An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in FortiManager, FortiAnalyzer & FortiAnalyzer-BigData may allow a privileged attacker to read arbitrary files from the underlying system via crafted HTTP or HTTPs requests.
Multiple relative path traversal vulnerabilities [CWE-23] in FortiManager, FortiAnalyzer & FortiAnalyzer-BigData may allow a privileged attacker to delete files from the underlying filesystem via crafted CLI requests.
A stack-based buffer overflow vulnerability [CWE-121] in FortiManager, FortiAnalyzer and FortiAnalyzer-BigData CLI may allow a privileged attacker to execute unauthorized code or commands via crafted CLI requests.
An Exposure of personal information to an unauthorized actor [CWE-359] in FortiManager, FortiAnalyzer & FortiAnalyzer-BigData may allow a privileged attacker with administrative read permissions to read event logs of another adom via crafted HTTP or HTTPs requests.
An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in FortiManager, FortiAnalyzer & FortiAnalyzer-BigData CLI may allow an authenticated privileged attacker to execute unauthorized code or commands via crafted CLI requests.
An authorization bypass through user-controlled key [CWE-639] vulnerability in FortiAnalyzer & FortiManager may allow a remote attacker with low privileges to read sensitive data via a crafted HTTP request.