<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – FortiOS (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/fortios.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/fortios-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – FortiOS (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:49 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2025-53844 – A out-of-bounds write vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, For...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-53844</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-53844</guid>
    <pubDate>Tue, 12 May 2026 18:16:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-53844</strong></p>
  <p>A out-of-bounds write vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11 allows attacker to execute unauthorized code or commands via specially crafted packets.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-53844">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-22153 – An Authentication Bypass by Primary Weakness vulnerability [CWE-305] vulnerabili...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-22153</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-22153</guid>
    <pubDate>Tue, 10 Feb 2026 16:16:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-22153</strong></p>
  <p>An Authentication Bypass by Primary Weakness vulnerability [CWE-305] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4 may allow an unauthenticated attacker to bypass LDAP authentication of Agentless VPN or FSSO policy, when the remote LDAP server is configured in a specific way.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-305</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-22153">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-24858 – An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24858</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24858</guid>
    <pubDate>Tue, 27 Jan 2026 20:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-24858</strong></p>
  <p>An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.5, FortiAnalyzer 7.4.0 through 7.4.9, FortiAnalyzer 7.2.0 through 7.2.11, FortiAnalyzer 7.0.0 through 7.0.15, FortiManager 7.6.0 through 7.6.5, FortiManager 7.4.0 through 7.4.9, FortiManager 7.2.0 through 7.2.11, FortiManager 7.0.0 through 7.0.15, FortiOS 7…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-288</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24858">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-25249 – A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-25249</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-25249</guid>
    <pubDate>Tue, 13 Jan 2026 17:15:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-25249</strong></p>
  <p>A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4 all versions, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7.0.0 through 7.0.5 allows attacker to execute unauthorized code or commands via specially crafted packets</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-25249">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-59718 – A improper verification of cryptographic signature vulnerability in Fortinet For...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-59718</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-59718</guid>
    <pubDate>Tue, 09 Dec 2025 18:15:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-59718</strong></p>
  <p>A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiProxy 7.6.0 through 7.6.3, FortiProxy 7.4.0 through 7.4.10, FortiProxy 7.2.0 through 7.2.14, FortiProxy 7.0.0 through 7.0.21, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7.0.0 through…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-347</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-59718">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-58413 – A stack-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-58413</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-58413</guid>
    <pubDate>Tue, 18 Nov 2025 17:16:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-58413</strong></p>
  <p>A stack-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiOS 6.2 all versions, FortiOS 6.0 all versions, FortiSASE 25.3.b allows attacker to execute unauthorized code or commands via specially crafted packets</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58413">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-53843 – A stack-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-53843</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-53843</guid>
    <pubDate>Tue, 18 Nov 2025 17:16:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-53843</strong></p>
  <p>A stack-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions allows attacker to execute unauthorized code or commands via specially crafted packets</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-53843">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-58325 – An Incorrect Provision of Specified Functionality vulnerability [CWE-684] in For...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-58325</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-58325</guid>
    <pubDate>Tue, 14 Oct 2025 16:15:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-58325</strong></p>
  <p>An Incorrect Provision of Specified Functionality vulnerability [CWE-684] in FortiOS 7.6.0, 7.4.0 through 7.4.5, 7.2.5 through 7.2.10, 7.0.0 through 7.0.15, 6.4 all versions may allow a local authenticated attacker to execute system commands via crafted CLI commands.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-684</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58325">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-57740 – An Heap-based Buffer Overflow vulnerability [CWE-122] in FortiOS version 7.6.2 a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-57740</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-57740</guid>
    <pubDate>Tue, 14 Oct 2025 16:15:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-57740</strong></p>
  <p>An Heap-based Buffer Overflow vulnerability [CWE-122] in FortiOS version 7.6.2 and below, version 7.4.7 and below, version 7.2.10 and below, 7.0 all versions, 6.4 all versions; FortiPAM version 1.5.0, version 1.4.2 and below, 1.3 all versions, 1.2 all versions, 1.1 all versions, 1.0 all versions and FortiProxy version 7.6.2 and below, version 7.4.3 and below, 7.2 all versions, 7.0 all versions RD…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-57740">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-25253 – An Improper Validation of Certificate with Host Mismatch vulnerability [CWE-297]...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-25253</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-25253</guid>
    <pubDate>Tue, 14 Oct 2025 16:15:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-25253</strong></p>
  <p>An Improper Validation of Certificate with Host Mismatch vulnerability [CWE-297] in FortiProxy version 7.6.1 and below, version 7.4.8 and below, 7.2 all versions, 7.0 all versions and FortiOS version 7.6.2 and below, version 7.4.8 and below, 7.2 all versions, 7.0 all versions ZTNA proxy may allow an unauthenticated attacker in a man-in-the middle position to intercept and tamper with connections…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-297</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-25253">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-50571 – A heap-based buffer overflow vulnerability in Fortinet FortiAnalyzer 7.6.0 throu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-50571</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-50571</guid>
    <pubDate>Tue, 14 Oct 2025 16:15:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-50571</strong></p>
  <p>A heap-based buffer overflow vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.2, FortiAnalyzer 7.4.0 through 7.4.5, FortiAnalyzer 7.2.0 through 7.2.9, FortiAnalyzer 7.0.0 through 7.0.13, FortiAnalyzer 6.4 all versions, FortiAnalyzer 6.2 all versions, FortiAnalyzer 6.0 all versions, FortiAnalyzer Cloud 7.4.1 through 7.4.5, FortiAnalyzer Cloud 7.2.1 through 7.2.9, FortiAnalyzer Cloud 7.0.1…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-50571">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-53744 – An incorrect privilege assignment vulnerability [CWE-266] in FortiOS Security Fa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-53744</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-53744</guid>
