Vulnerabilities
Vulnerable Software
Fortinet:  >> Fortios  >> 5.6.10  Security Vulnerabilities
A privilege escalation vulnerability in Fortinet FortiOS 6.0.0 to 6.0.6, 5.6.0 to 5.6.10, 5.4 and below allows admin users to elevate their profile to super_admin via restoring modified configurations.
CVSS Score
7.2
EPSS Score
0.004
Published
2019-04-09
CVE-2018-13374
Known exploited
A Improper Access Control in Fortinet FortiOS 6.0.2, 5.6.7 and before, FortiADC 6.1.0, 6.0.0 to 6.0.1, 5.4.0 to 5.4.4 allows attacker to obtain the LDAP server login credentials configured in FortiGate via pointing a LDAP server connectivity test request to a rogue LDAP server instead of the configured one.
CVSS Score
4.3
EPSS Score
0.041
Published
2019-01-22
An information disclosure vulnerability in Fortinet FortiOS 6.0.0 and below versions reveals user's web portal login credentials in a Javascript file sent to client-side when pages bookmarked in web portal use the Single Sign-On feature.
CVSS Score
8.1
EPSS Score
0.012
Published
2018-07-05


Contact Us

Shodan ® - All rights reserved