Latest fortinet fortiproxy Vulnerabilities

Administrator cookie leakage
Fortinet FortiOS>=7.4.0<=7.4.1
Fortinet FortiOS>=7.2.0<=7.2.6
Fortinet FortiOS>=7.0.0<=7.0.12
Fortinet FortiOS>=6.4.0<=6.4.14
Fortinet FortiOS>=6.2.0<=6.2.15
Fortinet FortiOS>=6.0
and 7 more
Administrator cookie leakage
Fortinet FortiOS>=7.4.0<=7.4.1
Fortinet FortiOS>=7.2.0<=7.2.6
Fortinet FortiOS>=7.0.0<=7.0.12
Fortinet FortiOS>=6.4.0<=6.4.14
Fortinet FortiOS>=6.2.0<=6.2.15
Fortinet FortiOS>=6.0
and 7 more
Out-of-bounds Write in captive portal
Fortinet FortiProxy>=2.0.0<=2.0.13
Fortinet FortiProxy>=7.0.0<=7.0.12
Fortinet FortiProxy>=7.2.0<=7.2.6
Fortinet FortiProxy=7.4.0
Fortinet FortiOS>=6.2.0<=6.2.15
Fortinet FortiOS>=6.4.0<=6.4.14
and 3 more
Authorization bypass in SSLVPN bookmarks
Fortinet FortiOS>=7.4.0<=7.4.1
Fortinet FortiOS>=7.2.0<=7.2.6
Fortinet FortiOS>=7.0.1<=7.0.13
Fortinet FortiOS>=6.4.7<=6.4.14
Fortinet FortiProxy>=7.4.0<=7.4.2
Fortinet FortiProxy>=7.2.0<=7.2.8
and 8 more
Out-of-bounds Write in captive portal
Fortinet FortiProxy>=2.0.0<=2.0.13
Fortinet FortiProxy>=7.0.0<=7.0.12
Fortinet FortiProxy>=7.2.0<=7.2.6
Fortinet FortiProxy=7.4.0
Fortinet FortiOS>=6.2.0<=6.2.15
Fortinet FortiOS>=6.4.0<=6.4.14
and 4 more
Authorization bypass in SSLVPN bookmarks
Fortinet FortiOS>=7.4.0<=7.4.1
Fortinet FortiOS>=7.2.0<=7.2.6
Fortinet FortiOS>=7.0.1<=7.0.13
Fortinet FortiOS>=6.4.7<=6.4.14
Fortinet FortiProxy>=7.4.0<=7.4.2
Fortinet FortiProxy>=7.2.0<=7.2.8
and 1 more
CVE-2023-44487 - Rapid Reset HTTP/2 vulnerability
Fortinet FortiOS>=7.4.0<=7.4.1
Fortinet FortiOS>=7.2.0<=7.2.6
Fortinet FortiOS>=7.0.0<=7.0.13
Fortinet FortiProxy>=7.4.0<=7.4.1
Fortinet FortiProxy>=7.2.0<=7.2.7
Fortinet FortiProxy>=7.0
Out-of-bound Write in sslvpnd
Fortinet FortiOS>=7.4.0<=7.4.2
Fortinet FortiOS>=7.2.0<=7.2.6
Fortinet FortiOS>=7.0.0<=7.0.13
Fortinet FortiOS>=6.4.0<=6.4.14
Fortinet FortiOS>=6.2.0<=6.2.15
Fortinet FortiOS>=6.0.0<=6.0.17
and 7 more
Out-of-bound Write in sslvpnd
Fortinet FortiOS
Fortinet FortiProxy>=1.0.0<2.0.14
Fortinet FortiProxy>=7.0.0<7.0.15
Fortinet FortiProxy>=7.2.0<7.2.9
Fortinet FortiProxy>=7.4.0<7.4.3
Fortinet FortiOS>=6.0.0<6.2.16
and 17 more
Format String Bug in fgfmd
Fortinet FortiOS=6.0.x
Fortinet FortiOS
Fortinet FortiSIEM
Fortinet FortiProxy>=7.0.0<=7.0.14
Fortinet FortiProxy>=7.2.0<=7.2.8
Fortinet FortiProxy>=7.4.0<=7.4.2
and 18 more
Format String Bug in fgfmd
Fortinet FortiOS>=7.4.0<=7.4.2
Fortinet FortiOS>=7.2.0<=7.2.6
Fortinet FortiOS>=7.0.0<=7.0.13
Fortinet FortiPAM>=1.2
Fortinet FortiPAM>=1.1
Fortinet FortiPAM>=1.0
and 4 more
An improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiSIEM version 7.1.0 through 7.1.1 and 7.0.0 through 7.0.2 and 6.7.0 through 6.7.8 and 6.6....
