Show filters
9 Total Results
Displaying 1-9 of 9
Sort by:
Attacker Value
Unknown
CVE-2017-3130
Disclosure Date: August 10, 2017 (last updated November 26, 2024)
An information disclosure vulnerability in Fortinet FortiOS 5.6.0, 5.4.4 and below versions allows attacker to get FortiOS version info by inspecting FortiOS IKE VendorID packets.
0
Attacker Value
Unknown
CVE-2017-3128
Disclosure Date: May 23, 2017 (last updated November 26, 2024)
A stored XSS (Cross-Site-Scripting) vulnerability in Fortinet FortiOS allows attackers to execute unauthorized code or commands via the policy global-label parameter.
0
Attacker Value
Unknown
CVE-2016-7541
Disclosure Date: March 30, 2017 (last updated November 26, 2024)
Long lived sessions in Fortinet FortiGate devices with FortiOS 5.x before 5.4.0 could violate a security policy during IPS signature updates when the FortiGate's IPSengine is configured in flow mode. All FortiGate versions with IPS configured in proxy mode (the default mode) are not affected.
0
Attacker Value
Unknown
CVE-2016-3978
Disclosure Date: April 08, 2016 (last updated November 25, 2024)
The Web User Interface (WebUI) in FortiOS 5.0.x before 5.0.13, 5.2.x before 5.2.3, and 5.4.x before 5.4.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks or cross-site scripting (XSS) attacks via the "redirect" parameter to "login."
0
Attacker Value
Unknown
CVE-2016-1909
Disclosure Date: January 15, 2016 (last updated November 25, 2024)
Fortinet FortiAnalyzer before 5.0.12 and 5.2.x before 5.2.5; FortiSwitch 3.3.x before 3.3.3; FortiCache 3.0.x before 3.0.8; and FortiOS 4.1.x before 4.1.11, 4.2.x before 4.2.16, 4.3.x before 4.3.17 and 5.0.x before 5.0.8 have a hardcoded passphrase for the Fortimanager_Access account, which allows remote attackers to obtain administrative access via an SSH session.
0
Attacker Value
Unknown
CVE-2015-2323
Disclosure Date: August 11, 2015 (last updated October 05, 2023)
FortiOS 5.0.x before 5.0.12 and 5.2.x before 5.2.4 supports anonymous, export, RC4, and possibly other weak ciphers when using TLS to connect to FortiGuard servers, which allows man-in-the-middle attackers to spoof TLS content by modifying packets.
0
Attacker Value
Unknown
CVE-2014-0351
Disclosure Date: September 10, 2014 (last updated October 05, 2023)
The FortiManager protocol service in Fortinet FortiOS before 4.3.16 and 5.x before 5.0.8 on FortiGate devices does not prevent use of anonymous ciphersuites, which makes it easier for man-in-the-middle attackers to obtain sensitive information or interfere with communications by modifying the client-server data stream.
0
Attacker Value
Unknown
CVE-2014-2216
Disclosure Date: August 25, 2014 (last updated October 05, 2023)
The FortiManager protocol service in Fortinet FortiOS before 4.3.16 and 5.0.0 before 5.0.8 on FortiGate devices allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted request.
0
Attacker Value
Unknown
CVE-2013-7182
Disclosure Date: February 04, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in firewall/schedule/recurrdlg in Fortinet FortiOS 5.0.5 allows remote attackers to inject arbitrary web script or HTML via the mkey parameter.
0