<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – FortiOS</title>
  <link>https://cvedaily.com/pages/tags/fortios.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/fortios.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – FortiOS</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:49 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2025-53844 – A out-of-bounds write vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, For...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-53844</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-53844</guid>
    <pubDate>Tue, 12 May 2026 18:16:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-53844</strong></p>
  <p>A out-of-bounds write vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11 allows attacker to execute unauthorized code or commands via specially crafted packets.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-53844">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-61624 – An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-61624</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-61624</guid>
    <pubDate>Tue, 14 Apr 2026 16:16:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-61624</strong></p>
  <p>An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') [CWE-22] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, FortiOS 7.4.0 through 7.4.9, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiPAM 1.7.0, FortiPAM 1.6 all versions, FortiPAM 1.5 all versions, FortiPAM 1.4 all versions, FortiPAM 1.3 all versions, FortiPAM 1.2 all versi…</p>
  <p><strong>CVSS:</strong> 6.0 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61624">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-53847 – A missing authentication for critical function vulnerability in Fortinet FortiOS...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-53847</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-53847</guid>
    <pubDate>Tue, 14 Apr 2026 16:16:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-53847</strong></p>
  <p>A missing authentication for critical function vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4 all versions, FortiOS 6.2.9 through 6.2.17 allows attacker to execute unauthorized code or commands via specially crafted packets.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-53847">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-22153 – An Authentication Bypass by Primary Weakness vulnerability [CWE-305] vulnerabili...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-22153</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-22153</guid>
    <pubDate>Tue, 10 Feb 2026 16:16:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-22153</strong></p>
  <p>An Authentication Bypass by Primary Weakness vulnerability [CWE-305] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4 may allow an unauthenticated attacker to bypass LDAP authentication of Agentless VPN or FSSO policy, when the remote LDAP server is configured in a specific way.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-305</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-22153">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-68686 – An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-68686</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-68686</guid>
    <pubDate>Tue, 10 Feb 2026 16:16:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-68686</strong></p>
  <p>An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1, FortiOS 7.4.0 through 7.4.6, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism observed in some post-exploit case…</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-68686">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-64157 – A use of externally-controlled format string vulnerability in Fortinet FortiOS 7...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-64157</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-64157</guid>
    <pubDate>Tue, 10 Feb 2026 16:16:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-64157</strong></p>
  <p>A use of externally-controlled format string vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, FortiOS 7.4.0 through 7.4.9, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0 all versions allows an authenticated admin to execute unauthorized code or commands via specifically crafted configuration.</p>
  <p><strong>CVSS:</strong> 6.7 · <strong>CWE:</strong> CWE-134</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-64157">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-62439 – An Improper Verification of Source of a Communication Channel vulnerability [CWE...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-62439</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-62439</guid>
    <pubDate>Tue, 10 Feb 2026 16:16:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-62439</strong></p>
  <p>An Improper Verification of Source of a Communication Channel vulnerability [CWE-940] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, FortiOS 7.4.0 through 7.4.9, FortiOS 7.2 all versions, FortiOS 7.0 all versions may allow an authenticated user with knowledge of FSSO policy configurations to gain unauthorized access to protected network resources via crafted requests.</p>
  <p><strong>CVSS:</strong> 4.2 · <strong>CWE:</strong> CWE-940</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-62439">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-55018 – An inconsistent interpretation of http requests ('http request smuggling') vulne...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-55018</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-55018</guid>
    <pubDate>Tue, 10 Feb 2026 16:16:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-55018</strong></p>
  <p>An inconsistent interpretation of http requests ('http request smuggling') vulnerability in Fortinet FortiOS 7.6.0, FortiOS 7.4.0 through 7.4.9, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4.3 through 6.4.16 may allow  an unauthenticated attacker to smuggle an unlogged http request through the firewall policies via a specially crafted header</p>
  <p><strong>CVSS:</strong> 5.8 · <strong>CWE:</strong> CWE-444</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-55018">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-25815 – Fortinet FortiOS through 7.6.6 allows attackers to decrypt LDAP credentials stor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-25815</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-25815</guid>
    <pubDate>Thu, 05 Feb 2026 22:15:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-25815</strong></p>
  <p>Fortinet FortiOS through 7.6.6 allows attackers to decrypt LDAP credentials stored in device configuration files, as exploited in the wild from 2025-12-16 through 2026 (by default, the encryption key is the same across all customers' installations). NOTE: the Supplier's position is that the instance of CWE-1394 is not a vulnerability because customers "are supposed to enable" a non-default option…</p>
  <p><strong>CVSS:</strong> 3.2 · <strong>CWE:</strong> CWE-1394</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25815">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-24858 – An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24858</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24858</guid>
    <pubDate>Tue, 27 Jan 2026 20:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-24858</strong></p>
  <p>An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.5, FortiAnalyzer 7.4.0 through 7.4.9, FortiAnalyzer 7.2.0 through 7.2.11, FortiAnalyzer 7.0.0 through 7.0.15, FortiManager 7.6.0 through 7.6.5, FortiManager 7.4.0 through 7.4.9, FortiManager 7.2.0 through 7.2.11, FortiManager 7.0.0 through 7.0.15, FortiOS 7…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-288</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24858">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-25249 – A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-25249</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-25249</guid>
    <pubDate>Tue, 13 Jan 2026 17:15:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-25249</strong></p>
  <p>A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4 all versions, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7.0.0 through 7.0.5 allows attacker to execute unauthorized code or commands via specially crafted packets</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-25249">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-40593 – A key management errors vulnerability in Fortinet FortiAnalyzer 7.4.0 through 7...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-40593</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-40593</guid>
    <pubDate>Thu, 11 Dec 2025 15:15:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-40593</strong></p>
  <p>A key management errors vulnerability in Fortinet FortiAnalyzer 7.4.0 through 7.4.2, FortiAnalyzer 7.2.0 through 7.2.5, FortiAnalyzer 7.0 all versions, FortiAnalyzer 6.4 all versions, FortiManager 7.4.0 through 7.4.2, FortiManager 7.2.0 through 7.2.5, FortiManager 7.0 all versions, FortiManager 6.4 all versions, FortiOS 7.6.0, FortiOS 7.4.4, FortiOS 7.2.7, FortiOS 7.0.14, FortiPortal 6.0 all vers…</p>
  <p><strong>CVSS:</strong> 6.0 · <strong>CWE:</strong> CWE-320</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-40593">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-62631 – An insufficient session expiration vulnerability [CWE-613] vulnerability in Fort...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-62631</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-62631</guid>
    <pubDate>Tue, 09 Dec 2025 18:16:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-62631</strong></p>
  <p>An insufficient session expiration vulnerability [CWE-613] vulnerability in Fortinet FortiOS 7.4.0, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions allows attacker to maintain access to network resources via an active SSLVPN session not terminated after a user's password change under particular conditions outside of the attacker's control</p>