Fortinet FortiSIEM>=6.4.0<=6.4.2
Fortinet FortiSIEM>=6.5.0<=6.5.2
Fortinet FortiSIEM>=6.6.0<=6.6.3
Fortinet FortiSIEM>=6.7.0<=6.7.8
Fortinet FortiSIEM>=7.0.0<=7.0.2
Fortinet FortiSIEM=7.1.0
and 3 more
An improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiSIEM version 7.1.0 through 7.1.1 and 7.0.0 through 7.0.2 and 6.7.0 through 6.7.8 and 6.6....
Fortinet FortiSIEM>=6.4.0<=6.4.2
Fortinet FortiSIEM>=6.5.0<=6.5.2
Fortinet FortiSIEM>=6.6.0<=6.6.3
Fortinet FortiSIEM>=6.7.0<=6.7.8
Fortinet FortiSIEM>=7.0.0<=7.0.2
Fortinet FortiSIEM=7.1.0
and 3 more
Improper authorization for HA requests
Fortinet FortiProxy=7.4.0
Fortinet FortiProxy=7.4.1
Fortinet FortiOS=7.2.5
Fortinet FortiOS=7.4.0
Fortinet FortiOS=7.4.1
Fortinet FortiOS>=7.4.0<=7.4.1
and 2 more
Improper authorization for HA requests
Fortinet FortiOS>=7.4.0<=7.4.1
Fortinet FortiOS=.
Fortinet FortiProxy>=7.4.0<=7.4.1
Firewall deny policy bypass
Fortinet FortiOS=.
Fortinet FortiOS>=7.0
Fortinet FortiOS>=6.4
Fortinet FortiProxy>=7.2.0<=7.2.3
Fortinet FortiProxy>=7.0.0<=7.0.9
Fortinet FortiProxy>=2.0.0<=2.0.12
Format String Bug in HTTPSd
Fortinet FortiOS=.
Fortinet FortiOS>=7.2.0<=7.2.4
Fortinet FortiOS>=7.0.0<=7.0.11
Fortinet FortiOS>=6.4.0<=6.4.12
Fortinet FortiOS>=6.2.0<=6.2.15
Fortinet FortiOS>=6.0
and 4 more
Format String Bug in HTTPSd
Fortinet FortiProxy>=7.0.0<=7.0.10
Fortinet FortiProxy>=7.2.0<=7.2.4
Fortinet FortiOS>=6.0.0<=6.0.17
Fortinet FortiOS>=6.2.0<=6.2.15
Fortinet FortiOS>=6.4.0<=6.4.12
Fortinet FortiOS>=7.0.0<=7.0.11
and 14 more
Firewall deny policy bypass
Fortinet FortiProxy>=2.0.0<=2.0.12
Fortinet FortiProxy>=7.0.0<=7.0.9
Fortinet FortiProxy>=7.2.0<=7.2.3
Fortinet FortiOS>=6.4.0<=6.4.14
Fortinet FortiOS>=7.0.0<=7.0.13
Fortinet FortiOS=7.2.0
and 6 more
Bypass of root file system integrity checks at boot time on VM
Fortinet FortiProxy>=2.0.0<=2.0.13
Fortinet FortiProxy>=7.0.0<=7.0.13
Fortinet FortiProxy>=7.2.0<=7.2.7
Fortinet FortiOS>=6.0.0<=6.0.17
Fortinet FortiOS>=6.2.0<=6.2.15
Fortinet FortiOS>=6.4.0<=6.4.14
and 7 more
DOS in headers management
Fortinet FortiProxy>=1.0.0<=1.0.7
Fortinet FortiProxy>=1.1.0<=1.1.6
Fortinet FortiProxy>=1.2.0<=1.2.13
Fortinet FortiProxy>=2.0.0<=2.0.13
Fortinet FortiProxy>=7.0.0<=7.0.10
Fortinet FortiProxy>=7.2.0<=7.2.4
and 17 more
DOS in headers management
Fortinet FortiOS=.
