Known vulnerabilities in FortiADC 6.2.5

Software: FortiADC
Version: 6.2.5
Software CPE: cpe:2.3:a:fortinet:fortiadc:*:*:*:*:*:*:*:*
Total vulnerabilities: 19
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.4

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting FortiADC version 6.2.5 FortiADC 6.2.5 is affected by 19 vulnerabilities: 1 high, 2 medium, 16 low Critical High Medium Low

Vulnerabilities (19)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU118608 - Exposure of sensitive information to an unauthorized actor
CVE-2025-54971
CWE-200 Low
No
No
7.4.3 18.11.2025 SB2025111877
#VU118599 - Out-of-bounds write
CVE-2025-48839
CWE-787 Low
No
No
7.4.8, 7.6.3, 8.0.1 18.11.2025 SB2025111868
#VU117647 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2023-37933
CWE-79 Medium
No
No
7.1.4, 7.2.2, 7.4.1 24.10.2025 SB2025102465
#VU117135 - Exposure of sensitive information to an unauthorized actor
CVE-2025-59921
CWE-200 Low
No
No
7.1.5, 7.2.4, 7.4.1 14.10.2025 SB20251014107
#VU113975 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2025-49813
CWE-78 Low
No
No
7.1.2, 7.2.1 13.08.2025 SB2025081301
#VU111053 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2025-31104
CWE-78 Low
No
No
7.1.5, 7.2.8, 7.4.7, 7.6.2 11.06.2025 SB2025061118
#VU97002 - Improperly Implemented Security Check for Standard
CVE-2024-36511
CWE-358 Low
No
No
7.4.5 10.09.2024 SB2024091082
#VU94013 - Improper Certificate Validation
CVE-2023-50178
CWE-295 Medium
No
No
7.2.4, 7.4.1 09.07.2024 SB20240709123
#VU94001 - Improper Access Control
CVE-2023-50181
CWE-284 Low
No
No
7.2.5, 7.4.2 09.07.2024 SB20240709108
#VU89567 - Exposure of sensitive information to an unauthorized actor
CVE-2023-50180
CWE-200 Low
No
No
7.2.4, 7.4.2 15.05.2024 SB2024051538
#VU84528 - Improper Authorization
CVE-2023-41673
CWE-285 Low
No
No
7.2.3, 7.4.1 18.12.2023 SB2023121848
#VU83296 - Memory corruption
CVE-2023-29177
CWE-119 Low
No
No
7.1.3, 7.2.1 20.11.2023 SB2023112036
#VU83286 - Improper Access Control
CVE-2023-26205
CWE-284 High
No
No
7.1.3, 7.2.0 20.11.2023 SB2023112037
#VU81962 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2023-25607
CWE-78 Low
No
No
7.0.4, 7.1.1 12.10.2023 SB2023101254
#VU80870 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2022-35849
CWE-78 Low
No
No
6.2.6, 7.0.4, 7.1.2 18.09.2023 SB2023091834
#VU77196 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2023-26210
CWE-78 Low
No
No
7.1.3, 7.2.1 13.06.2023 SB2023061326
#VU75735 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2023-27993
CWE-22 Low
No
No
7.1.2, 7.2.1 04.05.2023 SB2023050444
#VU75067 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2022-43948
CWE-78 Low
No
No
7.0.4, 7.1.2 13.04.2023 SB2023041321
#VU74977 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2022-43952
CWE-79 Low
No
No
6.2.6, 7.0.4, 7.1.2 11.04.2023 SB2023041196