  <p><strong>CVSS:</strong> 5.6 · <strong>CWE:</strong> CWE-613</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-62631">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-59718 – A improper verification of cryptographic signature vulnerability in Fortinet For...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-59718</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-59718</guid>
    <pubDate>Tue, 09 Dec 2025 18:15:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-59718</strong></p>
  <p>A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiProxy 7.6.0 through 7.6.3, FortiProxy 7.4.0 through 7.4.10, FortiProxy 7.2.0 through 7.2.14, FortiProxy 7.0.0 through 7.0.21, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7.0.0 through…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-347</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-59718">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-47570 – An insertion of sensitive information into log file vulnerability [CWE-532] in F...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-47570</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-47570</guid>
    <pubDate>Tue, 09 Dec 2025 18:15:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-47570</strong></p>
  <p>An insertion of sensitive information into log file vulnerability [CWE-532] in FortiOS 7.4.0 through 7.4.3, 7.2.0 through 7.2.7, 7.0 all versions; FortiProxy 7.4.0 through 7.4.3, 7.2.0 through 7.2.11; FortiPAM 1.4 all versions, 1.3 all versions, 1.2 all versions, 1.1 all versions, 1.0 all versions and FortiSRA 1.4 all versions may allow a read-only administrator to retrieve API tokens of other ad…</p>
  <p><strong>CVSS:</strong> 6.6 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-47570">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-58413 – A stack-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-58413</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-58413</guid>
    <pubDate>Tue, 18 Nov 2025 17:16:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-58413</strong></p>
  <p>A stack-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiOS 6.2 all versions, FortiOS 6.0 all versions, FortiSASE 25.3.b allows attacker to execute unauthorized code or commands via specially crafted packets</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58413">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-54821 – An Improper Privilege Management vulnerability [CWE-269] vulnerability in Fortin...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-54821</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-54821</guid>
    <pubDate>Tue, 18 Nov 2025 17:16:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-54821</strong></p>
  <p>An Improper Privilege Management vulnerability [CWE-269] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4 all versions, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiPAM 1.6.0, FortiPAM 1.5 all versions, FortiPAM 1.4 all versions, FortiPAM 1.3 all versions, FortiPAM 1.2 all versions, FortiPAM 1.1 all versions, FortiPAM 1.0 all versions, Forti…</p>
  <p><strong>CVSS:</strong> 1.9 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-54821">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-53843 – A stack-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-53843</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-53843</guid>
    <pubDate>Tue, 18 Nov 2025 17:16:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-53843</strong></p>
  <p>A stack-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions allows attacker to execute unauthorized code or commands via specially crafted packets</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-53843">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-58903 – An Unchecked Return Value vulnerability [CWE-252] in Fortinet FortiOS version 7...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-58903</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-58903</guid>
    <pubDate>Tue, 14 Oct 2025 16:15:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-58903</strong></p>
  <p>An Unchecked Return Value vulnerability [CWE-252] in Fortinet FortiOS version 7.6.0 through 7.6.3 and before 7.4.8 API allows an authenticated user to cause a  Null Pointer Dereference, crashing the http daemon via a specialy crafted request.</p>
  <p><strong>CVSS:</strong> 2.7 · <strong>CWE:</strong> CWE-252</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58903">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-58325 – An Incorrect Provision of Specified Functionality vulnerability [CWE-684] in For...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-58325</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-58325</guid>
    <pubDate>Tue, 14 Oct 2025 16:15:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-58325</strong></p>
  <p>An Incorrect Provision of Specified Functionality vulnerability [CWE-684] in FortiOS 7.6.0, 7.4.0 through 7.4.5, 7.2.5 through 7.2.10, 7.0.0 through 7.0.15, 6.4 all versions may allow a local authenticated attacker to execute system commands via crafted CLI commands.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-684</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58325">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-57740 – An Heap-based Buffer Overflow vulnerability [CWE-122] in FortiOS version 7.6.2 a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-57740</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-57740</guid>
    <pubDate>Tue, 14 Oct 2025 16:15:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-57740</strong></p>
  <p>An Heap-based Buffer Overflow vulnerability [CWE-122] in FortiOS version 7.6.2 and below, version 7.4.7 and below, version 7.2.10 and below, 7.0 all versions, 6.4 all versions; FortiPAM version 1.5.0, version 1.4.2 and below, 1.3 all versions, 1.2 all versions, 1.1 all versions, 1.0 all versions and FortiProxy version 7.6.2 and below, version 7.4.3 and below, 7.2 all versions, 7.0 all versions RD…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-57740">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-54822 – An improper authorization vulnerability [CWE-285] vulnerability in Fortinet Fort...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-54822</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-54822</guid>
    <pubDate>Tue, 14 Oct 2025 16:15:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-54822</strong></p>
  <p>An improper authorization vulnerability [CWE-285] vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2.0 through 7.2.8, FortiOS 7.0.0 through 7.0.11, FortiProxy 7.4.0 through 7.4.8, FortiProxy 7.2 all versions, FortiProxy 7.0 all versions, FortiProxy 2.0 all versions allows an authenticated attacker to access static files of others VDOMs via crafted HTTP or HTTPS requests.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-285</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-54822">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-47890 – An URL Redirection to Untrusted Site vulnerabilities [CWE-601] vulnerability in ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-47890</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-47890</guid>
    <pubDate>Tue, 14 Oct 2025 16:15:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-47890</strong></p>
  <p>An URL Redirection to Untrusted Site vulnerabilities [CWE-601] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiProxy 7.6.0 through 7.6.3, FortiProxy 7.4 all versions, FortiProxy 7.2 all versions, FortiProxy 7.0 all versions, FortiSASE 25.2.a may allow an unauthenticated attacker…</p>
  <p><strong>CVSS:</strong> 2.6 · <strong>CWE:</strong> CWE-601</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-47890">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-31514 – An Insertion of Sensitive Information into Log File vulnerability [CWE-532] in F...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-31514</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-31514</guid>
    <pubDate>Tue, 14 Oct 2025 16:15:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-31514</strong></p>
  <p>An Insertion of Sensitive Information into Log File vulnerability [CWE-532] in FortiOS 7.6.0 through 7.6.3, 7.4 all versions, 7.2 all versions, 7.0 all versions, 6.4 all versions may allow an attacker with at least read-only privileges to retrieve sensitive 2FA-related information via observing logs or via diagnose command.</p>
  <p><strong>CVSS:</strong> 2.7 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-31514">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-31366 – An Improper Neutralization of Input During Web Page Generation vulnerability [CW...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-31366</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-31366</guid>
    <pubDate>Tue, 14 Oct 2025 16:15:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-31366</strong></p>
  <p>An Improper Neutralization of Input During Web Page Generation vulnerability [CWE-79] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiProxy 7.6.0 through 7.6.3, FortiProxy 7.4 all versions, FortiProxy 7.2 all versions, FortiProxy 7.0 all versions, FortiSASE 25.2.a may allow an un…</p>
  <p><strong>CVSS:</strong> 4.7 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-31366">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-25255 – An Improperly Implemented Security Check for Standard vulnerability [CWE-358] vu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-25255</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-25255</guid>
    <pubDate>Tue, 14 Oct 2025 16:15:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-25255</strong></p>