Fortinet FortiOS>=7.2.0<=7.2.5
Fortinet FortiOS>=7.0.0<=7.0.12
Fortinet FortiOS>=6.4
Fortinet FortiOS>=6.2
Fortinet FortiOS>=6.0
and 6 more
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiSIEM version 7.0.0 and 6.7.0 through 6.7.5 and 6.6.0 through 6.6.3 and 6.5.0 through 6.5.1...
Fortinet FortiSIEM>=6.6.0<=6.6.3
Fortinet FortiSIEM>=6.7.0<=6.7.5
Fortinet FortiSIEM=6.4.0
Fortinet FortiSIEM=6.4.1
Fortinet FortiSIEM=6.4.2
Fortinet FortiSIEM=6.5.0
and 4 more
FortiOS & FortiProxy - Webproxy process denial of service
Fortinet FortiProxy>=7.0.0<=7.0.8
Fortinet FortiProxy=7.2.0
Fortinet FortiProxy=7.2.1
Fortinet FortiProxy=7.2.2
Fortinet FortiOS>=7.0.0<=7.0.10
Fortinet FortiOS>=7.2.0<=7.2.4
- Rapid Reset HTTP/2 vulnerability
Microsoft Windows 11=21H2
Microsoft Windows 11=21H2
Microsoft Windows Server 2022
Microsoft Windows Server 2022
Microsoft Windows 11=22H2
Microsoft Windows 11=22H2
and 556 more
An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiProxy 7.2.0 through 7.2.4, 7.0.0 through 7.0.10 and FortiOS 7.2.0 through 7.2.4, ...
Fortinet FortiProxy>=7.0.0<7.0.11
Fortinet FortiProxy>=7.2.0<7.2.5
Fortinet FortiOS>=6.2.0<6.2.15
Fortinet FortiOS>=6.4.0<6.4.13
Fortinet FortiOS>=7.0.0<7.0.12
Fortinet FortiOS>=7.2.0<7.2.5
A stack-based overflow vulnerability [CWE-124] in Fortinet FortiOS version 7.0.0 through 7.0.10 and 7.2.0 through 7.2.3 and FortiProxy version 7.0.0 through 7.0.9 and 7.2.0 through 7.2.2 allows a remo...
Fortinet FortiProxy>=7.0.0<=7.0.9
Fortinet FortiProxy=7.2.0
Fortinet FortiProxy=7.2.1
Fortinet FortiProxy=7.2.2
Fortinet FortiOS>=7.0.0<=7.0.10
Fortinet FortiOS>=7.2.0<=7.2.3
A null pointer dereference in Fortinet FortiOS before 7.2.5 and before 7.0.11, FortiProxy before 7.2.3 and before 7.0.9 allows attacker to denial of sslvpn service via specifically crafted request in ...
Fortinet FortiProxy>=7.0.0<=7.0.9
Fortinet FortiProxy>=7.2.0<=7.2.3
Fortinet FortiOS>=7.0.0<7.0.11
Fortinet FortiOS>=7.2.0<7.2.5
A null pointer dereference in Fortinet FortiOS before 7.2.5, before 7.0.11 and before 6.4.13, FortiProxy before 7.2.4 and before 7.0.10 allows attacker to denial of sslvpn service via specifically cr...
