Show filters
874 Total Results
Displaying 131-140 of 874
Sort by:
Attacker Value
Unknown
CVE-2024-27785
Disclosure Date: July 09, 2024 (last updated September 10, 2024)
An improper neutralization of formula elements in a CSV File vulnerability [CWE-1236] in FortiAIOps version 2.0.0 may allow a remote authenticated attacker to execute arbitrary commands on a client's workstation via poisoned CSV reports.
0
Attacker Value
Unknown
CVE-2024-27784
Disclosure Date: July 09, 2024 (last updated September 10, 2024)
Multiple Exposure of sensitive information to an unauthorized actor vulnerabilities [CWE-200] in FortiAIOps version 2.0.0 may allow an authenticated, remote attacker to retrieve sensitive information from the API endpoint or log files.
0
Attacker Value
Unknown
CVE-2024-27783
Disclosure Date: July 09, 2024 (last updated August 17, 2024)
Multiple cross-site request forgery (CSRF) vulnerabilities [CWE-352] in FortiAIOps version 2.0.0 may allow an unauthenticated remote attacker to perform arbitrary actions on behalf of an authenticated user via tricking the victim to execute malicious GET requests.
0
Attacker Value
Unknown
CVE-2024-27782
Disclosure Date: July 09, 2024 (last updated August 17, 2024)
Multiple insufficient session expiration vulnerabilities [CWE-613] in FortiAIOps version 2.0.0 may allow an attacker to re-use stolen old session tokens to perform unauthorized operations via crafted requests.
0
Attacker Value
Unknown
CVE-2024-26015
Disclosure Date: July 09, 2024 (last updated September 10, 2024)
An incorrect parsing of numbers with different radices vulnerability [CWE-1389] in FortiProxy version 7.4.3 and below, version 7.2.10 and below, version 7.0.17 and below and FortiOS version 7.4.3 and below, version 7.2.8 and below, version 7.0.15 and below IP address validation feature may permit an unauthenticated attacker to bypass the IP blocklist via crafted requests.
0
Attacker Value
Unknown
CVE-2024-23663
Disclosure Date: July 09, 2024 (last updated September 10, 2024)
An improper access control in Fortinet FortiExtender 4.1.1 - 4.1.9, 4.2.0 - 4.2.6, 5.3.2, 7.0.0 - 7.0.4, 7.2.0 - 7.2.4 and 7.4.0 - 7.4.2 allows an attacker to create users with elevated privileges via a crafted HTTP request.
0
Attacker Value
Unknown
CVE-2024-21759
Disclosure Date: July 09, 2024 (last updated September 10, 2024)
An authorization bypass through user-controlled key in Fortinet FortiPortal version 7.2.0, and versions 7.0.0 through 7.0.6 allows attacker to view unauthorized resources via HTTP or HTTPS requests.
0
Attacker Value
Unknown
CVE-2023-50181
Disclosure Date: July 09, 2024 (last updated September 10, 2024)
An improper access control vulnerability [CWE-284] in Fortinet FortiADC version 7.4.0 through 7.4.1 and before 7.2.4 allows a read only authenticated attacker to perform some write actions via crafted HTTP or HTTPS requests.
0
Attacker Value
Unknown
CVE-2023-50179
Disclosure Date: July 09, 2024 (last updated September 10, 2024)
An improper certificate validation vulnerability [CWE-295] in FortiADC 7.4.0, 7.2 all versions, 7.1 all versions, 7.0 all versions may allow a remote and unauthenticated attacker to perform a Man-in-the-Middle attack on the communication channel between the device and public SDN connectors.
0
Attacker Value
Unknown
CVE-2023-50178
Disclosure Date: July 09, 2024 (last updated September 20, 2024)
An improper certificate validation vulnerability [CWE-295] in FortiADC 7.4.0, 7.2.0 through 7.2.3, 7.1 all versions, 7.0 all versions, 6.2 all versions, 6.1 all versions and 6.0 all versions may allow a remote and unauthenticated attacker to perform a Man-in-the-Middle attack on the communication channel between the device and various remote servers such as private SDN connectors and FortiToken Cloud.
0