    <pubDate>Tue, 12 Aug 2025 19:15:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-53744</strong></p>
  <p>An incorrect privilege assignment vulnerability [CWE-266] in FortiOS Security Fabric version 7.6.0 through 7.6.2, 7.4.0 through 7.4.7, 7.2 all versions, 7.0 all versions, 6.4 all versions, may allow a remote authenticated attacker with high privileges to escalate their privileges to super-admin via registering the device to a malicious FortiManager.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-266</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-53744">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-26009 – An authentication bypass using an alternate path or channel [CWE-288] vulnerabil...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-26009</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-26009</guid>
    <pubDate>Tue, 12 Aug 2025 19:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-26009</strong></p>
  <p>An authentication bypass using an alternate path or channel [CWE-288] vulnerability in Fortinet FortiOS 6.4.0 through 6.4.15, FortiOS 6.2.0 through 6.2.16, FortiOS 6.0 all versions, FortiPAM 1.2.0, FortiPAM 1.1.0 through 1.1.2, FortiPAM 1.0.0 through 1.0.3, FortiProxy 7.4.0 through 7.4.2, FortiProxy 7.2.0 through 7.2.8, FortiProxy 7.0.0 through 7.0.15, FortiSwitchManager 7.2.0 through 7.2.3, Fort…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-288</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-26009">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-52965 – A missing critical step in authentication vulnerability [CWE-304] in Fortinet Fo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-52965</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-52965</guid>
    <pubDate>Tue, 08 Jul 2025 15:15:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-52965</strong></p>
  <p>A missing critical step in authentication vulnerability [CWE-304] in Fortinet FortiOS version 7.6.0 through 7.6.1, 7.4.0 through 7.4.5, 7.2.0 through 7.2.10, and before 7.0.16 & FortiProxy version 7.6.0 through 7.6.1, 7.4.0 through 7.4.8, 7.2.0 through 7.2.13 and before 7.0.20 allows an API-user using api-key + PKI user certificate authentication to login even if the certificate is invalid.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-304</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-52965">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-22252 – A missing authentication for critical function in Fortinet FortiProxy versions 7...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-22252</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-22252</guid>
    <pubDate>Wed, 28 May 2025 08:15:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-22252</strong></p>
  <p>A missing authentication for critical function in Fortinet FortiProxy versions 7.6.0 through 7.6.1, FortiSwitchManager version 7.2.5, and FortiOS versions 7.4.4 through 7.4.6 and version 7.6.0 may allow an attacker with knowledge of an existing admin account to access the device as a valid admin via an authentication bypass.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-22252">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-26013 – A improper restriction of communication channel to intended endpoints vulnerabil...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-26013</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-26013</guid>
    <pubDate>Tue, 08 Apr 2025 14:15:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-26013</strong></p>
  <p>A improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in Fortinet FortiOS version 7.4.0 through 7.4.4, 7.2.0 through 7.2.8, 7.0.0 through 7.0.15, 6.4.0 through 6.4.15 and before 6.2.16, Fortinet FortiProxy version 7.4.0 through 7.4.2, 7.2.0 through 7.2.9 and before 7.0.15, Fortinet FortiManager version 7.4.0 through 7.4.2, 7.2.0 through 7.2.4, 7.0.0 through…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-923</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-26013">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-25610 – A buffer underwrite ('buffer underflow') vulnerability in the administrative int...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-25610</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-25610</guid>
    <pubDate>Mon, 24 Mar 2025 16:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-25610</strong></p>
  <p>A buffer underwrite ('buffer underflow') vulnerability in the administrative interface of Fortinet FortiOS version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.6, version 6.4.0 through 6.4.11 and version 6.2.12 and below, FortiProxy version 7.2.0 through 7.2.2, version 7.0.0 through 7.0.8, version 2.0.12 and below and FortiOS-6K7K version 7.0.5, version 6.4.0 through 6.4.10 and version 6.2.0 th…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-124</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-25610">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-26006 – An improper neutralization of input during web page Generation vulnerability [CW...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-26006</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-26006</guid>
    <pubDate>Fri, 14 Mar 2025 10:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-26006</strong></p>
  <p>An improper neutralization of input during web page Generation vulnerability [CWE-79] in FortiOS version 7.4.3 and below, version 7.2.7 and below, version 7.0.13 and below and FortiProxy version 7.4.3 and below, version 7.2.9 and below, version 7.0.16 and below web SSL VPN UI may allow a remote unauthenticated attacker to perform a Cross-Site Scripting attack via a malicious samba server.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-26006">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-45324 – A use of externally-controlled format string vulnerability [CWE-134] in FortiOS ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-45324</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-45324</guid>
    <pubDate>Tue, 11 Mar 2025 15:15:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-45324</strong></p>
  <p>A use of externally-controlled format string vulnerability [CWE-134] in FortiOS version 7.4.0 through 7.4.4, version 7.2.0 through 7.2.9, version 7.0.0 through 7.0.15 and before 6.4.15, FortiProxy version 7.4.0 through 7.4.6, version 7.2.0 through 7.2.12 and before 7.0.19, FortiPAM version 1.4.0 through 1.4.2 and before 1.3.1, FortiSRA version 1.4.0 through 1.4.2 and before 1.3.1 and FortiWeb ver…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-134</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-45324">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-24472 – An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-24472</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-24472</guid>
    <pubDate>Tue, 11 Feb 2025 17:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-24472</strong></p>
  <p>An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS 7.0.0 through 7.0.16 and FortiProxy 7.2.0 through 7.2.12, 7.0.0 through 7.0.19 may allow a remote unauthenticated attacker with prior knowledge of upstream and downstream devices serial numbers to gain super-admin privileges on the downstream device, if the Security Fabric is enabled, via crafted…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-288</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-24472">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-40591 – An incorrect privilege assignment vulnerability [CWE-266] in Fortinet FortiOS ve...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-40591</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-40591</guid>
    <pubDate>Tue, 11 Feb 2025 17:15:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-40591</strong></p>
