Known vulnerabilities in FortiOS - page 4
Vendor:
Fortinet, Inc
Software:
FortiOS
Software CPE:
cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*
Website:
https://www.fortinet.com/
Total vulnerabilities:
290
Public exploits:
24
Known exploited (KEV):
22
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
7.6.7
7.4.12
7.4.10
7.0.19
7.2.13
7.4.11
7.6.6
6.4.17
7.6.5
7.0.18
7.4.9
7.6.4
7.2.12
7.4.8
7.6.3
6.2.17
6.4.16
7.2.11
7.6.2
7.4.7
7.0.17
7.4.6
7.6.1
7.6.0
7.4.5
7.0.16
7.2.10
7.2.9
7.4.4
7.0.15
7.2.8
6.0.18
7.4.3
6.4.15
7.0.14
6.2.16
7.2.7
7.4.2
7.0.13
7.4.1
7.2.6
6.4.14
7.0.12
6.0.17
6.2.15
7.2.5
6.2.14
6.4.13
7.0.11
7.4.0
7.0.10
6.2.13
6.4.12
7.2.4
6.0.16
7.0.9
7.2.3
6.2.12
6.4.11
7.0.8
7.0.7
7.2.2
6.4.10
7.2.1
6.0.15
6.2.11
7.0.6
6.4.9
7.2.0
7.0.5
7.0.4
6.0.14
6.4.8
7.0.3
5.6.14
6.2.10
7.0.2
6.2.9
6.2.8
6.4.7
6.0.13
7.0.1
7.0.0
6.4.6
6.4.5
6.4.4
6.4.3
5.4.13
6.0.12
6.0.8
6.2.7
6.2.6
6.4.2
6.0.11
5.6.13
5.6.12
6.2.5
4.3.17
6.0.9
6.4.0
6.4.1
6.0.10
6.2.4
6.2.3
6.0.7
5.6.11
5.6.10
5.4.12
5.2.15
5.2.14
6.2.2
6.2.1
6.0.6
6.2.0
6.0.5
6.0.4
5.6.9
5.6.8
5.6.7
5.6.6
5.6.5
5.4.11
5.4.10
5.0.14
6.0.3
6.0.2
5.6.4
6.0.1
6.0.0
5.4.9
5.4.8
5.4.7
5.2.13
5.6.3
5.4.6
5.2.12
5.6.2
5.6.1
5.6.0
5.4.5
5.4.4
5.4.3
5.2.11
5.4.2
5.4.1
5.2.4
5.2.10
5.2.9
5.2.8
5.2.7
5.2.6
5.4
4.3.16
5.2.5
4.3.13
4.3.14
4.3.15
4.3.12
4.3.10
5.0
3.0
2.36
2.5 0mr4
3.0 beta
2.80
2.50 mr5
2.50
3.0 mr1
3 beta
2.8 mr10
4.3.9
4.3.8
4.3.7
4.3.6
4.3.5
4.3.4
4.3.3
4.3.2
4.3.1
4.3.0
4.2.13
4.2.12
4.2.11
4.2.10
4.2.9
4.2.8
4.2.7
4.2.6
4.2.5
4.2.4
4.2.3
4.2.2
4.2.1
4.2.0
4.1.11
4.1.10
4.1.9
4.1.8
4.1.7
4.1.6
4.1.5
4.1.4
4.1.3
4.1.2
4.1.1
4.1.0
5.4.0
5.2.3
5.2.2
5.2.1
5.2.0
5.0.13
5.0.12
5.0.11
5.0.10
5.0.9
5.0.8
5.0.7
5.0.6
5.0.5
5.0.4
5.0.3
5.0.2
5.0.1
5.0.0
Vulnerabilities (290)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU111041 - Exposure of sensitive information to an unauthorized actor CVE-2025-25250 |
CWE-200 | Low | 7.4.8, 7.6.1 | 11.06.2025 |
SB2025061106 |
||
| #VU109045 - Missing Authentication for Critical Function CVE-2025-22252 |
CWE-306 | High | 7.4.7, 7.6.1 | 13.05.2025 |
SB2025051366 |
||
| #VU109041 - Integer overflow CVE-2025-47294 |
CWE-190 | Medium | 7.0.15, 7.2.8 | 13.05.2025 |
SB2025051361 |
||
| #VU109040 - Buffer over-read CVE-2025-47295 |
CWE-126 | Low | 7.0.15, 7.2.8, 7.4.4 | 13.05.2025 |
SB2025051360 |
||
