Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In March 2025
A improper neutralization of special elements used in a command ('command injection') in Fortinet FortiManager versions 7.4.1 through 7.4.3, FortiManager Cloud versions 7.4.1 through 7.4.3 allows attacker to escalation of privilege via specifically crafted packets
CVSS Score
8.8
EPSS Score
0.001
Published
2025-03-14
An improper validation of integrity check value vulnerability [CWE-354] in FortiNDR version 7.4.2 and below, version 7.2.1 and below, version 7.1.1 and below, version 7.0.6 and below may allow an authenticated attacker with at least Read/Write permission on system maintenance to install a corrupted firmware image.
CVSS Score
6.5
EPSS Score
0.0
Published
2025-03-14
IBM Security QRadar 3.12 EDR stores user credentials in plain text which can be read by a local privileged user.
CVSS Score
4.1
EPSS Score
0.0
Published
2025-03-14
IBM Security QRadar 3.12 EDR uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt sensitive credential information.
CVSS Score
5.9
EPSS Score
0.0
Published
2025-03-14
AnĀ improper certificate validation vulnerability [CWE-295] in FortiPortal version 7.4.0, version 7.2.4 and below, version 7.0.8 and below, version 6.0.15 and below when connecting to a FortiManager device, a FortiAnalyzer device, or an SMTP server may allow an unauthenticated attacker in a Man-in-the-Middle position to intercept on and tamper with the encrypted communication channel established between the FortiPortal and those endpoints.
CVSS Score
4.8
EPSS Score
0.0
Published
2025-03-14
In the Linux kernel, the following vulnerability has been resolved: netfilter: allow exp not to be removed in nf_ct_find_expectation Currently nf_conntrack_in() calling nf_ct_find_expectation() will remove the exp from the hash table. However, in some scenario, we expect the exp not to be removed when the created ct will not be confirmed, like in OVS and TC conntrack in the following patches. This patch allows exp not to be removed by setting IPS_CONFIRMED in the status of the tmpl.
CVSS Score
5.5
EPSS Score
0.0
Published
2025-03-14
Tenda AC6 v15.03.05.16 was discovered to contain a buffer overflow via the formWifiWpsOOB function.
CVSS Score
9.8
EPSS Score
0.001
Published
2025-03-14
Tenda AC6 v15.03.05.16 was discovered to contain a buffer overflow via the fromAddressNat function.
CVSS Score
9.8
EPSS Score
0.001
Published
2025-03-14
Tenda AC9 v15.03.05.19(6318) was discovered to contain a buffer overflow via the formWifiWpsOOB function.
CVSS Score
5.9
EPSS Score
0.001
Published
2025-03-14
Tenda AC6 v15.03.05.16 was discovered to contain a buffer overflow via the formSetSpeedWan function.
CVSS Score
9.8
EPSS Score
0.001
Published
2025-03-14


Contact Us

Shodan ® - All rights reserved