Show filters
8 Total Results
Displaying 1-8 of 8
Sort by:
Attacker Value
Unknown

CVE-2017-3130

Disclosure Date: August 10, 2017 (last updated November 26, 2024)
An information disclosure vulnerability in Fortinet FortiOS 5.6.0, 5.4.4 and below versions allows attacker to get FortiOS version info by inspecting FortiOS IKE VendorID packets.
0
Attacker Value
Unknown

CVE-2017-3128

Disclosure Date: May 23, 2017 (last updated November 26, 2024)
A stored XSS (Cross-Site-Scripting) vulnerability in Fortinet FortiOS allows attackers to execute unauthorized code or commands via the policy global-label parameter.
0
Attacker Value
Unknown

CVE-2016-7541

Disclosure Date: March 30, 2017 (last updated November 26, 2024)
Long lived sessions in Fortinet FortiGate devices with FortiOS 5.x before 5.4.0 could violate a security policy during IPS signature updates when the FortiGate's IPSengine is configured in flow mode. All FortiGate versions with IPS configured in proxy mode (the default mode) are not affected.
0
Attacker Value
Unknown

CVE-2016-3978

Disclosure Date: April 08, 2016 (last updated November 25, 2024)
The Web User Interface (WebUI) in FortiOS 5.0.x before 5.0.13, 5.2.x before 5.2.3, and 5.4.x before 5.4.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks or cross-site scripting (XSS) attacks via the "redirect" parameter to "login."
0
Attacker Value
Unknown

CVE-2016-1909

Disclosure Date: January 15, 2016 (last updated November 25, 2024)
Fortinet FortiAnalyzer before 5.0.12 and 5.2.x before 5.2.5; FortiSwitch 3.3.x before 3.3.3; FortiCache 3.0.x before 3.0.8; and FortiOS 4.1.x before 4.1.11, 4.2.x before 4.2.16, 4.3.x before 4.3.17 and 5.0.x before 5.0.8 have a hardcoded passphrase for the Fortimanager_Access account, which allows remote attackers to obtain administrative access via an SSH session.
0
Attacker Value
Unknown

CVE-2015-2323

Disclosure Date: August 11, 2015 (last updated October 05, 2023)
FortiOS 5.0.x before 5.0.12 and 5.2.x before 5.2.4 supports anonymous, export, RC4, and possibly other weak ciphers when using TLS to connect to FortiGuard servers, which allows man-in-the-middle attackers to spoof TLS content by modifying packets.
0
Attacker Value
Unknown

CVE-2014-0351

Disclosure Date: September 10, 2014 (last updated October 05, 2023)
The FortiManager protocol service in Fortinet FortiOS before 4.3.16 and 5.x before 5.0.8 on FortiGate devices does not prevent use of anonymous ciphersuites, which makes it easier for man-in-the-middle attackers to obtain sensitive information or interfere with communications by modifying the client-server data stream.
0
Attacker Value
Unknown

CVE-2014-2216

Disclosure Date: August 25, 2014 (last updated October 05, 2023)
The FortiManager protocol service in Fortinet FortiOS before 4.3.16 and 5.0.0 before 5.0.8 on FortiGate devices allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted request.
0