Fortinet FortiProxy>=7.0.0<7.0.10
Fortinet FortiProxy>=7.2.0<7.2.4
Fortinet FortiOS>=6.4.0<6.4.13
Fortinet FortiOS>=7.0.0<7.0.11
Fortinet FortiOS>=7.2.0<7.2.5
A loop with unreachable exit condition ('infinite loop') in Fortinet FortiOS version 7.2.0 through 7.2.4, FortiOS version 7.0.0 through 7.0.10, FortiOS 6.4 all versions, FortiOS 6.2 all versions, For...
Fortinet FortiProxy>=1.0.0<=1.0.7
Fortinet FortiProxy>=1.1.0<=1.1.6
Fortinet FortiProxy>=1.2.0<=1.2.13
Fortinet FortiProxy>=2.0.0<=2.0.12
Fortinet FortiProxy>=7.0.0<=7.0.9
Fortinet FortiProxy>=7.2.0<=7.2.3
and 14 more
An improper certificate validation vulnerability [CWE-295] in FortiOS 6.2 all versions, 6.4 all versions, 7.0.0 through 7.0.10, 7.2.0 and FortiProxy 1.2 all versions, 2.0 all versions, 7.0.0 through 7...
Fortinet FortiProxy>=1.2.0<=1.2.13
Fortinet FortiProxy>=2.0.0<=2.0.12
Fortinet FortiProxy>=7.0.0<=7.0.9
Fortinet FortiProxy>=7.2.0<=7.2.3
Fortinet FortiOS>=6.0.0<=6.0.17
Fortinet FortiOS>=6.2.0<=6.2.15
and 3 more
A access of uninitialized pointer vulnerability [CWE-824] in Fortinet FortiProxy version 7.2.0 through 7.2.3 and before 7.0.9 and FortiOS version 7.2.0 through 7.2.4 and before 7.0.11 allows an authe...
Fortinet FortiProxy>=1.1.0<=1.1.6
Fortinet FortiProxy>=1.2.0<=1.2.13
Fortinet FortiProxy>=2.0.0<=2.0.12
Fortinet FortiProxy>=7.0.0<=7.0.9
Fortinet FortiProxy=7.2.0
Fortinet FortiProxy=7.2.1
and 7 more
An insertion of sensitive information into log file vulnerability in Fortinet FortiOS 7.2.0 through 7.2.4 and FortiProxy 7.0.0 through 7.0.10. 7.2.0 through 7.2.1 allows an attacker to read certain pa...
Fortinet FortiProxy>=7.0.0<=7.0.10
Fortinet FortiProxy=7.2.0
Fortinet FortiProxy=7.2.1
Fortinet FortiOS>=7.2.0<=7.2.4
A use of externally-controlled format string in Fortinet FortiOS version 7.2.0 through 7.2.4, FortiOS all versions 7.0, FortiOS all versions 6.4, FortiOS all versions 6.2, FortiProxy version 7.2.0 thr...
Fortinet FortiProxy>=7.0.0<=7.0.7
Fortinet FortiProxy=7.2.0
Fortinet FortiProxy=7.2.1
Fortinet FortiOS>=6.2.0<=6.2.15
Fortinet FortiOS>=6.4.0<=6.4.12
Fortinet FortiOS>=7.0.0<=7.0.11
and 1 more
A out-of-bounds write in Fortinet FortiOS version 7.2.0 through 7.2.3, FortiOS version 7.0.0 through 7.0.10, FortiOS version 6.4.0 through 6.4.12, FortiOS all versions 6.2, FortiOS all versions 6.0, F...
Fortinet FortiProxy>=1.0.0<=1.0.7
Fortinet FortiProxy>=1.1.0<=1.1.6
Fortinet FortiProxy>=1.2.0<=1.2.13
Fortinet FortiProxy>=2.0.0<=2.0.12
Fortinet FortiProxy>=7.0.0<=7.0.8
Fortinet FortiProxy=7.2.0
and 7 more
A relative path traversal vulnerability [CWE-23] in Fortinet FortiOS version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.9 and before 6.4.12, FortiProxy version 7.2.0 through 7.2.1 and 7.0.0 throug...