  <p>An Improperly Implemented Security Check for Standard vulnerability [CWE-358] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiProxy 7.6.0 through 7.6.3, FortiProxy 7.4.0 through 7.4.11, FortiProxy 7.2 all versions, FortiProxy 7.0.1 through 7.0.22 may allow an unauthenticated proxy user to bypass the domain fronting protection feature via crafted HTTP requests.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-358</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-25255">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-25253 – An Improper Validation of Certificate with Host Mismatch vulnerability [CWE-297]...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-25253</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-25253</guid>
    <pubDate>Tue, 14 Oct 2025 16:15:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-25253</strong></p>
  <p>An Improper Validation of Certificate with Host Mismatch vulnerability [CWE-297] in FortiProxy version 7.6.1 and below, version 7.4.8 and below, 7.2 all versions, 7.0 all versions and FortiOS version 7.6.2 and below, version 7.4.8 and below, 7.2 all versions, 7.0 all versions ZTNA proxy may allow an unauthenticated attacker in a man-in-the middle position to intercept and tamper with connections…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-297</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-25253">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-25252 – An Insufficient Session Expiration vulnerability [CWE-613] in FortiOS SSL VPN 7...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-25252</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-25252</guid>
    <pubDate>Tue, 14 Oct 2025 16:15:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-25252</strong></p>
  <p>An Insufficient Session Expiration vulnerability [CWE-613] in FortiOS SSL VPN 7.6.0 through 7.6.2, 7.4.0 through 7.4.6, 7.2.0 through 7.2.10, 7.0.0 through 7.0.16, 6.4 all versions may allow a remote attacker (e.g. a former admin whose account was removed and whose session was terminated) in possession of the SAML record of a user session to access or re-open that session via re-use of SAML recor…</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-613</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-25252">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-22258 – A heap-based buffer overflow in Fortinet FortiSRA 1.5.0, 1.4.0 through 1.4.2, Fo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-22258</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-22258</guid>
    <pubDate>Tue, 14 Oct 2025 16:15:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-22258</strong></p>
  <p>A heap-based buffer overflow in Fortinet FortiSRA 1.5.0, 1.4.0 through 1.4.2, FortiPAM 1.5.0, 1.4.0 through 1.4.2, 1.3.0 through 1.3.1, 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiProxy 7.6.0 through 7.6.1, 7.4.0 through 7.4.7, FortiOS 7.6.0 through 7.6.2, 7.4.0 through 7.4.6, 7.2.0 through 7.2.10, 7.0.2 through 7.0.16, FortiSwitchManager 7.2.1 through 7.2.5 allows attackers to escalate…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-22258">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-50571 – A heap-based buffer overflow vulnerability in Fortinet FortiAnalyzer 7.6.0 throu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-50571</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-50571</guid>
    <pubDate>Tue, 14 Oct 2025 16:15:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-50571</strong></p>
  <p>A heap-based buffer overflow vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.2, FortiAnalyzer 7.4.0 through 7.4.5, FortiAnalyzer 7.2.0 through 7.2.9, FortiAnalyzer 7.0.0 through 7.0.13, FortiAnalyzer 6.4 all versions, FortiAnalyzer 6.2 all versions, FortiAnalyzer 6.0 all versions, FortiAnalyzer Cloud 7.4.1 through 7.4.5, FortiAnalyzer Cloud 7.2.1 through 7.2.9, FortiAnalyzer Cloud 7.0.1…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-50571">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-47569 – A insertion of sensitive information into sent data vulnerability in Fortinet Fo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-47569</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-47569</guid>
    <pubDate>Tue, 14 Oct 2025 16:15:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-47569</strong></p>
  <p>A insertion of sensitive information into sent data vulnerability in Fortinet FortiMail 7.4.0 through 7.4.2, FortiMail 7.2.0 through 7.2.6, FortiMail 7.0 all versions, FortiManager 7.6.0 through 7.6.1, FortiManager 7.4.1 through 7.4.3, FortiManager Cloud 7.4.1 through 7.4.3, FortiNDR 7.6.0 through 7.6.1, FortiNDR 7.4.0 through 7.4.8, FortiNDR 7.2 all versions, FortiNDR 7.1 all versions, FortiNDR…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-201</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-47569">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-26008 – An improper check or handling of exceptional conditions vulnerability [CWE-703] ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-26008</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-26008</guid>
    <pubDate>Tue, 14 Oct 2025 16:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-26008</strong></p>
  <p>An improper check or handling of exceptional conditions vulnerability [CWE-703] in FortiOS version 7.4.0 through 7.4.3 and before 7.2.7, FortiProxy version 7.4.0 through 7.4.3 and before 7.2.9, FortiPAM before 1.2.0 and FortiSwitchManager version 7.2.0 through 7.2.3 and version 7.0.0 through 7.0.3 fgfm daemon may allow an unauthenticated attacker to repeatedly reset the fgfm connection via crafte…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-754</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-26008">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-46718 – A stack-based buffer overflow in Fortinet FortiOS version 7.4.0 through 7.4.1 an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-46718</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-46718</guid>
    <pubDate>Tue, 14 Oct 2025 16:15:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-46718</strong></p>
  <p>A stack-based buffer overflow in Fortinet FortiOS version 7.4.0 through 7.4.1 and 7.2.0 through 7.2.7 and 7.0.0 through 7.0.12 and 6.4.6 through 6.4.15 and 6.2.9 through 6.2.16 and 6.0.13 through 6.0.18 allows attacker to execute unauthorized code or commands via specially crafted CLI commands.</p>
  <p><strong>CVSS:</strong> 6.7 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-46718">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-22862 – An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-22862</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-22862</guid>
    <pubDate>Thu, 02 Oct 2025 13:15:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-22862</strong></p>
  <p>An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] in FortiOS 7.4.0 through 7.4.7, 7.2.0 through 7.2.11, 7.0.6 and above; and FortiProxy 7.6.0 through 7.6.2, 7.4.0 through 7.4.8, 7.2 all versions, 7.0.5 and above may allow an authenticated attacker to elevate their privileges via triggering a malicious Webhook action in the Automation Stitch component.</p>
  <p><strong>CVSS:</strong> 6.7 · <strong>CWE:</strong> CWE-288</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-22862">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-53744 – An incorrect privilege assignment vulnerability [CWE-266] in FortiOS Security Fa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-53744</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-53744</guid>
    <pubDate>Tue, 12 Aug 2025 19:15:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-53744</strong></p>
  <p>An incorrect privilege assignment vulnerability [CWE-266] in FortiOS Security Fabric version 7.6.0 through 7.6.2, 7.4.0 through 7.4.7, 7.2 all versions, 7.0 all versions, 6.4 all versions, may allow a remote authenticated attacker with high privileges to escalate their privileges to super-admin via registering the device to a malicious FortiManager.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-266</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-53744">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-25248 – An Integer Overflow or Wraparound vulnerability [CWE-190] in FortiOS version 7.6...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-25248</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-25248</guid>
    <pubDate>Tue, 12 Aug 2025 19:15:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-25248</strong></p>
  <p>An Integer Overflow or Wraparound vulnerability [CWE-190] in FortiOS version 7.6.2 and below, version 7.4.7 and below, version 7.2.10 and below, 7.2 all versions, 6.4 all versions, FortiProxy version 7.6.2 and below, version 7.4.3 and below, 7.2 all versions, 7.0 all versions, 2.0 all versions and FortiPAM version 1.5.0, version 1.4.2 and below, 1.3 all versions, 1.2 all versions, 1.1 all version…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-25248">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-26009 – An authentication bypass using an alternate path or channel [CWE-288] vulnerabil...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-26009</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-26009</guid>
    <pubDate>Tue, 12 Aug 2025 19:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-26009</strong></p>
  <p>An authentication bypass using an alternate path or channel [CWE-288] vulnerability in Fortinet FortiOS 6.4.0 through 6.4.15, FortiOS 6.2.0 through 6.2.16, FortiOS 6.0 all versions, FortiPAM 1.2.0, FortiPAM 1.1.0 through 1.1.2, FortiPAM 1.0.0 through 1.0.3, FortiProxy 7.4.0 through 7.4.2, FortiProxy 7.2.0 through 7.2.8, FortiProxy 7.0.0 through 7.0.15, FortiSwitchManager 7.2.0 through 7.2.3, Fort…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-288</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-26009">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-45584 – A double free vulnerability [CWE-415] vulnerability in Fortinet FortiOS 7.4.0, F...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-45584</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-45584</guid>
