Known vulnerabilities in FortiOS - page 4

Software: FortiOS
Software CPE: cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*
Total vulnerabilities: 286
Public exploits: 24
Known exploited (KEV): 21
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting FortiOS FortiOS is affected by 286 known vulnerabilities: 13 critical, 32 high, 106 medium, 135 low Critical High Medium Low

Vulnerabilities (286)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU107376 - Allocation of Resources Without Limits or Throttling
CVE-2024-46666
CWE-770 Medium
No
No
7.4.5, 7.6.1 11.04.2025 SB2025041107
#VU107372 - Weak Authentication
CVE-2024-50563
CWE-1390 High
No
No
7.0.16, 7.2.9, 7.4.5 10.04.2025 SB2025041046
#VU107373 - Weak Authentication
CVE-2024-48886
CWE-1390 High
No
No
7.0.16, 7.2.9, 7.4.5 10.04.2025 SB2025041046
#VU107371 - Allocation of Resources Without Limits or Throttling
CVE-2024-46668
CWE-770 Medium
No
No
6.4.16, 7.0.16, 7.2.9, 7.4.5 10.04.2025 SB2025041045
#VU107346 - NULL Pointer Dereference
CVE-2024-36504
CWE-476 Medium
Available
No
7.2.9, 7.4.5 10.04.2025 SB2025041026
#VU107321 - Origin Validation Error
CVE-2023-46715
CWE-346 Low
No
No
7.4.2 09.04.2025 SB2025040986
#VU107320 - NULL Pointer Dereference
CVE-2023-42786
CWE-476 Medium
No
No
7.2.6, 7.4.2 09.04.2025 SB2025040985
#VU107319 - NULL Pointer Dereference
CVE-2023-42785
CWE-476 Medium
No
No
7.2.6, 7.4.2 09.04.2025 SB2025040985
#VU107296 - Insufficiently Protected Credentials
CVE-2024-32122
CWE-522 Low
No
No
7.6.0 09.04.2025 SB2025040963
#VU107250 - Improper Restriction of Communication Channel to Intended Endpoints
CVE-2024-50565
CWE-923 High
No
No
6.2.17, 7.0.16, 7.2.9, 7.4.5 09.04.2025 SB2025040907
SB2025040908
SB2025040909
and 3 more
#VU107249 - Improper Restriction of Communication Channel to Intended Endpoints
CVE-2024-26013
CWE-923 High
No
No
6.2.17, 7.0.16, 7.2.9, 7.4.5 09.04.2025 SB2025040907
SB2025040908
SB2025040909
and 3 more
#VU105622 - Use of Externally-Controlled Format String
CVE-2024-45324
CWE-134 Low
No
No
6.4.16, 7.0.16, 7.2.10, 7.4.5 12.03.2025 SB2025031208
SB2025031209
SB2025031210
and 2 more
#VU103885 - Use of Externally-Controlled Format String
CVE-2023-40721
CWE-134 Low
No
No
7.2.7, 7.4.2 12.02.2025 SB2025021205
SB2025021206
SB2025021207
and 1 more
#VU103835 - Incorrect Privilege Assignment
CVE-2024-40591
CWE-266 Low
No
No
7.0.16, 7.2.10, 7.4.5, 7.6.1 11.02.2025 SB20250211168
#VU103797 - Stack-based buffer overflow
CVE-2024-35279
CWE-121 Critical
No
No
7.2.9, 7.4.5 11.02.2025 SB20250211102
#VU103246 - Out-of-bounds write
CVE-2024-52963
CWE-787 Low
No
No
7.6.1 22.01.2025 SB2025012295
#VU102875 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2024-48885
CWE-22 Medium
No
No
7.0.16, 7.2.10, 7.4.5, 7.6.1 16.01.2025 SB2025011650
SB2025011651
SB2025011652
and 3 more
#VU102874 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2024-48884
CWE-22 Low
No
No
7.0.16, 7.2.10, 7.4.5, 7.6.1 16.01.2025 SB2025011650
SB2025011651
SB2025011652
and 3 more
#VU102827 - Out-of-bounds read
CVE-2024-46670
CWE-125 Medium
No
No
7.2.10, 7.4.5, 7.6.1 15.01.2025 SB2025011590
#VU102825 - Integer overflow
CVE-2024-46669
CWE-190 Low
No
No
7.4.5 15.01.2025 SB2025011589


Showing elements 61 - 80 out of 286