Fortinet FortiProxy>=1.0.0<=1.0.7
Fortinet FortiProxy>=1.1.0<=1.1.6
Fortinet FortiProxy>=1.2.0<=1.2.13
Fortinet FortiProxy>=2.0.0<=2.0.11
Fortinet FortiProxy>=7.0.0<=7.0.7
Fortinet FortiProxy=7.2.0
and 9 more
A cleartext transmission of sensitive information vulnerability [CWE-319] in Fortinet FortiOS version 7.2.0 through 7.2.4, 7.0.0 through 7.0.8, FortiProxy version 7.2.0 through 7.2.1 and 7.0.0 through...
Fortinet FortiProxy>=7.0.0<=7.0.7
Fortinet FortiProxy=7.2.0
Fortinet FortiProxy=7.2.1
Fortinet FortiOS>=7.0.0<=7.0.8
Fortinet FortiOS>=7.2.0<=7.2.4
Heap buffer overflow in sslvpn pre-authentication
Fortinet Fortios-6k7k>=6.2.10<=6.2.13
Fortinet Fortios-6k7k=6.0.10
Fortinet Fortios-6k7k=6.0.12
Fortinet Fortios-6k7k=6.0.13
Fortinet Fortios-6k7k=6.0.14
Fortinet Fortios-6k7k=6.0.15
and 25 more
A out-of-bounds write in Fortinet FortiOS version 7.2.0 through 7.2.3, FortiOS version 7.0.0 through 7.0.10, FortiOS version 6.4.0 through 6.4.11, FortiOS version 6.2.0 through 6.2.13, FortiOS all ver...
Fortinet FortiProxy=1.0.0
Fortinet FortiProxy=1.1.0
Fortinet FortiProxy=1.2.0
Fortinet FortiProxy=2.0.0
Fortinet FortiOS>=6.0.0<=6.0.16
Fortinet FortiOS>=6.2.0<6.2.14
and 3 more
A url redirection to untrusted site ('open redirect') in Fortinet FortiOS version 7.2.0 through 7.2.3, FortiOS version 7.0.0 through 7.0.9, FortiOS versions 6.4.0 through 6.4.12, FortiOS all versions ...
Fortinet FortiProxy>=1.0.0<=2.0.12
Fortinet FortiProxy>=7.0.0<7.0.9
Fortinet FortiProxy>=7.2.0<7.2.3
Fortinet FortiOS>=6.0.0<6.4.13
Fortinet FortiOS>=7.0.0<7.0.11
Fortinet FortiOS>=7.2.0<7.2.4
An improper neutralization of input during web page generation vulnerability ('Cross-site Scripting') [CWE-79] in Fortinet FortiOS version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.9, version 6.4...
Fortinet FortiProxy>=7.0.0<7.0.8
Fortinet FortiProxy>=7.2.0<7.2.2
Fortinet FortiOS>=6.2.0<6.2.13
Fortinet FortiOS>=6.4.0<6.4.12
Fortinet FortiOS>=7.0.0<7.0.10
Fortinet FortiOS>=7.2.0<7.2.4
An improper restriction of excessive authentication attempts vulnerability [CWE-307] in Fortinet FortiOS version 7.2.0 through 7.2.3 and before 7.0.10, FortiProxy version 7.2.0 through 7.2.2 and befor...
Fortinet FortiProxy>=1.0.0<=2.0.9
Fortinet FortiProxy>=7.0.0<7.0.8
Fortinet FortiProxy>=7.2.0<7.2.2
Fortinet FortiOS>=6.2.0<6.4.13
Fortinet FortiOS>=7.0.0<7.0.11
Fortinet FortiOS>=7.2.0<7.2.4
A missing authentication for critical function vulnerability [CWE-306] in FortiPresence infrastructure server before version 1.2.1 allows a remote, unauthenticated attacker to access the Redis and Mon...
