Vulnerabilities
Vulnerable Software
Fortinet:  >> Fortios  >> 6.4.6  Security Vulnerabilities
An improper validation of certificate with host mismatch [CWE-297] vulnerability in FortiOS versions 6.4.6 and below may allow the connection to a malicious LDAP server via options in GUI, leading to disclosure of sensitive information, such as AD credentials.
CVSS Score
3.5
EPSS Score
0.001
Published
2021-11-02
A buffer underwrite vulnerability in the firmware verification routine of FortiOS before 7.0.1 may allow an attacker located in the adjacent network to potentially execute arbitrary code via a specifically crafted firmware image.
CVSS Score
4.3
EPSS Score
0.001
Published
2021-08-04


Contact Us

Shodan ® - All rights reserved