Known vulnerabilities in FortiAnalyzer 6.4.0 - page 2

Software: FortiAnalyzer
Version: 6.4.0
Software CPE: cpe:2.3:a:fortinet:fortianalyzer:*:*:*:*:*:*:*:*
Total vulnerabilities: 73
Public exploits: 5
Known exploited (KEV): 1
Highest CVSSv4 Score: 9.4

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting FortiAnalyzer version 6.4.0 FortiAnalyzer 6.4.0 is affected by 73 vulnerabilities: 8 high, 24 medium, 41 low Critical High Medium Low

Vulnerabilities (73)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU100782 - Client-Side Enforcement of Server-Side Security
CVE-2024-23666
CWE-602 Medium
Public exploit available
No
6.4.15, 7.0.13, 7.2.6, 7.4.3 21.11.2024 SB2024112167
SB2024112168
#VU100460 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2024-35274
CWE-22 Low
No
No
7.4.3 14.11.2024 SB2024111414
SB2024111415
#VU100455 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2024-32118
CWE-78 Low
No
No
7.2.6, 7.4.3 14.11.2024 SB2024111412
SB2024111413
#VU100453 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2024-32117
CWE-22 Low
No
No
7.2.6, 7.4.3 14.11.2024 SB2024111409
SB2024111410
#VU100452 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2024-32116
CWE-22 Low
No
No
7.2.6, 7.4.3 14.11.2024 SB2024111404
SB2024111405
#VU100450 - Improper Access Control
CVE-2023-44255
CWE-284 Low
No
No
7.4.3 14.11.2024 SB2024111401
SB2024111402
#VU100413 - Heap-based Buffer Overflow
CVE-2024-33505
CWE-122 High
No
No
7.2.6, 7.4.3 12.11.2024 SB20241112168
SB20241112169
#VU97007 - Improper Access Control
CVE-2023-44254
CWE-284 Low
No
No
7.2.5, 7.4.1 10.09.2024 SB2024091087
#VU93513 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2024-6387
CWE-362 High
Public exploit available
No
6.4.15, 7.0.13, 7.2.6, 7.4.4 01.07.2024 SB2024070144
SB2024070145
SB2024070152
and 89 more
#VU87527 - Use of Externally-Controlled Format String
CVE-2023-41842
CWE-134 Low
No
No
7.0.10, 7.2.4, 7.4.2 14.03.2024 SB2024031434
#VU84860 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2023-25606
CWE-22 Medium
No
No
6.4.12, 7.0.7, 7.2.2 29.12.2023 SB2023122909
#VU81962 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2023-25607
CWE-78 Low
No
No
6.4.12, 7.0.8, 7.2.3, 7.4.0 12.10.2023 SB2023101254
#VU81960 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2023-42788
CWE-78 Low
No
No
6.2.12, 6.4.13, 7.0.9, 7.2.4, 7.4.1 12.10.2023 SB2023101257
#VU81959 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2023-41838
CWE-22 Low
No
No
6.2.12, 6.4.13, 7.0.9, 7.2.4, 7.4.1 12.10.2023 SB2023101257
#VU81958 - Client-Side Enforcement of Server-Side Security
CVE-2023-42787
CWE-602 Medium
No
No
7.2.4, 7.4.1 12.10.2023 SB2023101256
#VU81957 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2023-42791
CWE-22 Medium
Public exploit available
No
6.2.12, 6.4.13, 7.0.9, 7.2.4, 7.4.1 12.10.2023 SB2023101257
#VU81956 - Authorization Bypass Through User-Controlled Key
CVE-2023-44249
CWE-639 Low
No
No
7.2.4, 7.4.1 12.10.2023 SB2023101256
#VU81954 - Insufficient Verification of Data Authenticity
CVE-2023-42782
CWE-345 Medium
No
No
7.2.4, 7.4.1 12.10.2023 SB2023101256
#VU80900 - Improper Privilege Management
CVE-2023-36638
CWE-269 Low
No
No
6.4.12, 7.0.8, 7.2.3 19.09.2023 SB2023091976
#VU75015 - Unprotected Transport of Credentials
CVE-2023-23776
CWE-523 Medium
No
No
6.4.11, 7.0.5, 7.2.2 12.04.2023 SB2023041215


Showing elements 21 - 40 out of 73