Show filters
104 Total Results
Displaying 71-80 of 104
Sort by:
Attacker Value
Unknown
CVE-2021-32597
Disclosure Date: August 06, 2021 (last updated February 23, 2025)
Multiple improper neutralization of input during web page generation (CWE-79) in FortiManager and FortiAnalyzer versions 7.0.0, 6.4.5 and below, 6.2.7 and below user interface, may allow a remote authenticated attacker to perform a Stored Cross Site Scripting attack (XSS) by injecting malicious payload in GET parameters.
0
Attacker Value
Unknown
CVE-2021-32603
Disclosure Date: August 05, 2021 (last updated February 23, 2025)
A server-side request forgery (SSRF) (CWE-918) vulnerability in FortiManager and FortiAnalyser GUI 7.0.0, 6.4.5 and below, 6.2.7 and below, 6.0.11 and below, 5.6.11 and below may allow a remote and authenticated attacker to access unauthorized files and services on the system via specifically crafted web requests.
0
Attacker Value
Unknown
CVE-2021-32598
Disclosure Date: August 05, 2021 (last updated February 23, 2025)
An improper neutralization of CRLF sequences in HTTP headers ('HTTP Response Splitting') vulnerability In FortiManager and FortiAnalyzer GUI 7.0.0, 6.4.6 and below, 6.2.8 and below, 6.0.11 and below, 5.6.11 and below may allow an authenticated and remote attacker to perform an HTTP request splitting attack which gives attackers control of the remaining headers and body of the response.
0
Attacker Value
Unknown
CVE-2021-24022
Disclosure Date: July 20, 2021 (last updated February 23, 2025)
A buffer overflow vulnerability in FortiAnalyzer CLI 6.4.5 and below, 6.2.7 and below, 6.0.x and FortiManager CLI 6.4.5 and below, 6.2.7 and below, 6.0.x may allow an authenticated, local attacker to perform a Denial of Service attack by running the `diagnose system geoip-city` command with a large ip value.
0
Attacker Value
Unknown
CVE-2020-12811
Disclosure Date: September 24, 2020 (last updated February 22, 2025)
An improper neutralization of script-related HTML tags in a web page in FortiManager 6.2.0, 6.2.1, 6.2.2, and 6.2.3and FortiAnalyzer 6.2.0, 6.2.1, 6.2.2, and 6.2.3 may allow an attacker to execute a cross site scripting (XSS) via the Identify Provider name field.
0
Attacker Value
Unknown
CVE-2020-9289
Disclosure Date: June 16, 2020 (last updated February 21, 2025)
Use of a hard-coded cryptographic key to encrypt password data in CLI configuration in FortiManager 6.2.3 and below, FortiAnalyzer 6.2.3 and below may allow an attacker with access to the CLI configuration or the CLI backup file to decrypt the sensitive data, via knowledge of the hard-coded key.
0
Attacker Value
Unknown
CVE-2019-17657
Disclosure Date: April 07, 2020 (last updated February 21, 2025)
An Uncontrolled Resource Consumption vulnerability in Fortinet FortiSwitch below 3.6.11, 6.0.6 and 6.2.2, FortiAnalyzer below 6.2.3, FortiManager below 6.2.3 and FortiAP-S/W2 below 6.2.2 may allow an attacker to cause admin webUI denial of service (DoS) via handling special crafted HTTP requests/responses in pieces slowly, as demonstrated by Slow HTTP DoS Attacks.
0
Attacker Value
Unknown
CVE-2019-17654
Disclosure Date: March 15, 2020 (last updated February 21, 2025)
An Insufficient Verification of Data Authenticity vulnerability in FortiManager 6.2.1, 6.2.0, 6.0.6 and below may allow an unauthenticated attacker to perform a Cross-Site WebSocket Hijacking (CSWSH) attack.
0
Attacker Value
Unknown
CVE-2015-3612
Disclosure Date: February 04, 2020 (last updated February 21, 2025)
A Cross-site Scripting (XSS) vulnerability exists in FortiManager 5.2.1 and earlier and 5.0.10 and earlier via an unspecified parameter in the FortiWeb auto update service page.
0
Attacker Value
Unknown
CVE-2015-3611
Disclosure Date: February 04, 2020 (last updated February 21, 2025)
A Command Injection vulnerability exists in FortiManager 5.2.1 and earlier and FortiManager 5.0.10 and earlier via unspecified vectors, which could let a malicious user run systems commands when executing a report.
0