Show filters
874 Total Results
Displaying 421-430 of 874
Sort by:
Attacker Value
Unknown
CVE-2022-33872
Disclosure Date: October 18, 2022 (last updated February 24, 2025)
An improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerabilities [CWE-78] in Telnet login components of FortiTester 2.3.0 through 3.9.1, 4.0.0 through 4.2.0, 7.0.0 through 7.1.0 may allow an unauthenticated remote attacker to execute arbitrary command in the underlying shell.
0
Attacker Value
Unknown
CVE-2022-29055
Disclosure Date: October 18, 2022 (last updated February 24, 2025)
A access of uninitialized pointer in Fortinet FortiOS version 7.2.0, 7.0.0 through 7.0.5, 6.4.0 through 6.4.8, 6.2.0 through 6.2.10, 6.0.x, FortiProxy version 7.0.0 through 7.0.4, 2.0.0 through 2.0.9, 1.2.x allows a remote unauthenticated or authenticated attacker to crash the sslvpn daemon via an HTTP GET request.
0
Attacker Value
Unknown
CVE-2022-35846
Disclosure Date: October 18, 2022 (last updated February 24, 2025)
An improper restriction of excessive authentication attempts vulnerability [CWE-307] in FortiTester Telnet port 2.3.0 through 3.9.1, 4.0.0 through 4.2.0, 7.0.0 through 7.1.0 may allow an unauthenticated attacker to guess the credentials of an admin user via a brute force attack.
0
Attacker Value
Unknown
CVE-2022-35844
Disclosure Date: October 18, 2022 (last updated February 24, 2025)
An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in the management interface of FortiTester 2.3.0 through 3.9.1, 4.0.0 through 4.2.0, 7.0.0 through 7.1.0 may allow an authenticated attacker to execute unauthorized commands via specifically crafted arguments to commands of the certificate import feature.
0
Attacker Value
Unknown
CVE-2022-26121
Disclosure Date: October 10, 2022 (last updated February 24, 2025)
An exposure of resource to wrong sphere vulnerability [CWE-668] in FortiAnalyzer and FortiManager GUI 7.0.0 through 7.0.3, 6.4.0 through 6.4.8, 6.2.0 through 6.2.9, 6.0.0 through 6.0.11, 5.6.0 through 5.6.11 may allow an unauthenticated and remote attacker to access report template images via referencing the name in the URL path.
0
Attacker Value
Unknown
CVE-2021-44171
Disclosure Date: October 10, 2022 (last updated February 24, 2025)
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiOS version 6.0.0 through 6.0.14, FortiOS version 6.2.0 through 6.2.10, FortiOS version 6.4.0 through 6.4.8, FortiOS version 7.0.0 through 7.0.3 allows attacker to execute privileged commands on a linked FortiSwitch via diagnostic CLI commands.
0
Attacker Value
Unknown
CVE-2022-29061
Disclosure Date: September 09, 2022 (last updated February 24, 2025)
An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiSOAR before 7.2.1 allows an authenticated attacker to execute unauthorized code or commands via crafted HTTP GET requests.
0
Attacker Value
Unknown
CVE-2022-35847
Disclosure Date: September 06, 2022 (last updated February 24, 2025)
An improper neutralization of special elements used in a template engine vulnerability [CWE-1336] in FortiSOAR management interface 7.2.0, 7.0.0 through 7.0.3, 6.4.0 through 6.4.4 may allow a remote and authenticated attacker to execute arbitrary code via a crafted payload.
0
Attacker Value
Unknown
CVE-2022-30298
Disclosure Date: September 06, 2022 (last updated February 24, 2025)
An improper privilege management vulnerability [CWE-269] in Fortinet FortiSOAR before 7.2.1 allows a GUI user who has already found a way to modify system files (via another, unrelated and hypothetical exploit) to execute arbitrary Python commands as root.
0
Attacker Value
Unknown
CVE-2022-29062
Disclosure Date: September 06, 2022 (last updated February 24, 2025)
Multiple relative path traversal vulnerabilities [CWE-23] in Fortinet FortiSOAR before 7.2.1 allows an authenticated attacker to write to the underlying filesystem with nginx permissions via crafted HTTP requests.
0