Show filters
874 Total Results
Displaying 411-420 of 874
Sort by:
Attacker Value
Unknown
CVE-2022-42473
Disclosure Date: November 02, 2022 (last updated February 24, 2025)
A missing authentication for a critical function vulnerability in Fortinet FortiSOAR 6.4.0 - 6.4.4 and 7.0.0 - 7.0.3 and 7.2.0 allows an attacker to disclose information via logging into the database using a privileged account without a password.
0
Attacker Value
Unknown
CVE-2022-39949
Disclosure Date: November 02, 2022 (last updated February 24, 2025)
An improper control of a resource through its lifetime vulnerability [CWE-664] in FortiEDR CollectorWindows 4.0.0 through 4.1, 5.0.0 through 5.0.3.751, 5.1.0 may allow a privileged user to terminate the FortiEDR processes with special tools and bypass the EDR protection.
0
Attacker Value
Unknown
CVE-2022-26119
Disclosure Date: November 02, 2022 (last updated February 24, 2025)
A improper authentication vulnerability in Fortinet FortiSIEM before 6.5.0 allows a local attacker with CLI access to perform operations on the Glassfish server directly via a hardcoded password.
0
Attacker Value
Unknown
CVE-2022-38372
Disclosure Date: November 02, 2022 (last updated February 24, 2025)
A hidden functionality vulnerability [CWE-1242] in FortiTester CLI 2.3.0 through 3.9.1, 4.0.0 through 4.2.0, 7.0.0 through 7.1.0 may allow a local, privileged user to obtain a root shell on the device via an undocumented command.
0
Attacker Value
Unknown
CVE-2022-26122
Disclosure Date: November 02, 2022 (last updated February 24, 2025)
An insufficient verification of data authenticity vulnerability [CWE-345] in FortiClient, FortiMail and FortiOS AV engines version 6.2.168 and below and version 6.4.274 and below may allow an attacker to bypass the AV engine via manipulating MIME attachment with junk and pad characters in base64.
0
Attacker Value
Unknown
CVE-2022-35842
Disclosure Date: November 02, 2022 (last updated February 24, 2025)
An exposure of sensitive information to an unauthorized actor vulnerabiltiy [CWE-200] in FortiOS SSL-VPN versions 7.2.0, versions 7.0.0 through 7.0.6 and versions 6.4.0 through 6.4.9 may allow a remote unauthenticated attacker to gain information about LDAP and SAML settings configured in FortiOS.
0
Attacker Value
Unknown
CVE-2022-38380
Disclosure Date: November 02, 2022 (last updated February 24, 2025)
An improper access control [CWE-284] vulnerability in FortiOS version 7.2.0 and versions 7.0.0 through 7.0.7 may allow a remote authenticated read-only user to modify the interface settings via the API.
0
Attacker Value
Unknown
CVE-2022-38381
Disclosure Date: November 02, 2022 (last updated February 24, 2025)
An improper handling of malformed request vulnerability [CWE-228] exists in FortiADC 5.0 all versions, 6.0.0 all versions, 6.1.0 all versions, 6.2.0 through 6.2.3, and 7.0.0 through 7.0.2. This may allow a remote attacker without privileges to bypass some Web Application Firewall (WAF) protection such as the SQL Injection and XSS filters via a malformed HTTP request.
0
Attacker Value
Unknown
CVE-2022-33874
Disclosure Date: October 18, 2022 (last updated February 24, 2025)
An improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerabilities [CWE-78] in SSH login components of FortiTester 2.3.0 through 3.9.1, 4.0.0 through 4.2.0, 7.0.0 through 7.1.0 may allow an unauthenticated remote attacker to execute arbitrary command in the underlying shell.
0
Attacker Value
Unknown
CVE-2022-33873
Disclosure Date: October 18, 2022 (last updated February 24, 2025)
An improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerabilities [CWE-78] in Console login components of FortiTester 2.3.0 through 3.9.1, 4.0.0 through 4.2.0, 7.0.0 through 7.1.0 may allow an unauthenticated attacker to execute arbitrary command in the underlying shell.
0