| #VU107376 - Allocation of Resources Without Limits or Throttling CVE-2024-46666 |
CWE-770 | Medium | 7.4.5, 7.6.1 | 11.04.2025 |
SB2025041107 |
||
| #VU107372 - Weak Authentication CVE-2024-50563 |
CWE-1390 | High | 7.0.16, 7.2.9, 7.4.5 | 10.04.2025 |
SB2025041046 |
||
| #VU107373 - Weak Authentication CVE-2024-48886 |
CWE-1390 | High | 7.0.16, 7.2.9, 7.4.5 | 10.04.2025 |
SB2025041046 |
||
| #VU107371 - Allocation of Resources Without Limits or Throttling CVE-2024-46668 |
CWE-770 | Medium | 6.4.16, 7.0.16, 7.2.9, 7.4.5 | 10.04.2025 |
SB2025041045 |
||
| #VU107346 - NULL Pointer Dereference CVE-2024-36504 |
CWE-476 | Medium | 7.2.9, 7.4.5 | 10.04.2025 |
SB2025041026 |
||
| #VU107321 - Origin Validation Error CVE-2023-46715 |
CWE-346 | Low | 7.4.2 | 09.04.2025 |
SB2025040986 |
||
| #VU107320 - NULL Pointer Dereference CVE-2023-42786 |
CWE-476 | Medium | 7.2.6, 7.4.2 | 09.04.2025 |
SB2025040985 |
||
| #VU107319 - NULL Pointer Dereference CVE-2023-42785 |
CWE-476 | Medium | 7.2.6, 7.4.2 | 09.04.2025 |
SB2025040985 |
||
| #VU107296 - Insufficiently Protected Credentials CVE-2024-32122 |
CWE-522 | Low | 7.6.0 | 09.04.2025 |
SB2025040963 |
||
| #VU107250 - Improper Restriction of Communication Channel to Intended Endpoints CVE-2024-50565 |
CWE-923 | High | 6.2.17, 7.0.16, 7.2.9, 7.4.5 | 09.04.2025 |
SB2025040907 SB2025040908 SB2025040909 and 3 more |
||
| #VU107249 - Improper Restriction of Communication Channel to Intended Endpoints CVE-2024-26013 |
CWE-923 | High | 6.2.17, 7.0.16, 7.2.9, 7.4.5 | 09.04.2025 |
SB2025040907 SB2025040908 SB2025040909 and 3 more |
||
| #VU105622 - Use of Externally-Controlled Format String CVE-2024-45324 |
CWE-134 | Low | 6.4.16, 7.0.16, 7.2.10, 7.4.5 | 12.03.2025 |
SB2025031208 SB2025031209 SB2025031210 and 2 more |
||
| #VU103885 - Use of Externally-Controlled Format String CVE-2023-40721 |
CWE-134 | Low | 7.2.7, 7.4.2 | 12.02.2025 |
SB2025021205 SB2025021206 SB2025021207 and 1 more |
||
| #VU103835 - Incorrect Privilege Assignment CVE-2024-40591 |
CWE-266 | Low | 7.0.16, 7.2.10, 7.4.5, 7.6.1 | 11.02.2025 |
SB20250211168 |
||
| #VU103797 - Stack-based buffer overflow CVE-2024-35279 |
CWE-121 | Critical | 7.2.9, 7.4.5 | 11.02.2025 |
SB20250211102 |
||
| #VU103246 - Out-of-bounds write CVE-2024-52963 |
CWE-787 | Low | 7.6.1 | 22.01.2025 |
SB2025012295 |
Showing elements 61 - 80 out of 290