Show filters
874 Total Results
Displaying 201-210 of 874
Sort by:
Attacker Value
Unknown
CVE-2023-44250
Disclosure Date: January 10, 2024 (last updated January 19, 2024)
An improper privilege management vulnerability [CWE-269] in a Fortinet FortiOS HA cluster version 7.4.0 through 7.4.1 and 7.2.5 and in a FortiProxy HA cluster version 7.4.0 through 7.4.1 allows an authenticated attacker to perform elevated actions via crafted HTTP or HTTPS requests.
0
Attacker Value
Unknown
CVE-2023-37934
Disclosure Date: January 10, 2024 (last updated January 19, 2024)
An allocation of resources without limits or throttling vulnerability [CWE-770] in FortiPAM 1.0 all versions allows an authenticated attacker to perform a denial of service attack via sending crafted HTTP or HTTPS requests in a high frequency.
0
Attacker Value
Unknown
CVE-2023-37932
Disclosure Date: January 10, 2024 (last updated January 19, 2024)
An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability [CWE-22] in FortiVoiceEntreprise version 7.0.0 and before 6.4.7 allows an authenticated attacker to read arbitrary files from the system via sending crafted HTTP or HTTPS requests
0
Attacker Value
Unknown
CVE-2023-44252
Disclosure Date: December 13, 2023 (last updated December 19, 2023)
** UNSUPPORTED WHEN ASSIGNED **An improper authentication vulnerability [CWE-287] in Fortinet FortiWAN version 5.2.0 through 5.2.1 and version 5.1.1 through 5.1.2 may allow an authenticated attacker to escalate his privileges via HTTP or HTTPs requests with crafted JWT token values.
0
Attacker Value
Unknown
CVE-2023-44251
Disclosure Date: December 13, 2023 (last updated December 19, 2023)
** UNSUPPORTED WHEN ASSIGNED **A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability [CWE-22] in Fortinet FortiWAN version 5.2.0 through 5.2.1 and version 5.1.1. through 5.1.2 may allow an authenticated attacker to read and delete arbitrary file of the system via crafted HTTP or HTTPs requests.
0
Attacker Value
Unknown
CVE-2023-47536
Disclosure Date: December 13, 2023 (last updated December 19, 2023)
An improper access control vulnerability [CWE-284] in FortiOS version 7.2.0, version 7.0.13 and below, version 6.4.14 and below and FortiProxy version 7.2.3 and below, version 7.0.9 and below, version 2.0.12 and below may allow a remote unauthenticated attacker to bypass the firewall deny geolocalisation policy via timing the bypass with a GeoIP database update.
0
Attacker Value
Unknown
CVE-2023-48791
Disclosure Date: December 13, 2023 (last updated December 16, 2023)
An improper neutralization of special elements used in a command ('Command Injection') vulnerability [CWE-77] in FortiPortal version 7.2.0, version 7.0.6 and below may allow a remote authenticated attacker with at least R/W permission to execute unauthorized commands via specifically crafted arguments in the Schedule System Backup page field.
0
Attacker Value
Unknown
CVE-2023-48782
Disclosure Date: December 13, 2023 (last updated December 16, 2023)
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 allows attacker to execute unauthorized code or commands via specifically crafted http get request parameters
0
Attacker Value
Unknown
CVE-2023-46713
Disclosure Date: December 13, 2023 (last updated December 20, 2023)
An improper output neutralization for logs in Fortinet FortiWeb 6.2.0 - 6.2.8, 6.3.0 - 6.3.23, 7.0.0 - 7.0.9, 7.2.0 - 7.2.5 and 7.4.0 may allow an attacker to forge traffic logs via a crafted URL of the web application.
0
Attacker Value
Unknown
CVE-2023-45587
Disclosure Date: December 13, 2023 (last updated December 16, 2023)
An improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiSandbox version 4.4.1 and 4.4.0 and 4.2.0 through 4.2.5 and 4.0.0 through 4.0.3 and 3.2.0 through 3.2.4 and 3.1.0 through 3.1.5 allows attacker to execute unauthorized code or commands via crafted HTTP requests
0