    <pubDate>Tue, 12 Aug 2025 19:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-45584</strong></p>
  <p>A double free vulnerability [CWE-415] vulnerability in Fortinet FortiOS 7.4.0, FortiOS 7.2.0 through 7.2.5, FortiOS 7.0.0 through 7.0.12, FortiOS 6.4 all versions, FortiPAM 1.1 all versions, FortiPAM 1.0 all versions, FortiProxy 7.4.0 through 7.4.1, FortiProxy 7.2.0 through 7.2.7, FortiProxy 7.0.0 through 7.0.13 allows a privileged attacker to execute code or commands via crafted HTTP or HTTPs re…</p>
  <p><strong>CVSS:</strong> 6.6 · <strong>CWE:</strong> CWE-415</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-45584">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-24477 – A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-24477</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-24477</guid>
    <pubDate>Tue, 15 Jul 2025 09:15:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-24477</strong></p>
  <p>A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.2, FortiOS 7.4.0 through 7.4.7, FortiOS 7.2.4 through 7.2.12 allows an attacker to escalate its privileges via a specially crafted CLI command</p>
  <p><strong>CVSS:</strong> 4.2 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-24477">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-55599 – An Improperly Implemented Security Check for Standard vulnerability [CWE-358] in...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-55599</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-55599</guid>
    <pubDate>Tue, 08 Jul 2025 15:15:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-55599</strong></p>
  <p>An Improperly Implemented Security Check for Standard vulnerability [CWE-358] in FortiOS version 7.6.0, version 7.4.7 and below, 7.0 all versions, 6.4 all versions and FortiProxy version 7.6.1 and below, version 7.4.8 and below, 7.2 all versions, 7.0 all versions may allow a remote unauthenticated user to bypass the DNS filter via Apple devices.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-358</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-55599">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-52965 – A missing critical step in authentication vulnerability [CWE-304] in Fortinet Fo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-52965</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-52965</guid>
    <pubDate>Tue, 08 Jul 2025 15:15:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-52965</strong></p>
  <p>A missing critical step in authentication vulnerability [CWE-304] in Fortinet FortiOS version 7.6.0 through 7.6.1, 7.4.0 through 7.4.5, 7.2.0 through 7.2.10, and before 7.0.16 & FortiProxy version 7.6.0 through 7.6.1, 7.4.0 through 7.4.8, 7.2.0 through 7.2.13 and before 7.0.20 allows an API-user using api-key + PKI user certificate authentication to login even if the certificate is invalid.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-304</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-52965">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-25250 – An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-25250</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-25250</guid>
    <pubDate>Tue, 10 Jun 2025 17:21:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-25250</strong></p>
  <p>An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] in FortiOS version 7.6.0, version 7.4.7 and below, 7.2 all versions, 7.0 all versions, 6.4 all versions SSL-VPN web-mode may allow an authenticated user to access full SSL-VPN settings via crafted URL.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-25250">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-24471 – An Improper Certificate Validation vulnerability [CWE-295] in FortiOS version 7...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-24471</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-24471</guid>
    <pubDate>Tue, 10 Jun 2025 17:21:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-24471</strong></p>
  <p>An Improper Certificate Validation vulnerability [CWE-295] in FortiOS version 7.6.1 and below, version 7.4.7 and below may allow an EAP verified remote user to connect from FortiClient via revoked certificate.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-24471">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-22254 – An Improper Privilege Management vulnerability [CWE-269] vulnerability in Fortin...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-22254</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-22254</guid>
    <pubDate>Tue, 10 Jun 2025 17:21:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-22254</strong></p>
  <p>An Improper Privilege Management vulnerability [CWE-269] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1, FortiOS 7.4.0 through 7.4.6, FortiOS 7.2.0 through 7.2.10, FortiOS 7.0.0 through 7.0.16, FortiOS 6.4.0 through 6.4.15, FortiProxy 7.6.0 through 7.6.1, FortiProxy 7.4.0 through 7.4.7, FortiWeb 7.6.0 through 7.6.1, FortiWeb 7.4.0 through 7.4.6 allows an authenticated attacker with at leas…</p>
  <p><strong>CVSS:</strong> 6.6 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-22254">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-22251 – An improper restriction of communication channel to intended endpoints vulnerabi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-22251</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-22251</guid>
    <pubDate>Tue, 10 Jun 2025 17:21:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-22251</strong></p>
  <p>An improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in FortiOS 7.6.0, 7.4.0 through 7.4.5, 7.2 all versions, 7.0 all versions, 6.4 all versions may allow an unauthenticated attacker to inject unauthorized sessions via crafted FGSP session synchronization packets.</p>
  <p><strong>CVSS:</strong> 3.1 · <strong>CWE:</strong> CWE-923</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-22251">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-50568 – A channel accessible by non-endpoint vulnerability [CWE-300] in Fortinet FortiOS...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-50568</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-50568</guid>
    <pubDate>Tue, 10 Jun 2025 17:19:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-50568</strong></p>
  <p>A channel accessible by non-endpoint vulnerability [CWE-300] in Fortinet FortiOS version 7.4.0 through 7.4.3, 7.2.0 through 7.2.7 and before 7.0.14 & FortiProxy version 7.4.0 through 7.4.3, 7.2.0 through 7.2.9 and before 7.0.16 allows an unauthenticated attacker with the knowledge of device specific data to spoof the identity of a downstream device of the security fabric via crafted TCP requests.</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-300</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-50568">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-50562 – An Insufficient Session Expiration vulnerability [CWE-613] in FortiOS SSL-VPN ve...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-50562</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-50562</guid>
    <pubDate>Tue, 10 Jun 2025 17:19:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-50562</strong></p>
  <p>An Insufficient Session Expiration vulnerability [CWE-613] in FortiOS SSL-VPN version 7.6.0, version 7.4.6 and below, version 7.2.10 and below, 7.0 all versions, 6.4 all versions may allow an attacker in possession of a cookie used to log in the SSL-VPN portal to log in again, although the session has expired or was logged out.</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-613</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-50562">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2023-29184 – An incomplete cleanup vulnerability [CWE-459] in FortiOS 7.2 all versions and be...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-29184</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-29184</guid>
    <pubDate>Tue, 10 Jun 2025 17:17:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2023-29184</strong></p>
  <p>An incomplete cleanup vulnerability [CWE-459] in FortiOS 7.2 all versions and before  & FortiProxy version 7.2.0 through 7.2.2 and before 7.0.8 allows a VDOM privileged attacker to add SSH key files on the system silently via crafted CLI requests.</p>
  <p><strong>CVSS:</strong> 3.2 · <strong>CWE:</strong> CWE-459</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-29184">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-47295 – A buffer over-read in Fortinet FortiOS versions 7.4.0 through 7.4.3, versions 7...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-47295</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-47295</guid>
    <pubDate>Wed, 28 May 2025 08:15:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-47295</strong></p>
  <p>A buffer over-read in Fortinet FortiOS versions 7.4.0 through 7.4.3, versions 7.2.0 through 7.2.7, and versions 7.0.0 through 7.0.14 may allow a remote unauthenticated attacker to crash the FGFM daemon via a specially crafted request, under rare conditions that are outside of the attacker's control.</p>
  <p><strong>CVSS:</strong> 3.7 · <strong>CWE:</strong> CWE-126</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-47295">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-47294 – A integer overflow or wraparound in Fortinet FortiOS versions 7.2.0 through 7.2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-47294</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-47294</guid>
    <pubDate>Wed, 28 May 2025 08:15:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-47294</strong></p>
  <p>A integer overflow or wraparound in Fortinet FortiOS versions 7.2.0 through 7.2.7, versions 7.0.0 through 7.0.14 may allow a remote unauthenticated attacker to crash the csfd daemon via a specially crafted request.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-47294">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-22252 – A missing authentication for critical function in Fortinet FortiProxy versions 7...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-22252</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-22252</guid>