  <p>An incorrect privilege assignment vulnerability [CWE-266] in Fortinet FortiOS version 7.6.0, 7.4.0 through 7.4.4, 7.2.0 through 7.2.9 and before 7.0.15 allows an authenticated admin whose access profile has the Security Fabric permission to escalate their privileges to super-admin by connecting the targetted FortiGate to a malicious upstream FortiGate they control.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-266</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-40591">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-35279 – A stack-based buffer overflow [CWE-121] vulnerability in Fortinet FortiOS versio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-35279</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-35279</guid>
    <pubDate>Tue, 11 Feb 2025 17:15:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-35279</strong></p>
  <p>A stack-based buffer overflow [CWE-121] vulnerability in Fortinet FortiOS version 7.2.4 through 7.2.8 and version 7.4.0 through 7.4.4 allows a remote unauthenticated attacker to execute arbitrary code or commands via crafted UDP packets through the CAPWAP control, provided the attacker were able to evade FortiOS stack protections and provided the fabric service is running on the exposed interface.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-35279">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-55591 – An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-55591</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-55591</guid>
    <pubDate>Tue, 14 Jan 2025 14:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-55591</strong></p>
  <p>An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy version 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12 allows a remote attacker to gain super-admin privileges via crafted requests to Node.js websocket module.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-288</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-55591">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-48886 – A weak authentication in Fortinet FortiOS versions 7.4.0 through 7.4.4, 7.2.0 th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-48886</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-48886</guid>
    <pubDate>Tue, 14 Jan 2025 14:15:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-48886</strong></p>
  <p>A weak authentication in Fortinet FortiOS versions 7.4.0 through 7.4.4, 7.2.0 through 7.2.8, 7.0.0 through 7.0.15, 6.4.0 through 6.4.15, FortiProxy versions 7.4.0 through 7.4.4, 7.2.0 through 7.2.10, 7.0.0 through 7.0.17, 2.0.0 through 2.0.14, FortiManager versions 7.6.0 through 7.6.1, 7.4.1 through 7.4.3, FortiManager Cloud versions 7.4.1 through 7.4.3, FortiAnalyzer Cloud versions 7.4.1 through…</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-1390</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-48886">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-48884 – A improper limitation of a pathname to a restricted directory ('path traversal')...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-48884</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-48884</guid>
    <pubDate>Tue, 14 Jan 2025 14:15:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-48884</strong></p>
  <p>A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiManager 7.6.0 through 7.6.1, FortiManager 7.4.1 through 7.4.3, FortiManager Cloud 7.4.1 through 7.4.3, FortiOS 7.6.0, FortiOS 7.4.0 through 7.4.4, FortiOS 7.2.0 through 7.2.9, FortiOS 7.0.0 through 7.0.15, FortiOS 6.4.0 through 6.4.15, FortiProxy 7.4.0 through 7.4.5, FortiProxy 7.2.0 th…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-48884">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-46670 – An Out-of-bounds Read vulnerability [CWE-125] in FortiOS version 7.6.0, version ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-46670</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-46670</guid>
    <pubDate>Tue, 14 Jan 2025 14:15:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-46670</strong></p>
  <p>An Out-of-bounds Read vulnerability [CWE-125] in FortiOS version 7.6.0, version 7.4.4 and below, version 7.2.9 and below and FortiSASE FortiOS tenant version 24.3.b IPsec IKE service may allow an unauthenticated remote attacker to trigger memory consumption leading to Denial of Service via crafted requests.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-46670">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-46668 – An allocation of resources without limits or throttling vulnerability [CWE-770] ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-46668</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-46668</guid>
    <pubDate>Tue, 14 Jan 2025 14:15:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-46668</strong></p>
  <p>An allocation of resources without limits or throttling vulnerability [CWE-770] in FortiOS versions 7.4.0 through 7.4.4, versions 7.2.0 through 7.2.8, versions 7.0.0 through 7.0.15, and versions 6.4.0 through 6.4.15 may allow an unauthenticated remote user to consume all system memory via multiple large file uploads.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-46668">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-50176 – A session fixation in Fortinet FortiOS version 7.4.0 through 7.4.3 and 7.2.0 thr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-50176</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-50176</guid>
    <pubDate>Tue, 12 Nov 2024 19:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-50176</strong></p>
  <p>A session fixation in Fortinet FortiOS version 7.4.0 through 7.4.3 and 7.2.0 through 7.2.7 and 7.0.0 through 7.0.13 allows attacker to execute unauthorized code or commands via phishing SAML authentication link.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-384</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-50176">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-26010 – A stack-based buffer overflow in Fortinet FortiPAM version 1.2.0, 1.1.0 through ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-26010</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-26010</guid>
    <pubDate>Tue, 11 Jun 2024 15:16:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-26010</strong></p>
  <p>A stack-based buffer overflow in Fortinet FortiPAM version 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiWeb, FortiAuthenticator, FortiSwitchManager version 7.2.0 through 7.2.3, 7.0.1 through 7.0.3, FortiOS version 7.4.0 through 7.4.3, 7.2.0 through 7.2.7, 7.0.0 through 7.0.14, 6.4.0 through 6.4.15, 6.2.0 through 6.2.16, 6.0.0 through 6.0.18, FortiProxy version 7.4.0 through 7.4.2, 7.2.0…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-26010">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-23110 – A stack-based buffer overflow in Fortinet FortiOS version 7.4.0 through 7.4.2, 7...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-23110</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-23110</guid>
    <pubDate>Tue, 11 Jun 2024 15:16:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-23110</strong></p>
  <p>A stack-based buffer overflow in Fortinet FortiOS version 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, 6.0 all versions allows attacker to execute unauthorized code or commands via specially crafted commands</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-23110">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-46714 – A stack-based buffer overflow [CWE-121] vulnerability in Fortinet FortiOS versio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-46714</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-46714</guid>
    <pubDate>Tue, 14 May 2024 17:15:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-46714</strong></p>
  <p>A stack-based buffer overflow [CWE-121] vulnerability in Fortinet FortiOS version 7.2.1 through 7.2.6 and version 7.4.0 through 7.4.1 allows a privileged attacker over the administrative interface to execute arbitrary code or commands via crafted HTTP or HTTPs requests.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-46714">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-41677 – A insufficiently protected credentials in Fortinet FortiProxy 7.4.0, 7.2.0 throu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-41677</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-41677</guid>
