Known vulnerabilities in FortiTester 3.2.0

Software: FortiTester
Version: 3.2.0
Software CPE: cpe:2.3:a:fortinet:fortitester:*:*:*:*:*:*:*:*
Total vulnerabilities: 12
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting FortiTester version 3.2.0 FortiTester 3.2.0 is affected by 12 vulnerabilities: 1 high, 2 medium, 9 low Critical High Medium Low

Vulnerabilities (12)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU84858 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2023-40716
CWE-78 Low
No
No
7.3.0 29.12.2023 SB2023122906
#VU81223 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2023-36642
CWE-78 Low
No
No
7.3.0 27.09.2023 SB2023092716
#VU81222 - Cleartext Storage of Sensitive Information
CVE-2023-40715
CWE-312 Low
No
No
7.3.0 27.09.2023 SB2023092716
#VU81220 - Use of Hard-coded Credentials
CVE-2023-40717
CWE-798 Low
No
No
7.3.0 27.09.2023 SB2023092716
#VU70664 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2022-35845
CWE-78 Medium
No
No
3.9.2, 4.2.1, 7.1.1, 7.2.0 03.01.2023 SB2023010327
#VU68919 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2022-33870
CWE-78 Low
No
No
3.9.2, 4.2.1, 7.1.1, 7.2.0 02.11.2022 SB2022110216
#VU68918 - Hidden Functionality (Backdoor)
CVE-2022-38372
CWE-912 Low
No
No
3.9.2, 4.2.1, 7.1.1, 7.2.0 02.11.2022 SB2022110216
#VU68104 - Improper Restriction of Excessive Authentication Attempts
CVE-2022-35846
CWE-307 Medium
No
No
3.9.2, 4.2.1, 7.1.1 10.10.2022 SB2022101027
#VU68103 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2022-35844
CWE-78 Low
No
No
3.9.2, 4.2.1, 7.1.1 10.10.2022 SB2022101027
#VU68102 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2022-33873
CWE-78 High
No
No
3.9.2, 4.2.1, 7.1.1 10.10.2022 SB2022101027
#VU46991 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2020-12817
CWE-79 Low
No
No
3.9.0 23.09.2020 SB2020092327
#VU46989 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2020-12815
CWE-79 Low
No
No
3.9.0 23.09.2020 SB2020092327