    <pubDate>Wed, 28 May 2025 08:15:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-22252</strong></p>
  <p>A missing authentication for critical function in Fortinet FortiProxy versions 7.6.0 through 7.6.1, FortiSwitchManager version 7.2.5, and FortiOS versions 7.4.4 through 7.4.6 and version 7.6.0 may allow an attacker with knowledge of an existing admin account to access the device as a valid admin via an authentication bypass.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-22252">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2024-50565 – A improper restriction of communication channel to intended endpoints vulnerabil...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-50565</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-50565</guid>
    <pubDate>Tue, 08 Apr 2025 14:15:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2024-50565</strong></p>
  <p>A improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in Fortinet FortiOS version 7.4.0 through 7.4.3, 7.2.0 through 7.2.7, 7.0.0 through 7.0.14, 6.4.0 through 6.4.15 and 6.2.0 through 6.2.16, Fortinet FortiProxy version 7.4.0 through 7.4.2, 7.2.0 through 7.2.9, 7.0.0 through 7.0.15 and 2.0.0 through 2.0.14, Fortinet FortiManager version 7.4.0 through 7.4.2…</p>
  <p><strong>CVSS:</strong> 3.1 · <strong>CWE:</strong> CWE-300</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-50565">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2024-32122 – A storing passwords in a recoverable format in Fortinet FortiOS 7.4.0 through 7...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-32122</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-32122</guid>
    <pubDate>Tue, 08 Apr 2025 14:15:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2024-32122</strong></p>
  <p>A storing passwords in a recoverable format in Fortinet FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions allows attacker to information disclosure via modification of LDAP server IP to point to a malicious server.</p>
  <p><strong>CVSS:</strong> 2.3 · <strong>CWE:</strong> CWE-257</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-32122">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-26013 – A improper restriction of communication channel to intended endpoints vulnerabil...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-26013</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-26013</guid>
    <pubDate>Tue, 08 Apr 2025 14:15:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-26013</strong></p>
  <p>A improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in Fortinet FortiOS version 7.4.0 through 7.4.4, 7.2.0 through 7.2.8, 7.0.0 through 7.0.15, 6.4.0 through 6.4.15 and before 6.2.16, Fortinet FortiProxy version 7.4.0 through 7.4.2, 7.2.0 through 7.2.9 and before 7.0.15, Fortinet FortiManager version 7.4.0 through 7.4.2, 7.2.0 through 7.2.4, 7.0.0 through…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-923</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-26013">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-25610 – A buffer underwrite ('buffer underflow') vulnerability in the administrative int...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-25610</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-25610</guid>
    <pubDate>Mon, 24 Mar 2025 16:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-25610</strong></p>
  <p>A buffer underwrite ('buffer underflow') vulnerability in the administrative interface of Fortinet FortiOS version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.6, version 6.4.0 through 6.4.11 and version 6.2.12 and below, FortiProxy version 7.2.0 through 7.2.2, version 7.0.0 through 7.0.8, version 2.0.12 and below and FortiOS-6K7K version 7.0.5, version 6.4.0 through 6.4.10 and version 6.2.0 th…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-124</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-25610">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-16151 – An improper neutralization of input during web page generation vulnerability [CW...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-16151</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-16151</guid>
    <pubDate>Fri, 21 Mar 2025 16:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-16151</strong></p>
  <p>An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiOS 6.4.1 and below, 6.2.9 and below may allow a remote unauthenticated attacker to either redirect users to malicious websites via a crafted "Host" header or to execute JavaScript code in the victim's browser context. This happens when the FortiGate has web filtering and category override enabled/config…</p>
  <p><strong>CVSS:</strong> 4.7 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-16151">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-9295 – FortiOS 6.2 running AV engine version 6.00142 and below, FortiOS 6.4 running AV ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-9295</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-9295</guid>
    <pubDate>Mon, 17 Mar 2025 14:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-9295</strong></p>
  <p>FortiOS 6.2 running AV engine version 6.00142 and below, FortiOS 6.4 running AV engine version 6.00144 and below and FortiClient 6.2 running AV engine version 6.00137 and below may not immediately detect certain types of malformed or non-standard RAR archives, potentially containing malicious files. Based on the samples provided, FortiClient will detect the malicious files upon trying extraction…</p>
  <p><strong>CVSS:</strong> 4.7 · <strong>CWE:</strong> CWE-358</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-9295">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-29010 – An exposure of sensitive information to an unauthorized actor vulnerability in F...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-29010</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-29010</guid>
    <pubDate>Mon, 17 Mar 2025 14:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-29010</strong></p>
  <p>An exposure of sensitive information to an unauthorized actor vulnerability in FortiOS version 6.2.4 and below, version 6.0.10 and belowmay allow remote authenticated actors to read the SSL VPN events log entries of users in other VDOMs by  executing "get vpn ssl monitor" from the CLI. The sensitive data includes usernames, user groups, and IP address.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-29010">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-15706 – An improper neutralization of input during web page generation in the SSL VPN po...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-15706</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-15706</guid>
    <pubDate>Mon, 17 Mar 2025 14:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-15706</strong></p>
  <p>An improper neutralization of input during web page generation in the SSL VPN portal of FortiProxy version 2.0.0, version 1.2.9 and below and FortiOS version 6.2.1 and below, version 6.0.8 and below, version 5.6.12 may allow a remote authenticated attacker to perform a stored cross site scripting attack (XSS).</p>
  <p><strong>CVSS:</strong> 4.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-15706">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-48785 – An improper certificate validation vulnerability [CWE-295] in FortiNAC-F version...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-48785</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-48785</guid>
    <pubDate>Fri, 14 Mar 2025 16:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-48785</strong></p>
  <p>An improper certificate validation vulnerability [CWE-295] in FortiNAC-F version 7.2.4 and below may allow a remote and unauthenticated attacker to perform a Man-in-the-Middle attack on the HTTPS communication channel between the FortiOS device, an inventory, and FortiNAC-F.</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-48785">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-26006 – An improper neutralization of input during web page Generation vulnerability [CW...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-26006</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-26006</guid>
    <pubDate>Fri, 14 Mar 2025 10:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-26006</strong></p>
  <p>An improper neutralization of input during web page Generation vulnerability [CWE-79] in FortiOS version 7.4.3 and below, version 7.2.7 and below, version 7.0.13 and below and FortiProxy version 7.4.3 and below, version 7.2.9 and below, version 7.0.16 and below web SSL VPN UI may allow a remote unauthenticated attacker to perform a Cross-Site Scripting attack via a malicious samba server.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-26006">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-45324 – A use of externally-controlled format string vulnerability [CWE-134] in FortiOS ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-45324</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-45324</guid>
    <pubDate>Tue, 11 Mar 2025 15:15:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-45324</strong></p>
  <p>A use of externally-controlled format string vulnerability [CWE-134] in FortiOS version 7.4.0 through 7.4.4, version 7.2.0 through 7.2.9, version 7.0.0 through 7.0.15 and before 6.4.15, FortiProxy version 7.4.0 through 7.4.6, version 7.2.0 through 7.2.12 and before 7.0.19, FortiPAM version 1.4.0 through 1.4.2 and before 1.3.1, FortiSRA version 1.4.0 through 1.4.2 and before 1.3.1 and FortiWeb ver…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-134</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-45324">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-24472 – An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-24472</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-24472</guid>