    <pubDate>Tue, 09 Apr 2024 15:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-41677</strong></p>
  <p>A insufficiently protected credentials in Fortinet FortiProxy 7.4.0, 7.2.0 through 7.2.6, 7.0.0 through 7.0.12, 2.0.0 through 2.0.13, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6, 1.0.0 through 1.0.7, Fortinet FortiOS 7.4.0 through 7.4.1, 7.2.0 through 7.2.6, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, 6.0.0 through 6.0.17 allows attacker to execute unauthorized code or command…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-522</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-41677">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-23112 – An authorization bypass through user-controlled key vulnerability [CWE-639] in F...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-23112</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-23112</guid>
    <pubDate>Tue, 12 Mar 2024 15:15:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-23112</strong></p>
  <p>An authorization bypass through user-controlled key vulnerability [CWE-639] in FortiOS version 7.4.0 through 7.4.1, 7.2.0 through 7.2.6, 7.0.1 through 7.0.13, 6.4.7 through 6.4.14, and FortiProxy version 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0.14 SSL-VPN may allow an authenticated attacker to gain access to another user’s bookmark via URL manipulation.</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-639</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-23112">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-46717 – An improper authentication vulnerability [CWE-287] in FortiOS versions 7.4.1 and...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-46717</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-46717</guid>
    <pubDate>Tue, 12 Mar 2024 15:15:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-46717</strong></p>
  <p>An improper authentication vulnerability [CWE-287] in FortiOS versions 7.4.1 and below, versions 7.2.6 and below, and versions 7.0.12 and below when configured with FortiAuthenticator in HA may allow a readonly user to gain read-write access via successive login attempts.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-46717">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-42790 – A stack-based buffer overflow in Fortinet FortiOS 7.4.0 through 7.4.1, 7.2.0 thr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-42790</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-42790</guid>
    <pubDate>Tue, 12 Mar 2024 15:15:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-42790</strong></p>
  <p>A stack-based buffer overflow in Fortinet FortiOS 7.4.0 through 7.4.1, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, FortiProxy 7.4.0, 7.2.0 through 7.2.6, 7.0.0 through 7.0.12, 2.0.0 through 2.0.13 allows attacker to execute unauthorized code or commands via specially crafted HTTP requests.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-42790">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-42789 – A out-of-bounds write in Fortinet FortiOS 7.4.0 through 7.4.1, 7.2.0 through 7.2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-42789</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-42789</guid>
    <pubDate>Tue, 12 Mar 2024 15:15:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-42789</strong></p>
  <p>A out-of-bounds write in Fortinet FortiOS 7.4.0 through 7.4.1, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, FortiProxy 7.4.0, 7.2.0 through 7.2.6, 7.0.0 through 7.0.12, 2.0.0 through 2.0.13 allows attacker to execute unauthorized code or commands via specially crafted HTTP requests.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-42789">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-29181 – A use of externally-controlled format string in Fortinet FortiOS 7.2.0 through 7...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-29181</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-29181</guid>
    <pubDate>Thu, 22 Feb 2024 10:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-29181</strong></p>
  <p>A use of externally-controlled format string in Fortinet FortiOS 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through 6.4.12, 6.2.0 through 6.2.14, 6.0.0 through 6.0.16, FortiProxy 7.2.0 through 7.2.4, 7.0.0 through 7.0.10, 2.0.0 through 2.0.12, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6, 1.0.0 through 1.0.7, FortiPAM 1.0.0 through 1.0.3 allows attacker to execute unauthorized code or commands…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-134</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-29181">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-29180 – A null pointer dereference in Fortinet FortiOS version 7.2.0 through 7.2.4, 7.0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-29180</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-29180</guid>
    <pubDate>Thu, 22 Feb 2024 10:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-29180</strong></p>
  <p>A null pointer dereference in Fortinet FortiOS version 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through 6.4.12, 6.2.0 through 6.2.14, 6.0.0 through 6.0.16, FortiProxy 7.2.0 through 7.2.3, 7.0.0 through 7.0.10, 2.0.0 through 2.0.12, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6, 1.0.0 through 1.0.7 allows attacker to denial of service via specially crafted HTTP requests.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-29180">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-23113 – A use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-23113</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-23113</guid>
    <pubDate>Thu, 15 Feb 2024 14:15:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-23113</strong></p>
  <p>A use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, FortiProxy versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0.14, FortiPAM versions 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiSwitchManager versions 7.2.0 through 7.2.3, 7.0.0 through 7.0.3 allows attacker to execute unauthorized c…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-134</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-23113">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-21762 – A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-21762</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-21762</guid>
    <pubDate>Fri, 09 Feb 2024 09:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-21762</strong></p>
  <p>A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, 6.0.0 through 6.0.17, FortiProxy versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0.14, 2.0.0 through 2.0.13, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6, 1.0.0 through 1.0.7 allows attacker to execute unauthorized code or c…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-21762">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-44250 – An improper privilege management vulnerability [CWE-269] in a Fortinet FortiOS H...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-44250</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-44250</guid>
    <pubDate>Wed, 10 Jan 2024 18:15:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-44250</strong></p>
  <p>An improper privilege management vulnerability [CWE-269] in a Fortinet FortiOS HA cluster version 7.4.0 through 7.4.1 and 7.2.5 and in a FortiProxy HA cluster version 7.4.0 through 7.4.1 allows an authenticated attacker to perform elevated actions via crafted HTTP or HTTPS requests.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-44250">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-41678 – A double free in Fortinet FortiOS versions 7.0.0 through 7.0.5, FortiPAM version...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-41678</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-41678</guid>
    <pubDate>Wed, 13 Dec 2023 07:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-41678</strong></p>
