Known vulnerabilities in FortiManager - page 3

Software: FortiManager
Software CPE: cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:*
Total vulnerabilities: 112
Public exploits: 7
Known exploited (KEV): 2
Highest CVSSv4 Score: 9.4

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting FortiManager FortiManager is affected by 112 known vulnerabilities: 2 critical, 13 high, 29 medium, 68 low Critical High Medium Low

Vulnerabilities (112)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU102597 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2024-46662
CWE-78 Low
No
No
7.4.4 14.01.2025 SB2025011436
#VU102596 - Operation on a Resource after Expiration or Release
CVE-2024-47571
CWE-672 Medium
No
No
6.4.13, 7.0.9, 7.2.4, 7.4.1 14.01.2025 SB2025011436
#VU101832 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2024-48889
CWE-78 Low
No
No
6.4.15, 7.0.13, 7.2.8, 7.4.5, 7.6.1 18.12.2024 SB2024121834
#VU100783 - Stack-based buffer overflow
CVE-2024-31496
CWE-121 Low
No
No
7.2.6, 7.4.3 21.11.2024 SB2024112169
SB2024112170
#VU100782 - Client-Side Enforcement of Server-Side Security
CVE-2024-23666
CWE-602 Medium
Available
No
6.4.15, 7.0.13, 7.2.6, 7.4.3 21.11.2024 SB2024112167
SB2024112168
#VU100460 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2024-35274
CWE-22 Low
No
No
7.4.3 14.11.2024 SB2024111414
SB2024111415
#VU100455 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2024-32118
CWE-78 Low
No
No
7.2.6, 7.4.3 14.11.2024 SB2024111412
SB2024111413
#VU100453 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2024-32117
CWE-22 Low
No
No
7.2.6, 7.4.3 14.11.2024 SB2024111409
SB2024111410
#VU100452 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2024-32116
CWE-22 Low
No
No
7.2.6, 7.4.3 14.11.2024 SB2024111404
SB2024111405
#VU100450 - Improper Access Control
CVE-2023-44255
CWE-284 Low
No
No
7.4.3 14.11.2024 SB2024111401
SB2024111402
#VU100413 - Heap-based Buffer Overflow
CVE-2024-33505
CWE-122 High
No
No
7.2.6, 7.4.3 12.11.2024 SB20241112168
SB20241112169
#VU100401 - Improper Authentication
CVE-2024-26011
CWE-287 Medium
No
No
6.4.15, 7.0.12, 7.2.5, 7.4.3 12.11.2024 SB20241112152
SB20241112154
SB20241112155
and 3 more
#VU99287 - Missing Authentication for Critical Function
CVE-2024-47575
CWE-306 Critical
Available
Exploited
6.2.13, 6.4.15, 7.0.13, 7.2.8, 7.4.5, 7.6.1 23.10.2024 SB2024102360
#VU98148 - Improper Access Control
CVE-2024-33506
CWE-284 Low
No
No
7.2.6, 7.4.3 08.10.2024 SB2024100850
#VU97007 - Improper Access Control
CVE-2023-44254
CWE-284 Low
No
No
7.2.5, 7.4.1 10.09.2024 SB2024091087
#VU96015 - Unverified Password Change
CVE-2024-21757
CWE-620 Low
No
No
7.0.11, 7.2.5, 7.4.2 14.08.2024 SB2024081476
#VU93513 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2024-6387
CWE-362 High
Available
No
6.4.15, 7.0.13, 7.2.6, 7.4.4 01.07.2024 SB2024070144
SB2024070145
SB2024070152
and 89 more
#VU88236 - Improper Control of Generation of Code ('Code Injection')
CVE-2023-47542
CWE-94 Low
No
No
7.0.11, 7.2.5, 7.4.2 09.04.2024 SB2024040957
#VU87527 - Use of Externally-Controlled Format String
CVE-2023-41842
CWE-134 Low
No
No
7.0.10, 7.2.4, 7.4.2 14.03.2024 SB2024031434
#VU87526 - Improper Access Control
CVE-2023-36554
CWE-284 High
No
No
6.4.14, 7.0.11, 7.2.4, 7.4.1 14.03.2024 SB2024031433


Showing elements 41 - 60 out of 112