    <pubDate>Tue, 11 Feb 2025 17:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-24472</strong></p>
  <p>An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS 7.0.0 through 7.0.16 and FortiProxy 7.2.0 through 7.2.12, 7.0.0 through 7.0.19 may allow a remote unauthenticated attacker with prior knowledge of upstream and downstream devices serial numbers to gain super-admin privileges on the downstream device, if the Security Fabric is enabled, via crafted…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-288</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-24472">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-40591 – An incorrect privilege assignment vulnerability [CWE-266] in Fortinet FortiOS ve...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-40591</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-40591</guid>
    <pubDate>Tue, 11 Feb 2025 17:15:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-40591</strong></p>
  <p>An incorrect privilege assignment vulnerability [CWE-266] in Fortinet FortiOS version 7.6.0, 7.4.0 through 7.4.4, 7.2.0 through 7.2.9 and before 7.0.15 allows an authenticated admin whose access profile has the Security Fabric permission to escalate their privileges to super-admin by connecting the targetted FortiGate to a malicious upstream FortiGate they control.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-266</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-40591">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-35279 – A stack-based buffer overflow [CWE-121] vulnerability in Fortinet FortiOS versio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-35279</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-35279</guid>
    <pubDate>Tue, 11 Feb 2025 17:15:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-35279</strong></p>
  <p>A stack-based buffer overflow [CWE-121] vulnerability in Fortinet FortiOS version 7.2.4 through 7.2.8 and version 7.4.0 through 7.4.4 allows a remote unauthenticated attacker to execute arbitrary code or commands via crafted UDP packets through the CAPWAP control, provided the attacker were able to evade FortiOS stack protections and provided the fabric service is running on the exposed interface.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-35279">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-55591 – An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-55591</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-55591</guid>
    <pubDate>Tue, 14 Jan 2025 14:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-55591</strong></p>
  <p>An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy version 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12 allows a remote attacker to gain super-admin privileges via crafted requests to Node.js websocket module.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-288</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-55591">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-54021 – An Improper Neutralization of CRLF Sequences in HTTP Headers ('http response spl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-54021</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-54021</guid>
    <pubDate>Tue, 14 Jan 2025 14:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-54021</strong></p>
  <p>An Improper Neutralization of CRLF Sequences in HTTP Headers ('http response splitting') vulnerability [CWE-113] in Fortinet FortiOS 7.2.0 through 7.6.0, FortiProxy 7.2.0 through 7.4.5 may allow a remote unauthenticated attacker to bypass the file filter via crafted HTTP headers.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-113</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-54021">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2024-52963 – A out-of-bounds write in Fortinet FortiOS versions 7.6.0, 7.4.0 through 7.4.6, 7...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-52963</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-52963</guid>
    <pubDate>Tue, 14 Jan 2025 14:15:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2024-52963</strong></p>
  <p>A out-of-bounds write in Fortinet FortiOS versions 7.6.0, 7.4.0 through 7.4.6, 7.2.0 through 7.2.10, 7.0.0 through 7.0.16, 6.4.0 through 6.4.15 allows attacker to trigger a denial of service via specially crafted packets.</p>
  <p><strong>CVSS:</strong> 3.7 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-52963">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-48886 – A weak authentication in Fortinet FortiOS versions 7.4.0 through 7.4.4, 7.2.0 th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-48886</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-48886</guid>
    <pubDate>Tue, 14 Jan 2025 14:15:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-48886</strong></p>
  <p>A weak authentication in Fortinet FortiOS versions 7.4.0 through 7.4.4, 7.2.0 through 7.2.8, 7.0.0 through 7.0.15, 6.4.0 through 6.4.15, FortiProxy versions 7.4.0 through 7.4.4, 7.2.0 through 7.2.10, 7.0.0 through 7.0.17, 2.0.0 through 2.0.14, FortiManager versions 7.6.0 through 7.6.1, 7.4.1 through 7.4.3, FortiManager Cloud versions 7.4.1 through 7.4.3, FortiAnalyzer Cloud versions 7.4.1 through…</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-1390</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-48886">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-48884 – A improper limitation of a pathname to a restricted directory ('path traversal')...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-48884</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-48884</guid>
    <pubDate>Tue, 14 Jan 2025 14:15:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-48884</strong></p>
  <p>A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiManager 7.6.0 through 7.6.1, FortiManager 7.4.1 through 7.4.3, FortiManager Cloud 7.4.1 through 7.4.3, FortiOS 7.6.0, FortiOS 7.4.0 through 7.4.4, FortiOS 7.2.0 through 7.2.9, FortiOS 7.0.0 through 7.0.15, FortiOS 6.4.0 through 6.4.15, FortiProxy 7.4.0 through 7.4.5, FortiProxy 7.2.0 th…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-48884">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-46670 – An Out-of-bounds Read vulnerability [CWE-125] in FortiOS version 7.6.0, version ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-46670</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-46670</guid>
    <pubDate>Tue, 14 Jan 2025 14:15:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-46670</strong></p>
  <p>An Out-of-bounds Read vulnerability [CWE-125] in FortiOS version 7.6.0, version 7.4.4 and below, version 7.2.9 and below and FortiSASE FortiOS tenant version 24.3.b IPsec IKE service may allow an unauthenticated remote attacker to trigger memory consumption leading to Denial of Service via crafted requests.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-46670">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2024-46669 – An Integer Overflow or Wraparound vulnerability [CWE-190] in version 7.4.4 and b...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-46669</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-46669</guid>
    <pubDate>Tue, 14 Jan 2025 14:15:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2024-46669</strong></p>
  <p>An Integer Overflow or Wraparound vulnerability [CWE-190] in version 7.4.4 and below, version 7.2.10 and below; FortiSASE version 23.4.b FortiOS tenant IPsec IKE service may allow an authenticated attacker to crash the IPsec tunnel via crafted requests, resulting in potential denial of service.</p>
  <p><strong>CVSS:</strong> 3.5 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-46669">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-46668 – An allocation of resources without limits or throttling vulnerability [CWE-770] ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-46668</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-46668</guid>
    <pubDate>Tue, 14 Jan 2025 14:15:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-46668</strong></p>
  <p>An allocation of resources without limits or throttling vulnerability [CWE-770] in FortiOS versions 7.4.0 through 7.4.4, versions 7.2.0 through 7.2.8, versions 7.0.0 through 7.0.15, and versions 6.4.0 through 6.4.15 may allow an unauthenticated remote user to consume all system memory via multiple large file uploads.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-46668">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-46666 – An allocation of resources without limits or throttling [CWE-770] vulnerability ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-46666</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-46666</guid>
    <pubDate>Tue, 14 Jan 2025 14:15:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-46666</strong></p>
  <p>An allocation of resources without limits or throttling [CWE-770] vulnerability in FortiOS versions 7.6.0, versions 7.4.4 through 7.4.0, 7.2 all versions, 7.0 all versions, 6.4 all versions may allow a remote unauthenticated attacker to prevent access to the GUI via specially crafted requests directed at specific endpoints.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-46666">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2024-46665 – An insertion of sensitive information into sent data vulnerability [CWE-201] in ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-46665</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-46665</guid>
    <pubDate>Tue, 14 Jan 2025 14:15:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2024-46665</strong></p>
  <p>An insertion of sensitive information into sent data vulnerability [CWE-201] in FortiOS 7.6.0, 7.4.0 through 7.4.4 may allow an attacker in a man-in-the-middle position to retrieve the RADIUS accounting server shared secret via intercepting accounting-requests.</p>
  <p><strong>CVSS:</strong> 3.7 · <strong>CWE:</strong> CWE-201</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-46665">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-36504 – An out-of-bounds read vulnerability [CWE-125] in FortiOS SSLVPN web portal versi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-36504</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-36504</guid>
