Authentication rate-limit bypass permits to brute force admin logins
CVSSv3 Score: 7.3
An Improper Control of Interaction Frequency vulnerability in FortiWeb may allow a remote unauthenticated attacker to bypass...
Protected hostname bypass
CVSSv3 Score: 5.0
An authentication bypass by spoofing vulnerability in FortiWeb protected hostname feature may allow a remote unauthenticated attacker...
Authentication Lockout Bypass via Race Condition
CVSSv3 Score: 3.4
An improper restriction of excessive authentication attempts vulnerability in FortiManager and FortiAnalyzer may allow an attacker to...
OS Command injection in FortiWeb API
CVSSv3 Score: 6.7
An OS Command Injection vulnerability in FortiWeb API may allow an authenticated attacked to execute arbitrary commands...
Null Pointer Dereference in Anti-Defacement feature
CVSSv3 Score: 2.5
A NULL Pointer Dereference vulnerability in FortiWeb may allow an authenticated attacker to crash the HTTP daemon...
Format string vulnerability in fazsvcd
CVSSv3 Score: 6.5
A use of externally-controlled format string vulnerability in FortiAnalyzer, FortiAnalyzer Cloud, FortiManager and FortiManager Cloud fazsvcd daemon...
Local privilege escalation via improper symlink following
CVSSv3 Score: 7.4
A UNIX symbolic link (Symlink) Following vulnerability in FortiClientLinux may allow a local and unprivileged user to...
Buffer overflow via fgtupdates service
CVSSv3 Score: 7.0
A Stack-based Buffer Overflow vulnerability in FortiManager fgtupdates service may allow a remote unauthenticated attacker to execute...
Lack of TLS Certificate Validation during initial SSO Authentication
CVSSv3 Score: 6.3
An improper certificate validation vulnerability in the FortiManager GUI may allow a remote unauthenticated attacker to view...