  <p>A double free in Fortinet FortiOS versions 7.0.0 through 7.0.5, FortiPAM version 1.0.0 through 1.0.3, 1.1.0 through 1.1.1 allows attacker to execute unauthorized code or commands via specifically crafted request.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-415</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-41678">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-36639 – A use of externally-controlled format string in Fortinet FortiProxy versions 7.2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-36639</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-36639</guid>
    <pubDate>Wed, 13 Dec 2023 07:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-36639</strong></p>
  <p>A use of externally-controlled format string in Fortinet FortiProxy versions 7.2.0 through 7.2.4, 7.0.0 through 7.0.10, FortiOS versions 7.4.0, 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through 6.4.12, 6.2.0 through 6.2.15, 6.0.0 through 6.0.17, FortiPAM versions 1.0.0 through 1.0.3 allows attacker to execute unauthorized code or commands  via specially crafted API requests.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-134</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-36639">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-41841 – An improper authorization vulnerability in Fortinet FortiOS 7.0.0 - 7.0.11 and 7...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-41841</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-41841</guid>
    <pubDate>Tue, 10 Oct 2023 17:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-41841</strong></p>
  <p>An improper authorization vulnerability in Fortinet FortiOS 7.0.0 - 7.0.11 and 7.2.0 - 7.2.4 allows an attacker belonging to the prof-admin profile to perform elevated actions.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-285</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-41841">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-29183 – An improper neutralization of input during web page generation ('Cross-site Scri...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-29183</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-29183</guid>
    <pubDate>Wed, 13 Sep 2023 13:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-29183</strong></p>
  <p>An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiProxy 7.2.0 through 7.2.4, 7.0.0 through 7.0.10 and FortiOS 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through 6.4.12, 6.2.0 through 6.2.14 GUI may allow an authenticated attacker to trigger malicious JavaScript code execution via crafted guest management setting.</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-29183">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-33308 – A stack-based overflow vulnerability [CWE-124] in Fortinet FortiOS version 7.0.0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-33308</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-33308</guid>
    <pubDate>Wed, 26 Jul 2023 15:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-33308</strong></p>
  <p>A stack-based overflow vulnerability [CWE-124] in Fortinet FortiOS version 7.0.0 through 7.0.10 and 7.2.0 through 7.2.3 and FortiProxy version 7.0.0 through 7.0.9 and 7.2.0 through 7.2.2 allows a remote unauthenticated attacker to execute arbitrary code or command via crafted packets reaching proxy policies or firewall policies with proxy mode alongside deep or full packet inspection.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-33308">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-27997 – A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-27997</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-27997</guid>
    <pubDate>Tue, 13 Jun 2023 09:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-27997</strong></p>
  <p>A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, version 6.4.12 and below, version 6.0.16 and below and FortiProxy version 7.2.3 and below, version 7.0.9 and below, version 2.0.12 and below, version 1.2 all versions, version 1.1 all versions SSL-VPN may allow a remote attacker to execute arbitrary code or commands via specifically…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-27997">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-41327 – A cleartext transmission of sensitive information vulnerability [CWE-319] in For...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-41327</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-41327</guid>
    <pubDate>Tue, 13 Jun 2023 09:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-41327</strong></p>
  <p>A cleartext transmission of sensitive information vulnerability [CWE-319] in Fortinet FortiOS version 7.2.0 through 7.2.4, 7.0.0 through 7.0.8, FortiProxy version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.8 allows an authenticated attacker with readonly superadmin privileges to intercept traffic in order to obtain other adminstrators cookies via diagnose CLI commands.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-319</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-41327">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-22640 – A out-of-bounds write in Fortinet FortiOS version 7.2.0 through 7.2.3, FortiOS v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-22640</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-22640</guid>
    <pubDate>Wed, 03 May 2023 22:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-22640</strong></p>
  <p>A out-of-bounds write in Fortinet FortiOS version 7.2.0 through 7.2.3, FortiOS version 7.0.0 through 7.0.10, FortiOS version 6.4.0 through 6.4.11, FortiOS version 6.2.0 through 6.2.13, FortiOS all versions 6.0,  FortiProxy version 7.2.0 through 7.2.1, FortiProxy version 7.0.0 through 7.0.7, FortiProxy all versions 2.0, FortiProxy all versions 1.2, FortiProxy all versions 1.1, FortiProxy all versi…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-22640">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-41330 – An improper neutralization of input during web page generation vulnerability ('C...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-41330</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-41330</guid>
    <pubDate>Tue, 11 Apr 2023 17:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-41330</strong></p>
  <p>An improper neutralization of input during web page generation vulnerability ('Cross-site Scripting') [CWE-79] in Fortinet FortiOS version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.9, version 6.4.0 through 6.4.11 and before 6.2.12 and FortiProxy version 7.2.0 through 7.2.1 and before 7.0.7 allows an unauthenticated attacker to perform an XSS attack via crafted HTTP GET requests.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-41330">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-42476 – A relative path traversal vulnerability [CWE-23] in Fortinet FortiOS version 7.2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-42476</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-42476</guid>
    <pubDate>Tue, 07 Mar 2023 17:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-42476</strong></p>
  <p>A relative path traversal vulnerability [CWE-23] in Fortinet FortiOS version 7.2.0 through 7.2.2, 7.0.0 through 7.0.8 and before 6.4.11, FortiProxy version 7.2.0 through 7.2.2 and 7.0.0 through 7.0.8 allows privileged VDOM administrators to escalate their privileges to super admin of the box via crafted CLI requests.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-23</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-42476">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-41335 – A relative path traversal vulnerability [CWE-23] in Fortinet FortiOS version 7.2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-41335</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-41335</guid>
    <pubDate>Thu, 16 Feb 2023 19:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-41335</strong></p>
