6.7

CVSS3.1

CVE-2024-33503 -

A improper privilege management in Fortinet FortiManager version 7.4.0 through 7.4.3, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14, FortiAnalyzer version 7.4.0 through 7.4.2, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14 allows attacker to escalation of privileg…

πŸ“… Published: Jan. 14, 2025, 2:09 p.m. πŸ”„ Last Modified: Jan. 31, 2025, 5:36 p.m.

9.6

CVSS3.1

CVE-2023-37936 -

A use of hard-coded cryptographic key in Fortinet FortiSwitch version 7.4.0 and 7.2.0 through 7.2.5 and 7.0.0 through 7.0.7 and 6.4.0 through 6.4.13 and 6.2.0 through 6.2.7 and 6.0.0 through 6.0.7 allows attacker to execute unauthorized code or commands via crafted requests.

πŸ“… Published: Jan. 14, 2025, 2:09 p.m. πŸ”„ Last Modified: Jan. 31, 2025, 5:42 p.m.

7.6

CVSS3.1

CVE-2023-37937 -

An improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiSwitch version 7.4.0 and 7.2.0 through 7.2.5 and 7.0.0 through 7.0.7 and 6.4.0 through 6.4.13 and 6.2.0 through 6.2.7 and 6.0.0 through 6.0.7 allows attacker to execute unauthorized code o…

πŸ“… Published: Jan. 14, 2025, 2:09 p.m. πŸ”„ Last Modified: Jan. 31, 2025, 5:43 p.m.

6.5

CVSS3.1

CVE-2024-56497 -

An improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiMail versions 7.2.0 through 7.2.4 and 7.0.0 through 7.0.6 and 6.4.0 through 6.4.7, FortiRecorder versions 7.0.0 and 6.4.0 through 6.4.4 allows attacker to execute unauthorized code or comm…

πŸ“… Published: Jan. 14, 2025, 2:09 p.m. πŸ”„ Last Modified: Feb. 3, 2025, 8:49 p.m.

7.1

CVSS3.1

CVE-2024-48884 -

A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiManager 7.6.0 through 7.6.1, FortiManager 7.4.1 through 7.4.3, FortiManager Cloud 7.4.1 through 7.4.3, FortiOS 7.6.0, FortiOS 7.4.0 through 7.4.4, FortiOS 7.2.0 through 7.2.9, FortiOS 7.0…

πŸ“… Published: Jan. 14, 2025, 2:09 p.m. πŸ”„ Last Modified: Jan. 14, 2026, 1:16 p.m.

3.7

CVSS3.1

CVE-2024-52969 -

An Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability [CWE-89] in FortiSIEM ersion 7.1.7 and below, version 7.1.0, version 7.0.3 and below, version 6.7.9 and below, 6.7.8, version 6.6.5 and below, version 6.5.3 and below, version 6.4.4 and below Updat…

πŸ“… Published: Jan. 14, 2025, 2:08 p.m. πŸ”„ Last Modified: Feb. 3, 2025, 10:01 p.m.

7.1

CVSS3.1

CVE-2024-46668 -

An allocation of resources without limits or throttling vulnerability [CWE-770] in FortiOS versions 7.4.0 through 7.4.4, versions 7.2.0 through 7.2.8, versions 7.0.0 through 7.0.15, and versions 6.4.0 through 6.4.15 may allow an unauthenticated remote user to consume all system memory via multiple …

πŸ“… Published: Jan. 14, 2025, 2:08 p.m. πŸ”„ Last Modified: Jan. 14, 2026, 9:16 a.m.

7

CVSS3.1

CVE-2024-35273 -

A out-of-bounds write in Fortinet FortiManager version 7.4.0 through 7.4.2, FortiAnalyzer version 7.4.0 through 7.4.2 allows attacker to escalation of privilege via specially crafted http requests.

πŸ“… Published: Jan. 14, 2025, 2:08 p.m. πŸ”„ Last Modified: Jan. 31, 2025, 5:38 p.m.

4.7

CVSS3.1

CVE-2023-46715 -

An origin validation error [CWE-346] vulnerability in Fortinet FortiOS IPSec VPN version 7.4.0 through 7.4.1 and version 7.2.6 and below allows an authenticated IPSec VPN user with dynamic IP addressing to send (but not receive) packets spoofing the IP of another user via crafted network packets.

πŸ“… Published: Jan. 14, 2025, 2:08 p.m. πŸ”„ Last Modified: Jan. 31, 2025, 5:20 p.m.

6.4

CVSS3.1

CVE-2023-42786 -

A null pointer dereference in FortiOS versions 7.4.0 through 7.4.1, 7.2.0 through 7.2.5, 7.0 all versions, 6.4 all versions , 6.2 all versions and 6.0 all versions allows attacker to trigger a denial of service via a crafted http request.

πŸ“… Published: Jan. 14, 2025, 2:08 p.m. πŸ”„ Last Modified: Jan. 17, 2025, 8:42 p.m.
Total resulsts: 343919
Page 6623 of 34,392
Β« previous page Β» next page
Filters