Show filters
874 Total Results
Displaying 241-250 of 874
Sort by:
Attacker Value
Unknown
CVE-2023-44249
Disclosure Date: October 10, 2023 (last updated February 25, 2025)
An authorization bypass through user-controlled key [CWE-639] vulnerability in Fortinet FortiManager version 7.4.0 and before 7.2.3 and FortiAnalyzer version 7.4.0 and before 7.2.3 allows a remote attacker with low privileges to read sensitive information via crafted HTTP requests.
0
Attacker Value
Unknown
CVE-2023-42788
Disclosure Date: October 10, 2023 (last updated February 25, 2025)
An improper neutralization of special elements used in an os command ('OS Command Injection') vulnerability [CWE-78] in FortiManager & FortiAnalyzer version 7.4.0, version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.8, version 6.4.0 through 6.4.12 and version 6.2.0 through 6.2.11 may allow a local attacker with low privileges to execute unauthorized code via specifically crafted arguments to a CLI command
0
Attacker Value
Unknown
CVE-2023-42787
Disclosure Date: October 10, 2023 (last updated February 25, 2025)
A client-side enforcement of server-side security [CWE-602] vulnerability in Fortinet FortiManager version 7.4.0 and before 7.2.3 and FortiAnalyzer version 7.4.0 and before 7.2.3 may allow a remote attacker with low privileges to access a privileged web console via client side code execution.
0
Attacker Value
Unknown
CVE-2023-42782
Disclosure Date: October 10, 2023 (last updated February 25, 2025)
A insufficient verification of data authenticity vulnerability [CWE-345] in FortiAnalyzer version 7.4.0 and below 7.2.3 allows a remote unauthenticated attacker to send messages to the syslog server of FortiAnalyzer via the knoweldge of an authorized device serial number.
0
Attacker Value
Unknown
CVE-2023-41841
Disclosure Date: October 10, 2023 (last updated February 25, 2025)
An improper authorization vulnerability in Fortinet FortiOS 7.0.0 - 7.0.11 and 7.2.0 - 7.2.4 allows an attacker belonging to the prof-admin profile to perform elevated actions.
0
Attacker Value
Unknown
CVE-2023-41838
Disclosure Date: October 10, 2023 (last updated February 25, 2025)
An improper neutralization of special elements used in an os command ('os command injection') in FortiManager 7.4.0 and 7.2.0 through 7.2.3 may allow attacker to execute unauthorized code or commands via FortiManager cli.
0
Attacker Value
Unknown
CVE-2023-41679
Disclosure Date: October 10, 2023 (last updated February 25, 2025)
An improper access control vulnerability [CWE-284] in FortiManager management interface 7.2.0 through 7.2.2, 7.0.0 through 7.0.7, 6.4.0 through 6.4.11, 6.2 all versions, 6.0 all versions may allow a remote and authenticated attacker with at least "device management" permission on his profile and belonging to a specific ADOM to add and delete CLI script on other ADOMs
0
Attacker Value
Unknown
CVE-2023-41675
Disclosure Date: October 10, 2023 (last updated February 25, 2025)
A use after free vulnerability [CWE-416] in FortiOS version 7.2.0 through 7.2.4 and version 7.0.0 through 7.0.10 and FortiProxy version 7.2.0 through 7.2.2 and version 7.0.0 through 7.0.8 may allow an unauthenticated remote attacker to crash the WAD process via multiple crafted packets reaching proxy policies or firewall policies with proxy mode alongside SSL deep packet inspection.
0
Attacker Value
Unknown
CVE-2023-40718
Disclosure Date: October 10, 2023 (last updated February 25, 2025)
A interpretation conflict in Fortinet IPS Engine versions 7.321, 7.166 and 6.158 allows attacker to evade IPS features via crafted TCP packets.
0
Attacker Value
Unknown
CVE-2023-37939
Disclosure Date: October 10, 2023 (last updated February 25, 2025)
An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiClient for Windows 7.2.0, 7.0 all versions, 6.4 all versions, 6.2 all versions, Linux 7.2.0, 7.0 all versions, 6.4 all versions, 6.2 all versions and Mac 7.2.0 through 7.2.1, 7.0 all versions, 6.4 all versions, 6.2 all versions, may allow a local authenticated attacker with no Administrative privileges to retrieve the list of files or folders excluded from malware scanning.
0