Vulnerabilities
Vulnerable Software
Fortinet:  Security Vulnerabilities
Fortinet FortiManager 5.0 before 5.0.11 and 5.2 before 5.2.2 allow local users to gain privileges via crafted CLI commands.
CVSS Score
7.8
EPSS Score
0.004
Published
2017-08-22
Fortinet FortiManager 5.0.x before 5.0.11, 5.2.x before 5.2.2 allows remote attackers to obtain arbitrary files via vectors involving another unspecified vulnerability.
CVSS Score
7.5
EPSS Score
0.02
Published
2017-08-11
Cross-site scripting (XSS) vulnerability in Fortinet FortiManager 5.0.x before 5.0.11, 5.2.x before 5.2.2 allows remote authenticated users to inject arbitrary web script or HTML via vectors involving unspecified parameters and a privilege escalation attack.
CVSS Score
5.4
EPSS Score
0.012
Published
2017-08-11
SQL injection vulnerability in Fortinet FortiManager 5.0.x before 5.0.11, 5.2.x before 5.2.2 allows remote attackers to execute arbitrary commands via unspecified parameters.
CVSS Score
9.8
EPSS Score
0.023
Published
2017-08-11
An information disclosure vulnerability in Fortinet FortiOS 5.6.0, 5.4.4 and below versions allows attacker to get FortiOS version info by inspecting FortiOS IKE VendorID packets.
CVSS Score
7.5
EPSS Score
0.014
Published
2017-08-10
An information disclosure vulnerability in Fortinet FortiWeb 5.8.2 and below versions allows logged-in admin user to view SNMPv3 user password in cleartext in webui via the HTML source code.
CVSS Score
4.9
EPSS Score
0.011
Published
2017-08-10
A hard-coded account named 'upgrade' in Fortinet FortiWLM 8.3.0 and lower versions allows a remote attacker to log-in and execute commands with 'upgrade' account privileges.
CVSS Score
9.8
EPSS Score
0.025
Published
2017-07-22
In FortiClientWindows 5.4.1 and 5.4.2, an attacker may escalate privilege via a FortiClientNamedPipe vulnerability.
CVSS Score
8.8
EPSS Score
0.018
Published
2017-06-26
A Cross-Site Scripting vulnerability in Fortinet FortiGate 5.2.0 through 5.2.10 allows attacker to execute unauthorized code or commands via the srcintf parameter during Firewall Policy Creation.
CVSS Score
6.1
EPSS Score
0.01
Published
2017-06-01
A Cross-Site Scripting vulnerability in Fortinet FortiWeb versions 5.7.1 and below allows attacker to execute unauthorized code or commands via an improperly sanitized POST parameter in the FortiWeb Site Publisher feature.
CVSS Score
6.1
EPSS Score
0.007
Published
2017-05-27


Contact Us

Shodan ® - All rights reserved