  <p>A relative path traversal vulnerability [CWE-23] in Fortinet FortiOS version 7.2.0 through 7.2.2, 7.0.0 through 7.0.8 and before 6.4.10, FortiProxy version 7.2.0 through 7.2.1, 7.0.0 through 7.0.7 and before 2.0.10, FortiSwitchManager 7.2.0 and before 7.0.0  allows an authenticated attacker to read and write files on the underlying Linux system via crafted HTTP requests.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-23</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-41335">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-41334 – An improper neutralization of input during web page generation [CWE-79] vulnerab...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-41334</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-41334</guid>
    <pubDate>Thu, 16 Feb 2023 19:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-41334</strong></p>
  <p>An improper neutralization of input during web page generation [CWE-79] vulnerability in FortiOS versions 7.0.0 to 7.0.7 and 7.2.0 to 7.2.3 may allow a remote, unauthenticated attacker to launch a cross site scripting (XSS) attack via the "redir" parameter of the URL seen when the "Sign in with FortiCloud" button is clicked.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-41334">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-42475 – A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-42475</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-42475</guid>
    <pubDate>Mon, 02 Jan 2023 09:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-42475</strong></p>
  <p>A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0 through 6.4.10, 6.2.0 through 6.2.11, 6.0.15 and earlier  and FortiProxy SSL-VPN 7.2.0 through 7.2.1, 7.0.7 and earlier may allow a remote unauthenticated attacker to execute arbitrary code or commands via specifically crafted requests.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-197</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-42475">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-35843 – An authentication bypass by assumed-immutable data vulnerability [CWE-302] in th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-35843</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-35843</guid>
    <pubDate>Tue, 06 Dec 2022 17:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-35843</strong></p>
  <p>An authentication bypass by assumed-immutable data vulnerability [CWE-302] in the FortiOS SSH login component 7.2.0,  7.0.0 through 7.0.7,  6.4.0 through 6.4.9, 6.2 all versions, 6.0 all versions and FortiProxy SSH login component 7.0.0 through 7.0.5, 2.0.0 through 2.0.10, 1.2.0 all versions may allow a remote and unauthenticated attacker to login into the device via sending specially crafted Acc…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-35843">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-29055 – A access of uninitialized pointer in Fortinet FortiOS version 7.2.0, 7.0.0 throu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-29055</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-29055</guid>
    <pubDate>Tue, 18 Oct 2022 15:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-29055</strong></p>
  <p>A access of uninitialized pointer in Fortinet FortiOS version 7.2.0, 7.0.0 through 7.0.5, 6.4.0 through 6.4.8, 6.2.0 through 6.2.10, 6.0.x, FortiProxy version 7.0.0 through 7.0.4, 2.0.0 through 2.0.9, 1.2.x allows a remote unauthenticated or authenticated attacker to crash the sslvpn daemon via an HTTP GET request.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-824</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-29055">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-40684 – An authentication bypass using an alternate path or channel [CWE-288] in Fortine...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-40684</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-40684</guid>
    <pubDate>Tue, 18 Oct 2022 14:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-40684</strong></p>
  <p>An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6, FortiProxy version 7.2.0 and version 7.0.0 through 7.0.6 and FortiSwitchManager version 7.2.0 and 7.0.0 allows an unauthenticated atttacker to perform operations on the administrative interface via specially crafted HTTP or HTTPS requests.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-40684">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-44171 – A improper neutralization of special elements used in an os command ('os command...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-44171</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-44171</guid>
    <pubDate>Mon, 10 Oct 2022 14:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-44171</strong></p>
  <p>A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiOS version 6.0.0 through 6.0.14, FortiOS version 6.2.0 through 6.2.10, FortiOS version 6.4.0 through 6.4.8, FortiOS version 7.0.0 through 7.0.3 allows attacker to execute privileged commands on a linked FortiSwitch via diagnostic CLI commands.</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-44171">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-22299 – A format string vulnerability [CWE-134] in the command line interpreter of Forti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-22299</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-22299</guid>
    <pubDate>Fri, 05 Aug 2022 20:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-22299</strong></p>
  <p>A format string vulnerability [CWE-134] in the command line interpreter of FortiADC version 6.0.0 through 6.0.4, FortiADC version 6.1.0 through 6.1.5, FortiADC version 6.2.0 through 6.2.1, FortiProxy version 1.0.0 through 1.0.7, FortiProxy version 1.1.0 through 1.1.6, FortiProxy version 1.2.0 through 1.2.13, FortiProxy version 2.0.0 through 2.0.7, FortiProxy version 7.0.0 through 7.0.1, FortiOS v…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-134</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-22299">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-36173 – A heap-based buffer overflow in the firmware signature verification function of ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-36173</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-36173</guid>
    <pubDate>Wed, 08 Dec 2021 19:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-36173</strong></p>
  <p>A heap-based buffer overflow in the firmware signature verification function of FortiOS versions 7.0.1, 7.0.0, 6.4.0 through 6.4.6, 6.2.0 through 6.2.9, and 6.0.0 through 6.0.13 may allow an attacker to execute arbitrary code via specially crafted installation images.</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-36173">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-41024 – A relative path traversal [CWE-23] vulnerabiltiy in FortiOS versions 7.0.0 and 7...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-41024</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-41024</guid>
    <pubDate>Wed, 08 Dec 2021 13:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-41024</strong></p>
  <p>A relative path traversal [CWE-23] vulnerabiltiy in FortiOS versions 7.0.0 and 7.0.1 and FortiProxy verison 7.0.0 may allow an unauthenticated, unauthorized attacker to inject path traversal character sequences to disclose sensitive information of the server via the GET request of the login page.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-41024">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-26109 – An integer overflow or wraparound vulnerability in the memory allocator of SSLVP...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-26109</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-26109</guid>
    <pubDate>Wed, 08 Dec 2021 13:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-26109</strong></p>
  <p>An integer overflow or wraparound vulnerability in the memory allocator of SSLVPN in FortiOS before 7.0.1 may allow an unauthenticated attacker to corrupt control data on the heap via specifically crafted requests to SSLVPN, resulting in potentially arbitrary code execution.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-26109">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-26108 – A use of hard-coded cryptographic key vulnerability in the SSLVPN of FortiOS bef...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-26108</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-26108</guid>
