Show filters
211 Total Results
Displaying 71-80 of 211
Sort by:
Attacker Value
Unknown

CVE-2023-41841

Disclosure Date: October 10, 2023 (last updated October 13, 2023)
An improper authorization vulnerability in Fortinet FortiOS 7.0.0 - 7.0.11 and 7.2.0 - 7.2.4 allows an attacker belonging to the prof-admin profile to perform elevated actions.
Attacker Value
Unknown

CVE-2023-41675

Disclosure Date: October 10, 2023 (last updated October 14, 2023)
A use after free vulnerability [CWE-416] in FortiOS version 7.2.0 through 7.2.4 and version 7.0.0 through 7.0.10 and FortiProxy version 7.2.0 through 7.2.2 and version 7.0.0 through 7.0.8 may allow an unauthenticated remote attacker to crash the WAD process via multiple crafted packets reaching proxy policies or firewall policies with proxy mode alongside SSL deep packet inspection.
Attacker Value
Unknown

CVE-2023-40718

Disclosure Date: October 10, 2023 (last updated October 14, 2023)
A interpretation conflict in Fortinet IPS Engine versions 7.321, 7.166 and 6.158 allows attacker to evade IPS features via crafted TCP packets.
Attacker Value
Unknown

CVE-2023-37935

Disclosure Date: October 10, 2023 (last updated October 13, 2023)
A use of GET request method with sensitive query strings vulnerability in Fortinet FortiOS 7.0.0 - 7.0.12, 7.2.0 - 7.2.5 and 7.4.0 allows an attacker to view plaintext passwords of remote services such as RDP or VNC, if the attacker is able to read the GET requests to those services.
Attacker Value
Unknown

CVE-2023-36555

Disclosure Date: October 10, 2023 (last updated October 14, 2023)
An improper neutralization of script-related html tags in a web page (basic xss) in Fortinet FortiOS 7.2.0 - 7.2.4 allows an attacker to execute unauthorized code or commands via the SAML and Security Fabric components.
Attacker Value
Unknown

CVE-2023-33301

Disclosure Date: October 10, 2023 (last updated October 14, 2023)
An improper access control vulnerability in Fortinet FortiOS 7.2.0 - 7.2.4 and 7.4.0 allows an attacker to access a restricted resource from a non trusted host.
Attacker Value
Unknown

CVE-2023-29183

Disclosure Date: September 13, 2023 (last updated October 08, 2023)
An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiProxy 7.2.0 through 7.2.4, 7.0.0 through 7.0.10 and FortiOS 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through 6.4.12, 6.2.0 through 6.2.14 GUI may allow an authenticated attacker to trigger malicious JavaScript code execution via crafted guest management setting.
Attacker Value
Unknown

CVE-2022-22305

Disclosure Date: September 01, 2023 (last updated October 08, 2023)
An improper certificate validation vulnerability [CWE-295] in FortiManager 7.0.1 and below, 6.4.6 and below; FortiAnalyzer 7.0.2 and below, 6.4.7 and below; FortiOS 6.2.x and 6.0.x; FortiSandbox 4.0.x, 3.2.x and 3.1.x may allow a network adjacent and unauthenticated attacker to man-in-the-middle the communication between the listed products and some external peers.
Attacker Value
Unknown

CVE-2023-29182

Disclosure Date: August 17, 2023 (last updated October 08, 2023)
A stack-based buffer overflow vulnerability [CWE-121] in Fortinet FortiOS before 7.0.3 allows a privileged attacker to execute arbitrary code via specially crafted CLI commands, provided the attacker were able to evade FortiOS stack protections.
Attacker Value
Unknown

CVE-2023-33308

Disclosure Date: July 26, 2023 (last updated October 08, 2023)
A stack-based overflow vulnerability [CWE-124] in Fortinet FortiOS version 7.0.0 through 7.0.10 and 7.2.0 through 7.2.3 and FortiProxy version 7.0.0 through 7.0.9 and 7.2.0 through 7.2.2 allows a remote unauthenticated attacker to execute arbitrary code or command via crafted packets reaching proxy policies or firewall policies with proxy mode alongside deep or full packet inspection.