    <pubDate>Tue, 14 Jan 2025 14:15:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-36504</strong></p>
  <p>An out-of-bounds read vulnerability [CWE-125] in FortiOS SSLVPN web portal versions 7.4.0 through 7.4.4, versions 7.2.0 through 7.2.8, 7.0 all verisons, and 6.4 all versions may allow an authenticated attacker to perform a denial of service on the SSLVPN web portal via a specially crafted URL.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-36504">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-46715 – An origin validation error [CWE-346] vulnerability in Fortinet FortiOS  IPSec VP...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-46715</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-46715</guid>
    <pubDate>Tue, 14 Jan 2025 14:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-46715</strong></p>
  <p>An origin validation error [CWE-346] vulnerability in Fortinet FortiOS  IPSec VPN version 7.4.0 through 7.4.1 and version 7.2.6 and below allows an authenticated IPSec VPN user with dynamic IP addressing to send (but not receive) packets spoofing the IP of another user via crafted network packets.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-346</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-46715">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-42786 – A null pointer dereference in FortiOS versions 7.4.0 through 7.4.1, 7.2.0 throug...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-42786</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-42786</guid>
    <pubDate>Tue, 14 Jan 2025 14:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-42786</strong></p>
  <p>A null pointer dereference in FortiOS versions 7.4.0 through 7.4.1, 7.2.0 through 7.2.5, 7.0 all versions, 6.4 all versions , 6.2 all versions and 6.0 all versions allows attacker to trigger a denial of service via a crafted http request.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-42786">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-42785 – A null pointer dereference in FortiOS versions 7.4.0 through 7.4.1, 7.2.0 throug...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-42785</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-42785</guid>
    <pubDate>Tue, 14 Jan 2025 14:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-42785</strong></p>
  <p>A null pointer dereference in FortiOS versions 7.4.0 through 7.4.1, 7.2.0 through 7.2.5, 7.0 all versions, 6.4 all versions , 6.2 all versions and 6.0 all versions allows attacker to trigger a denial of service via a crafted http request.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-42785">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-12820 – Under non-default configuration, a stack-based buffer overflow in FortiOS versio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-12820</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-12820</guid>
    <pubDate>Thu, 19 Dec 2024 11:15:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-12820</strong></p>
  <p>Under non-default configuration, a stack-based buffer overflow in FortiOS version 6.0.10 and below, version 5.6.12 and below may allow a remote attacker authenticated to the SSL VPN to crash the FortiClient NAC daemon (fcnacd) and potentially execute arbitrary code via requesting a large FortiClient file name. We are not aware of proof of concept code successfully achieving the latter.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-12820">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-33510 – An improper neutralization of special elements in output used by a downstream co...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-33510</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-33510</guid>
    <pubDate>Tue, 12 Nov 2024 19:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-33510</strong></p>
  <p>An improper neutralization of special elements in output used by a downstream component ('Injection') vulnerability [CWE-74] in FortiOS version 7.4.3 and below, version 7.2.8 and below, version 7.0.16 and below; FortiProxy version 7.4.3 and below, version 7.2.9 and below, version 7.0.16 and below; FortiSASE version 24.2.b SSL-VPN web user interface may allow a remote unauthenticated attacker to p…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-358</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-33510">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-26011 – A missing authentication for critical function in Fortinet FortiManager version ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-26011</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-26011</guid>
    <pubDate>Tue, 12 Nov 2024 19:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-26011</strong></p>
  <p>A missing authentication for critical function in Fortinet FortiManager version 7.4.0 through 7.4.2, 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through 6.4.14, FortiPAM version 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiProxy version 7.4.0 through 7.4.2, 7.2.0 through 7.2.9, 7.0.0 through 7.0.17, 2.0.0 through 2.0.14, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6, 1.0.0 through 1.0.7…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-26011">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-50176 – A session fixation in Fortinet FortiOS version 7.4.0 through 7.4.3 and 7.2.0 thr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-50176</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-50176</guid>
    <pubDate>Tue, 12 Nov 2024 19:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-50176</strong></p>
  <p>A session fixation in Fortinet FortiOS version 7.4.0 through 7.4.3 and 7.2.0 through 7.2.7 and 7.0.0 through 7.0.13 allows attacker to execute unauthorized code or commands via phishing SAML authentication link.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-384</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-50176">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-36505 – An improper access control vulnerability [CWE-284] in FortiOS 7.4.0 through 7.4...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-36505</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-36505</guid>
    <pubDate>Tue, 13 Aug 2024 16:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-36505</strong></p>
  <p>An improper access control vulnerability [CWE-284] in FortiOS 7.4.0 through 7.4.3, 7.2.5 through 7.2.7, 7.0.12 through 7.0.14 and 6.4.x may allow an attacker who has already successfully obtained write access to the underlying system (via another hypothetical exploit) to bypass the file integrity checking system.</p>
  <p><strong>CVSS:</strong> 5.1 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-36505">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2022-45862 – An insufficient session expiration vulnerability [CWE-613] vulnerability in Fort...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-45862</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-45862</guid>
    <pubDate>Tue, 13 Aug 2024 16:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2022-45862</strong></p>
  <p>An insufficient session expiration vulnerability [CWE-613] vulnerability in FortiOS 7.2.5 and below, 7.0 all versions, 6.4 all versions; FortiProxy 7.2 all versions, 7.0 all versions; FortiPAM 1.3 all versions, 1.2 all versions, 1.1 all versions, 1.0 all versions; FortiSwitchManager 7.2.1 and below, 7.0 all versions GUI may allow attackers to re-use websessions after GUI logout, should they manag…</p>
  <p><strong>CVSS:</strong> 3.7 · <strong>CWE:</strong> CWE-613</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-45862">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2024-26015 – An incorrect parsing of numbers with different radices vulnerability [CWE-1389] ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-26015</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-26015</guid>
    <pubDate>Tue, 09 Jul 2024 16:15:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2024-26015</strong></p>
  <p>An incorrect parsing of numbers with different radices vulnerability [CWE-1389] in FortiProxy version 7.4.3 and below, version 7.2.10 and below, version 7.0.17 and below and FortiOS version 7.4.3 and below, version 7.2.8 and below, version 7.0.15 and below IP address validation feature may permit an unauthenticated attacker to bypass the IP blocklist via crafted requests.</p>
  <p><strong>CVSS:</strong> 3.4 · <strong>CWE:</strong> CWE-1389</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-26015">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-26010 – A stack-based buffer overflow in Fortinet FortiPAM version 1.2.0, 1.1.0 through ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-26010</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-26010</guid>
    <pubDate>Tue, 11 Jun 2024 15:16:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-26010</strong></p>
  <p>A stack-based buffer overflow in Fortinet FortiPAM version 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiWeb, FortiAuthenticator, FortiSwitchManager version 7.2.0 through 7.2.3, 7.0.1 through 7.0.3, FortiOS version 7.4.0 through 7.4.3, 7.2.0 through 7.2.7, 7.0.0 through 7.0.14, 6.4.0 through 6.4.15, 6.2.0 through 6.2.16, 6.0.0 through 6.0.18, FortiProxy version 7.4.0 through 7.4.2, 7.2.0…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-26010">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-23111 – An improper neutralization of input during web page Generation ('Cross-site Scri...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-23111</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-23111</guid>
    <pubDate>Tue, 11 Jun 2024 15:16:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-23111</strong></p>