    <pubDate>Wed, 08 Dec 2021 13:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-26108</strong></p>
  <p>A use of hard-coded cryptographic key vulnerability in the SSLVPN of FortiOS before 7.0.1 may allow an attacker to retrieve the key by reverse engineering.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-26108">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-26110 – An improper access control vulnerability [CWE-284] in FortiOS autod daemon 7.0.0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-26110</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-26110</guid>
    <pubDate>Wed, 08 Dec 2021 11:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-26110</strong></p>
  <p>An improper access control vulnerability [CWE-284] in FortiOS autod daemon 7.0.0, 6.4.6 and below, 6.2.9 and below, 6.0.12 and below and FortiProxy 2.0.1 and below, 1.2.9 and below may allow an authenticated low-privileged attacker to escalate their privileges to super_admin via a specific crafted configuration of fabric automation CLI script and auto-script features.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-26110">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-12812 – An improper authentication vulnerability in SSL VPN in FortiOS 6.4.0, 6.2.0 to 6...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-12812</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-12812</guid>
    <pubDate>Fri, 24 Jul 2020 23:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-12812</strong></p>
  <p>An improper authentication vulnerability in SSL VPN in FortiOS 6.4.0, 6.2.0 to 6.2.3, 6.0.9 and below may result in a user being able to log in successfully without being prompted for the second factor of authentication (FortiToken) if they changed the case of their username.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-178</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-12812">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-13371 – An external control of system vulnerability in FortiOS may allow an authenticate...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-13371</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-13371</guid>
    <pubDate>Thu, 02 Apr 2020 14:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-13371</strong></p>
  <p>An external control of system vulnerability in FortiOS may allow an authenticated, regular user to change the routing settings of the device via connecting to the ZebOS component.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-13371">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-15705 – An Improper Input Validation vulnerability in the SSL VPN portal of FortiOS vers...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-15705</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-15705</guid>
    <pubDate>Wed, 27 Nov 2019 21:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-15705</strong></p>
  <p>An Improper Input Validation vulnerability in the SSL VPN portal of FortiOS versions 6.2.1 and below, and 6.0.6 and below may allow an unauthenticated remote attacker to crash the SSL VPN service by sending a crafted POST request.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-15705">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-15703 – An Insufficient Entropy in PRNG vulnerability in Fortinet FortiOS 6.2.1, 6.2.0, ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-15703</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-15703</guid>
    <pubDate>Thu, 24 Oct 2019 14:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-15703</strong></p>
  <p>An Insufficient Entropy in PRNG vulnerability in Fortinet FortiOS 6.2.1, 6.2.0, 6.0.8 and below for device not enable hardware TRNG token and models not support builtin TRNG seed allows attacker to theoretically recover the long term ECDSA secret in a TLS client with a RSA handshake and mutual ECDSA authentication via the help of flush+reload side channel attacks in FortiGate VM models only.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-331</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-15703">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2018-13382 – An Improper Authorization vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-13382</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-13382</guid>
    <pubDate>Tue, 04 Jun 2019 21:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2018-13382</strong></p>
  <p>An Improper Authorization vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.8 and 5.4.1 to 5.4.10 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 to 1.1.6, 1.0.0 to 1.0.7 under SSL VPN web portal allows an unauthenticated attacker to modify the password of an SSL VPN web portal user via specially crafted HTTP requests</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-13382">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2018-13379 – An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal"...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-13379</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-13379</guid>
    <pubDate>Tue, 04 Jun 2019 21:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2018-13379</strong></p>
  <p>An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.3 to 5.6.7 and 5.4.6 to 5.4.12 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 to 1.1.6, 1.0.0 to 1.0.7 under SSL VPN web portal allows an unauthenticated attacker to download system files via special crafted HTTP resource requests.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-13379">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-17544 – A privilege escalation vulnerability in Fortinet FortiOS 6.0.0 to 6.0.6, 5.6.0 t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-17544</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-17544</guid>
    <pubDate>Tue, 09 Apr 2019 16:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-17544</strong></p>
  <p>A privilege escalation vulnerability in Fortinet FortiOS 6.0.0 to 6.0.6, 5.6.0 to 5.6.10, 5.4 and below allows admin users to elevate their profile to super_admin via restoring modified configurations.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-17544">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2018-1352 – A format string vulnerability in Fortinet FortiOS 5.6.0 allows attacker to execu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-1352</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-1352</guid>
    <pubDate>Fri, 08 Feb 2019 18:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2018-1352</strong></p>
  <p>A format string vulnerability in Fortinet FortiOS 5.6.0 allows attacker to execute unauthorized code or commands via the SSH username variable.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-134</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-1352">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-13376 – An uninitialized memory buffer leak exists in Fortinet FortiOS 5.6.1 to 5.6.3, 5...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-13376</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-13376</guid>
    <pubDate>Tue, 27 Nov 2018 15:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-13376</strong></p>
  <p>An uninitialized memory buffer leak exists in Fortinet FortiOS 5.6.1 to 5.6.3, 5.4.6 to 5.4.7, 5.2 all versions under web proxy's disclaimer response web pages, potentially causing sensitive data to be displayed in the HTTP response.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-13376">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-9185 – An information disclosure vulnerability in Fortinet FortiOS 6.0.0 and below vers...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-9185</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-9185</guid>
    <pubDate>Thu, 05 Jul 2018 13:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-9185</strong></p>
