Known vulnerabilities in FortiOS - page 3

Software: FortiOS
Software CPE: cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*
Total vulnerabilities: 286
Public exploits: 24
Known exploited (KEV): 21
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting FortiOS FortiOS is affected by 286 known vulnerabilities: 13 critical, 32 high, 106 medium, 135 low Critical High Medium Low

Vulnerabilities (286)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU117133 - Improperly Implemented Security Check for Standard
CVE-2025-25255
CWE-358 Low
No
No
7.6.4 14.10.2025 SB20251014105
#VU117130 - Improper Check or Handling of Exceptional Conditions
CVE-2024-26008
CWE-703 Medium
No
No
7.2.8, 7.4.4 14.10.2025 SB20251014102
#VU113970 - Incorrect Privilege Assignment
CVE-2025-53744
CWE-266 Low
No
No
7.4.8, 7.6.3 12.08.2025 SB20250812105
#VU113960 - Integer overflow
CVE-2025-25248
CWE-190 Low
No
No
7.2.11, 7.4.8, 7.6.3 12.08.2025 SB2025081299
#VU113958 - Authentication Bypass Using an Alternate Path or Channel
CVE-2024-26009
CWE-288 High
No
No
6.2.17, 6.4.16 12.08.2025 SB2025081297
#VU113906 - Double Free
CVE-2023-45584
CWE-415 Low
No
No
7.0.13, 7.2.6, 7.4.1 12.08.2025 SB2025081281
#VU112497 - Heap-based Buffer Overflow
CVE-2025-24477
CWE-122 Low
No
No
7.2.12, 7.4.8, 7.6.3 08.07.2025 SB2025070845
#VU112496 - Missing Critical Step in Authentication
CVE-2024-52965
CWE-304 Low
No
No
7.0.17, 7.2.11, 7.4.6, 7.6.3 08.07.2025 SB2025070844
#VU112495 - Improperly Implemented Security Check for Standard
CVE-2024-55599
CWE-358 Medium
No
No
7.2.11, 7.4.8, 7.6.1 08.07.2025 SB2025070843
#VU111054 - Improper Privilege Management
CVE-2025-22254
CWE-269 High
No
No
6.4.16, 7.0.17, 7.2.11, 7.4.7, 7.6.2 11.06.2025 SB2025061119
#VU111051 - Improper Certificate Validation
CVE-2025-24471
CWE-295 Low
No
No
7.4.8, 7.6.2 11.06.2025 SB2025061116
#VU111050 - Authentication Bypass Using an Alternate Path or Channel
CVE-2025-22862
CWE-288 Low
No
No
7.4.8 11.06.2025 SB2025061115
#VU111048 - Insufficient Session Expiration
CVE-2024-50562
CWE-613 Medium
No
No
7.2.11, 7.4.8, 7.6.1 11.06.2025 SB2025061113
#VU111047 - Improper Restriction of Communication Channel to Intended Endpoints
CVE-2025-22251
CWE-923 Low
No
No
7.4.6, 7.6.1 11.06.2025 SB2025061112
#VU111045 - Channel Accessible by Non-Endpoint ('Man-in-the-Middle')
CVE-2024-50568
CWE-300 Medium
No
No
7.2.9, 7.4.4 11.06.2025 SB2025061110
#VU111042 - Incomplete cleanup
CVE-2023-29184
CWE-459 Low
No
No
- 11.06.2025 SB2025061107
#VU111041 - Exposure of sensitive information to an unauthorized actor
CVE-2025-25250
CWE-200 Low
No
No
7.4.8, 7.6.1 11.06.2025 SB2025061106
#VU109045 - Missing Authentication for Critical Function
CVE-2025-22252
CWE-306 High
No
No
7.4.7, 7.6.1 13.05.2025 SB2025051366
#VU109041 - Integer overflow
CVE-2025-47294
CWE-190 Medium
No
No
7.0.15, 7.2.8 13.05.2025 SB2025051361
#VU109040 - Buffer over-read
CVE-2025-47295
CWE-126 Low
No
No
7.0.15, 7.2.8, 7.4.4 13.05.2025 SB2025051360


Showing elements 41 - 60 out of 286