Known vulnerabilities in FortiManager - page 2

Software: FortiManager
Software CPE: cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:*
Total vulnerabilities: 112
Public exploits: 7
Known exploited (KEV): 2
Highest CVSSv4 Score: 9.4

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting FortiManager FortiManager is affected by 112 known vulnerabilities: 2 critical, 13 high, 29 medium, 68 low Critical High Medium Low

Vulnerabilities (112)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU107367 - Buffer Underwrite ('Buffer Underflow')
CVE-2024-35276
CWE-124 Medium
No
No
6.4.15, 7.0.13, 7.2.6, 7.4.4 10.04.2025 SB2025041041
#VU107364 - Missing Authentication for Critical Function
CVE-2024-35277
CWE-306 High
No
No
6.4.15, 7.0.13, 7.2.6, 7.4.3 10.04.2025 SB2025041039
#VU107362 - Improper Privilege Management
CVE-2024-45331
CWE-269 Low
No
No
7.2.6, 7.4.4 10.04.2025 SB2025041038
#VU107363 - Improper Privilege Management
CVE-2024-33503
CWE-269 Low
No
No
7.2.6, 7.4.4 10.04.2025 SB2025041038
#VU107359 - Out-of-bounds write
CVE-2024-35273
CWE-787 Low
No
No
7.4.3 10.04.2025 SB2025041036
#VU107358 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2024-35275
CWE-89 Low
No
No
7.4.3 10.04.2025 SB2025041035
#VU107312 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2024-40584
CWE-78 Low
No
No
7.2.6, 7.4.4 09.04.2025 SB2025040977
#VU107311 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2024-36508
CWE-22 Low
No
No
7.2.6, 7.4.3 09.04.2025 SB2025040976
#VU107310 - Use of Hard-coded Cryptographic Key
CVE-2024-33504
CWE-321 Low
No
No
7.2.10, 7.4.6, 7.6.2 09.04.2025 SB2025040975
#VU107295 - Improper Output Neutralization for Logs
CVE-2024-52962
CWE-117 Medium
No
No
7.0.14, 7.2.9, 7.4.6, 7.6.2 09.04.2025 SB2025040962
#VU107250 - Improper Restriction of Communication Channel to Intended Endpoints
CVE-2024-50565
CWE-923 High
No
No
6.2.14, 6.4.15, 7.0.12, 7.2.5, 7.4.3 09.04.2025 SB2025040907
SB2025040908
SB2025040909
and 3 more
#VU107249 - Improper Restriction of Communication Channel to Intended Endpoints
CVE-2024-26013
CWE-923 High
No
No
6.2.14, 6.4.15, 7.0.12, 7.2.5, 7.4.3 09.04.2025 SB2025040907
SB2025040908
SB2025040909
and 3 more
#VU105614 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2024-33501
CWE-89 Low
No
No
7.2.6, 7.4.3 11.03.2025 SB20250311116
#VU105613 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2024-32123
CWE-78 Low
No
No
7.2.6, 7.4.4 11.03.2025 SB20250311115
#VU103834 - Information Exposure Through Log Files
CVE-2024-40585
CWE-532 Medium
No
No
7.0.9, 7.2.4, 7.4.1 11.02.2025 SB20250211166
SB20250211167
#VU102875 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2024-48885
CWE-22 Medium
No
No
7.4.4, 7.6.2 16.01.2025 SB2025011650
SB2025011651
SB2025011652
and 3 more
#VU102874 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2024-48884
CWE-22 Low
No
No
7.4.4, 7.6.2 16.01.2025 SB2025011650
SB2025011651
SB2025011652
and 3 more
#VU102600 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2024-33502
CWE-22 Low
No
No
7.2.6, 7.4.3 14.01.2025 SB2025011439
#VU102599 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2024-36512
CWE-22 Low
No
No
7.0.13, 7.2.6, 7.4.4 14.01.2025 SB2025011438
#VU102598 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2024-32115
CWE-22 Low
No
No
7.2.6, 7.4.3 14.01.2025 SB2025011437


Showing elements 21 - 40 out of 112