  <p>An improper neutralization of input during web page Generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiOS version 7.4.3 and below, 7.2 all versions, 7.0 all versions and FortiProxy version 7.4.2 and below, 7.2 all versions, 7.0 all versions reboot page may allow a remote privileged attacker with super-admin access to execute JavaScript code via crafted HTTP GET requests.</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-23111">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-23110 – A stack-based buffer overflow in Fortinet FortiOS version 7.4.0 through 7.4.2, 7...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-23110</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-23110</guid>
    <pubDate>Tue, 11 Jun 2024 15:16:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-23110</strong></p>
  <p>A stack-based buffer overflow in Fortinet FortiOS version 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, 6.0 all versions allows attacker to execute unauthorized code or commands via specially crafted commands</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-23110">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2024-21754 – A use of password hash with insufficient computational effort vulnerability [CWE...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-21754</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-21754</guid>
    <pubDate>Tue, 11 Jun 2024 15:16:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2024-21754</strong></p>
  <p>A use of password hash with insufficient computational effort vulnerability [CWE-916] affecting FortiOS version 7.4.3 and below, 7.2 all versions, 7.0 all versions, 6.4 all versions and FortiProxy version 7.4.2 and below, 7.2 all versions, 7.0 all versions, 2.0 all versions may allow a privileged attacker with super-admin profile and CLI access to decrypting the backup file.</p>
  <p><strong>CVSS:</strong> 1.8 · <strong>CWE:</strong> CWE-916</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-21754">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-46720 – A stack-based buffer overflow in Fortinet FortiOS version 7.4.0 through 7.4.1 an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-46720</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-46720</guid>
    <pubDate>Tue, 11 Jun 2024 15:15:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-46720</strong></p>
  <p>A stack-based buffer overflow in Fortinet FortiOS version 7.4.0 through 7.4.1 and 7.2.0 through 7.2.7 and 7.0.0 through 7.0.12 and 6.4.6 through 6.4.15 and 6.2.9 through 6.2.16 and 6.0.13 through 6.0.18 allows attacker to execute unauthorized code or commands via specially crafted CLI commands.</p>
  <p><strong>CVSS:</strong> 6.7 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-46720">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-26007 – An improper check or handling of exceptional conditions vulnerability [CWE-703] ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-26007</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-26007</guid>
    <pubDate>Tue, 14 May 2024 17:15:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-26007</strong></p>
  <p>An improper check or handling of exceptional conditions vulnerability [CWE-703] in Fortinet FortiOS version 7.4.1 allows an unauthenticated attacker to provoke a denial of service on the administrative interface via crafted HTTP requests.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-703</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-26007">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-46714 – A stack-based buffer overflow [CWE-121] vulnerability in Fortinet FortiOS versio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-46714</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-46714</guid>
    <pubDate>Tue, 14 May 2024 17:15:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-46714</strong></p>
  <p>A stack-based buffer overflow [CWE-121] vulnerability in Fortinet FortiOS version 7.2.1 through 7.2.6 and version 7.4.0 through 7.4.1 allows a privileged attacker over the administrative interface to execute arbitrary code or commands via crafted HTTP or HTTPs requests.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-46714">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-45586 – An insufficient verification of data authenticity vulnerability [CWE-345] in For...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-45586</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-45586</guid>
    <pubDate>Tue, 14 May 2024 17:15:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-45586</strong></p>
  <p>An insufficient verification of data authenticity vulnerability [CWE-345] in Fortinet FortiOS SSL-VPN tunnel mode version 7.4.0 through 7.4.1, version 7.2.0 through 7.2.7 and before 7.0.12 & FortiProxy SSL-VPN tunnel mode version 7.4.0 through 7.4.1, version 7.2.0 through 7.2.7 and before 7.0.13 allows an authenticated VPN user to send (but not receive) packets spoofing the IP of another user via…</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-345</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-45586">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-45583 – A use of externally-controlled format string in Fortinet FortiProxy versions 7.2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-45583</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-45583</guid>
    <pubDate>Tue, 14 May 2024 17:15:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-45583</strong></p>
  <p>A use of externally-controlled format string in Fortinet FortiProxy versions 7.2.0 through 7.2.5, 7.0.0 through 7.0.11, 2.0.0 through 2.0.13, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6 FortiPAM versions 1.1.0, 1.0.0 through 1.0.3 FortiOS versions 7.4.0, 7.2.0 through 7.2.5, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15 FortiSwitchManager versions 7.2.0 through 7.2.2, 7.0.0 throu…</p>
  <p><strong>CVSS:</strong> 6.7 · <strong>CWE:</strong> CWE-134</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-45583">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-44247 – A double free vulnerability [CWE-415] vulnerability in Fortinet FortiOS 6.4 all ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-44247</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-44247</guid>
    <pubDate>Tue, 14 May 2024 17:15:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-44247</strong></p>
  <p>A double free vulnerability [CWE-415] vulnerability in Fortinet FortiOS 6.4 all versions may allow a privileged attacker to execute code or commands via crafted HTTP or HTTPs requests.</p>
  <p><strong>CVSS:</strong> 6.6 · <strong>CWE:</strong> CWE-415</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-44247">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-36640 – A use of externally-controlled format string in Fortinet FortiProxy versions 7.2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-36640</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-36640</guid>
    <pubDate>Tue, 14 May 2024 17:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-36640</strong></p>
  <p>A use of externally-controlled format string in Fortinet FortiProxy versions 7.2.0 through 7.2.4, 7.0.0 through 7.0.10, 2.0.0 through 2.0.13, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6, 1.0.0 through 1.0.7, FortiPAM versions 1.0.0 through 1.0.3, FortiOS versions 7.2.0, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, 6.0.0 through 6.0.16 allows attacker to execute unauthorized cod…</p>
  <p><strong>CVSS:</strong> 6.7 · <strong>CWE:</strong> CWE-134</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-36640">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-23662 – An exposure of sensitive information to an unauthorized actor in Fortinet FortiO...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-23662</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-23662</guid>
    <pubDate>Tue, 09 Apr 2024 15:15:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-23662</strong></p>
  <p>An exposure of sensitive information to an unauthorized actor in Fortinet FortiOS at least version at least 7.4.0 through 7.4.1 and 7.2.0 through 7.2.5 and 7.0.0 through 7.0.15 and 6.4.0 through 6.4.15 allows attacker to information disclosure via HTTP requests.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-23662">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-48784 – A use of externally-controlled format string vulnerability [CWE-134] in FortiOS ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-48784</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-48784</guid>
    <pubDate>Tue, 09 Apr 2024 15:15:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-48784</strong></p>
  <p>A use of externally-controlled format string vulnerability [CWE-134] in FortiOS version 7.4.1 and below, version 7.2.7 and below, 7.0 all versions, 6.4 all versions command line interface may allow a local privileged attacker with super-admin profile and CLI access to execute arbitrary code or commands via specially crafted requests.</p>
  <p><strong>CVSS:</strong> 6.7 · <strong>CWE:</strong> CWE-134</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-48784">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-41677 – A insufficiently protected credentials in Fortinet FortiProxy 7.4.0, 7.2.0 throu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-41677</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-41677</guid>
    <pubDate>Tue, 09 Apr 2024 15:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-41677</strong></p>
  <p>A insufficiently protected credentials in Fortinet FortiProxy 7.4.0, 7.2.0 through 7.2.6, 7.0.0 through 7.0.12, 2.0.0 through 2.0.13, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6, 1.0.0 through 1.0.7, Fortinet FortiOS 7.4.0 through 7.4.1, 7.2.0 through 7.2.6, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, 6.0.0 through 6.0.17 allows attacker to execute unauthorized code or command…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-522</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-41677">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