Fortinet FortiProxy>=1.0.0<2.0.0
A relative path traversal vulnerability [CWE-23] in Fortinet FortiOS version 7.2.0 through 7.2.2, 7.0.0 through 7.0.8 and before 6.4.11, FortiProxy version 7.2.0 through 7.2.2 and 7.0.0 through 7.0.8 ...
Fortinet FortiProxy>=1.1.0<=1.1.6
Fortinet FortiProxy>=1.2.0<=1.2.13
Fortinet FortiProxy>=2.0.0<=2.0.11
Fortinet FortiProxy>=7.0.0<=7.0.7
Fortinet FortiProxy=7.2.0
Fortinet FortiProxy=7.2.1
and 4 more
An access of uninitialized pointer vulnerability [CWE-824] in the SSL VPN portal of Fortinet FortiOS version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.9 and before 6.4.11 and FortiProxy version 7...
Fortinet FortiProxy>=1.2.0<=1.2.13
Fortinet FortiProxy>=2.0.0<=2.0.11
Fortinet FortiProxy>=7.0.0<=7.0.7
Fortinet FortiProxy=1.1.5
Fortinet FortiProxy=1.1.6
Fortinet FortiProxy=7.2.0
and 5 more
An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in Fortinet FortiProxy version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.7, FortiOS version 7.2.0 through 7.2.3 an...
Fortinet FortiProxy>=7.0.0<=7.0.8
Fortinet FortiProxy>=7.2.0<=7.2.2
Fortinet FortiOS>=6.2.3<=6.2.13
Fortinet FortiOS>=6.4.0<=6.4.11
Fortinet FortiOS>=7.0.0<=7.0.9
Fortinet FortiOS>=7.2.0<=7.2.3
A relative path traversal vulnerability [CWE-23] in Fortinet FortiOS version 7.2.0 through 7.2.2, 7.0.0 through 7.0.8 and before 6.4.10, FortiProxy version 7.2.0 through 7.2.1, 7.0.0 through 7.0.7 and...
Fortinet FortiSwitchManager=7.0.0
Fortinet FortiSwitchManager=7.2.0
Fortinet FortiProxy>=1.1.0<=1.1.6
Fortinet FortiProxy>=1.2.0<=1.2.13
Fortinet FortiProxy>=2.0.0<=2.0.10
Fortinet FortiProxy>=7.0.0<=7.0.7
and 8 more
A improper neutralization of crlf sequences in http headers ('http response splitting') in Fortinet FortiOS versions 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0 through 6.4.11, 6.2.0 through 6.2.1...
Fortinet FortiProxy>=1.1.0<=1.1.6
Fortinet FortiProxy>=1.2.0<=1.2.13
Fortinet FortiProxy>=2.0.0<=2.0.10
Fortinet FortiProxy>=7.0.0<=7.0.7
Fortinet FortiProxy=7.2.0
Fortinet FortiProxy=7.2.1
and 7 more
A missing cryptographic steps vulnerability [CWE-325] in the functions that encrypt the DHCP and DNS keys in Fortinet FortiOS version 7.2.0, 7.0.0 through 7.0.5, 6.4.0 through 6.4.9, 6.2.x and 6.0.x m...
Fortinet FortiProxy>=1.1.0<=1.1.6
Fortinet FortiProxy>=1.2.0<=1.2.13
Fortinet FortiProxy>=2.0.0<=2.0.11
Fortinet FortiProxy>=7.0.0<7.0.8
Fortinet FortiProxy=7.2.0
Fortinet FortiProxy=7.2.1
and 5 more
An improper privilege management vulnerability [CWE-269] in Fortinet FortiOS version 7.2.0 and before 7.0.7 and FortiProxy version 7.2.0 through 7.2.1 and before 7.0.7 allows an attacker that has acce...
Fortinet FortiProxy>=1.1.0<=2.0.9
Fortinet FortiProxy>=7.0.0<7.0.8
Fortinet FortiProxy>=7.2.0<7.2.2
Fortinet FortiOS>=6.0.0<7.0.8
Fortinet FortiOS>=7.2.0<7.2.1

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2024 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203