read arbitrary files via the -f flag to the dig command.
0
Attacker Value
Unknown
CVE-2015-1458
Disclosure Date: February 03, 2015 (last updated October 05, 2023)
Fortinet FortiAuthenticator 3.0.0 allows local users to bypass intended restrictions and gain privileges by creating /tmp/privexec/dbgcore_enable_shell_access and executing the "shell" command.
0
Attacker Value
Unknown
CVE-2015-1456
Disclosure Date: February 03, 2015 (last updated October 05, 2023)
Fortinet FortiAuthenticator 3.0.0 logs the PostgreSQL usernames and passwords in cleartext, which allows remote administrators to obtain sensitive information by reading the log at debug/startup/.
0
Attacker Value
Unknown
CVE-2015-1455
Disclosure Date: February 03, 2015 (last updated October 05, 2023)
Fortinet FortiAuthenticator 3.0.0 has a password of (1) slony for the slony PostgreSQL user and (2) www-data for the www-data PostgreSQL user, which makes it easier for remote attackers to obtain access via unspecified vectors.
0
Attacker Value
Unknown
CVE-2015-1459
Disclosure Date: February 03, 2015 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in Fortinet FortiAuthenticator 3.0.0 allows remote attackers to inject arbitrary web script or HTML via the operation parameter to cert/scep/.
0
Attacker Value
Unknown
CVE-2013-6990
Disclosure Date: April 30, 2014 (last updated October 05, 2023)
FortiGuard FortiAuthenticator before 3.0 allows remote administrators to gain privileges via the command line interface.
0