  <p>An information disclosure vulnerability in Fortinet FortiOS 6.0.0 and below versions reveals user's web portal login credentials in a Javascript file sent to client-side when pages bookmarked in web portal use the Single Sign-On feature.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-9185">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-7738 – An Information Disclosure vulnerability in Fortinet FortiOS 5.6.0 to 5.6.2, 5.4...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-7738</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-7738</guid>
    <pubDate>Wed, 13 Dec 2017 22:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-7738</strong></p>
  <p>An Information Disclosure vulnerability in Fortinet FortiOS 5.6.0 to 5.6.2, 5.4.0 to 5.4.5, 5.2 and below versions allow an admin user with super_admin privileges to view the current SSL VPN web portal session info which may contains user credentials through the fnsysctl CLI command.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-7738">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-3130 – An information disclosure vulnerability in Fortinet FortiOS 5.6.0, 5.4.4 and bel...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-3130</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-3130</guid>
    <pubDate>Thu, 10 Aug 2017 21:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-3130</strong></p>
  <p>An information disclosure vulnerability in Fortinet FortiOS 5.6.0, 5.4.4 and below versions allows attacker to get FortiOS version info by inspecting FortiOS IKE VendorID packets.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-3130">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2016-6909 – Buffer overflow in the Cookie parser in Fortinet FortiOS 4.x before 4.1.11, 4.2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-6909</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-6909</guid>
    <pubDate>Wed, 24 Aug 2016 16:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2016-6909</strong></p>
  <p>Buffer overflow in the Cookie parser in Fortinet FortiOS 4.x before 4.1.11, 4.2.x before 4.2.13, and 4.3.x before 4.3.9 and FortiSwitch before 3.4.3 allows remote attackers to execute arbitrary code via a crafted HTTP request, aka EGREGIOUSBLUNDER.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-6909">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2016-1909 – Fortinet FortiAnalyzer before 5.0.12 and 5.2.x before 5.2.5; FortiSwitch 3.3.x b...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-1909</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-1909</guid>
    <pubDate>Fri, 15 Jan 2016 20:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2016-1909</strong></p>
  <p>Fortinet FortiAnalyzer before 5.0.12 and 5.2.x before 5.2.5; FortiSwitch 3.3.x before 3.3.3; FortiCache 3.0.x before 3.0.8; and FortiOS 4.1.x before 4.1.11, 4.2.x before 4.2.16, 4.3.x before 4.3.17 and 5.0.x before 5.0.8 have a hardcoded passphrase for the Fortimanager_Access account, which allows remote attackers to obtain administrative access via an SSH session.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-1909">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2015-7361 – FortiOS 5.2.3, when configured to use High Availability (HA) and the dedicated m...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-7361</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-7361</guid>
    <pubDate>Thu, 15 Oct 2015 20:59:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2015-7361</strong></p>
  <p>FortiOS 5.2.3, when configured to use High Availability (HA) and the dedicated management interface is enabled, does not require authentication for access to the ZebOS shell on the HA dedicated management interface, which allows remote attackers to obtain shell access via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-7361">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2015-1452 – The Control and Provisioning of Wireless Access Points (CAPWAP) daemon in Fortin...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-1452</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-1452</guid>
    <pubDate>Mon, 02 Feb 2015 16:59:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2015-1452</strong></p>
  <p>The Control and Provisioning of Wireless Access Points (CAPWAP) daemon in Fortinet FortiOS 5.0 Patch 7 build 4457 allows remote attackers to cause a denial of service (locked CAPWAP Access Controller) via a large number of ClientHello DTLS messages.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-17</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-1452">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2014-2216 – The FortiManager protocol service in Fortinet FortiOS before 4.3.16 and 5.0.0 be...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-2216</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-2216</guid>
    <pubDate>Mon, 25 Aug 2014 14:55:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2014-2216</strong></p>
  <p>The FortiManager protocol service in Fortinet FortiOS before 4.3.16 and 5.0.0 before 5.0.8 on FortiGate devices allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted request.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-2216">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2005-3057 – The FTP component in FortiGate 2.8 running FortiOS 2.8MR10 and v3beta, and other...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2005-3057</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2005-3057</guid>
    <pubDate>Sat, 31 Dec 2005 05:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2005-3057</strong></p>
  <p>The FTP component in FortiGate 2.8 running FortiOS 2.8MR10 and v3beta, and other versions before 3.0 MR1, allows remote attackers to bypass the Fortinet FTP anti-virus engine by sending a STOR command and uploading a file before the FTP server response has been sent, as demonstrated using LFTP.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2005-3057">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2005-3058 – Interpretation conflict in Fortinet FortiGate 2.8, running FortiOS 2.8MR10 and v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2005-3058</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2005-3058</guid>
    <pubDate>Sat, 31 Dec 2005 05:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2005-3058</strong></p>
  <p>Interpretation conflict in Fortinet FortiGate 2.8, running FortiOS 2.8MR10 and v3beta, allows remote attackers to bypass the URL blocker via an (1) HTTP request terminated with a line feed (LF) and not carriage return line feed (CRLF) or (2) HTTP request with no Host field, which is still processed by most web servers without violating RFC2616.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2005-3058">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2005-4570 – The Internet Key Exchange version 1 (IKEv1) implementations in Fortinet FortiOS ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2005-4570</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2005-4570</guid>
    <pubDate>Thu, 29 Dec 2005 11:03:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2005-4570</strong></p>
  <p>The Internet Key Exchange version 1 (IKEv1) implementations in Fortinet FortiOS 2.50, 2.80 and 3.0, FortiClient 2.0,; and FortiManager 2.80 and 3.0 allow remote attackers to cause a denial of service (termination of a process that is automatically restarted) via IKE packets with invalid values of certain IPSec attributes, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1.  NOTE: due to th…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2005-4570">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2005-1837 – Fortinet firewall running FortiOS 2.x contains a hardcoded username with the pas...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2005-1837</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2005-1837</guid>
    <pubDate>Wed, 01 Jun 2005 04:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2005-1837</strong></p>
  <p>Fortinet firewall running FortiOS 2.x contains a hardcoded username with the password set to the serial number, which allows local users with console access to gain privileges.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2005-1837">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
