Vulnerabilities
Vulnerable Software
Fortinet:  Security Vulnerabilities
A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.2.0 through 5.2.11 and 5.4.0 through 5.4.4 allows attackers to execute unauthorized code or commands via the "Groups" input while creating or editing User Groups.
CVSS Score
5.4
EPSS Score
0.003
Published
2017-09-12
Fortinet FortiManager 5.0 before 5.0.11 and 5.2 before 5.2.2 allow local users to gain privileges via crafted CLI commands.
CVSS Score
7.8
EPSS Score
0.002
Published
2017-08-22
Fortinet FortiManager 5.0.x before 5.0.11, 5.2.x before 5.2.2 allows remote attackers to obtain arbitrary files via vectors involving another unspecified vulnerability.
CVSS Score
7.5
EPSS Score
0.003
Published
2017-08-11
Cross-site scripting (XSS) vulnerability in Fortinet FortiManager 5.0.x before 5.0.11, 5.2.x before 5.2.2 allows remote authenticated users to inject arbitrary web script or HTML via vectors involving unspecified parameters and a privilege escalation attack.
CVSS Score
5.4
EPSS Score
0.002
Published
2017-08-11
SQL injection vulnerability in Fortinet FortiManager 5.0.x before 5.0.11, 5.2.x before 5.2.2 allows remote attackers to execute arbitrary commands via unspecified parameters.
CVSS Score
9.8
EPSS Score
0.008
Published
2017-08-11
An information disclosure vulnerability in Fortinet FortiOS 5.6.0, 5.4.4 and below versions allows attacker to get FortiOS version info by inspecting FortiOS IKE VendorID packets.
CVSS Score
7.5
EPSS Score
0.003
Published
2017-08-10
An information disclosure vulnerability in Fortinet FortiWeb 5.8.2 and below versions allows logged-in admin user to view SNMPv3 user password in cleartext in webui via the HTML source code.
CVSS Score
4.9
EPSS Score
0.004
Published
2017-08-10
A hard-coded account named 'upgrade' in Fortinet FortiWLM 8.3.0 and lower versions allows a remote attacker to log-in and execute commands with 'upgrade' account privileges.
CVSS Score
9.8
EPSS Score
0.009
Published
2017-07-22
In FortiClientWindows 5.4.1 and 5.4.2, an attacker may escalate privilege via a FortiClientNamedPipe vulnerability.
CVSS Score
8.8
EPSS Score
0.006
Published
2017-06-26
A Cross-Site Scripting vulnerability in Fortinet FortiGate 5.2.0 through 5.2.10 allows attacker to execute unauthorized code or commands via the srcintf parameter during Firewall Policy Creation.
CVSS Score
6.1
EPSS Score
0.003
Published
2017-06-01


Contact Us

Shodan ® - All rights reserved