Known vulnerabilities in FortiVoice

Software: FortiVoice
Software CPE: cpe:2.3:a:fortinet:fortivoice:*:*:*:*:*:*:*:*
Total vulnerabilities: 23
Public exploits: 3
Known exploited (KEV): 1
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting FortiVoice FortiVoice is affected by 23 known vulnerabilities: 1 critical, 5 high, 7 medium, 10 low Critical High Medium Low

Vulnerabilities (23)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU125992 - Exposure of sensitive information to an unauthorized actor
CVE-2024-23104
CWE-200 Low
No
No
7.0.2 14.04.2026 SB20260414115
#VU123715 - Cleartext Storage of Sensitive Information
CVE-2025-55717
CWE-312 Low
No
No
7.0.7, 7.2.1 10.03.2026 SB2026031077
#VU121225 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2025-58693
CWE-22 Low
No
No
7.0.8, 7.2.3 13.01.2026 SB2026011364
#VU119443 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2025-60024
CWE-22 Medium
No
No
7.0.8, 7.2.3 09.12.2025 SB2025120953
#VU119428 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2025-64156
CWE-89 Low
No
No
7.0.8, 7.2.3 09.12.2025 SB2025120944
#VU118607 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2025-58692
CWE-89 Medium
No
No
7.0.8, 7.2.3 18.11.2025 SB2025111876
#VU117148 - Insertion of Sensitive Information Into Sent Data
CVE-2024-47569
CWE-201 Low
No
No
6.4.10, 7.0.5 15.10.2025 SB2025101507
#VU113959 -
CVE-2024-40588
Low
No
No
6.4.10, 7.0.5 12.08.2025 SB2025081298
#VU112498 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2025-47856
CWE-78 High
No
No
6.4.11, 7.0.7, 7.2.1 08.07.2025 SB2025070846
#VU109101 - Stack-based buffer overflow
CVE-2025-32756
CWE-121 Critical
Available
Exploited
6.4.11, 7.0.7, 7.2.1 13.05.2025 SB20250513104
#VU107378 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2024-40587
CWE-78 Low
No
No
6.4.10, 7.0.5 11.04.2025 SB2025041109
#VU107250 - Improper Restriction of Communication Channel to Intended Endpoints
CVE-2024-50565
CWE-923 High
No
No
6.4.9, 7.0.3 09.04.2025 SB2025040907
SB2025040908
SB2025040909
and 3 more
#VU107249 - Improper Restriction of Communication Channel to Intended Endpoints
CVE-2024-26013
CWE-923 High
No
No
6.4.9, 7.0.3 09.04.2025 SB2025040907
SB2025040908
SB2025040909
and 3 more
#VU102875 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2024-48885
CWE-22 Medium
No
No
6.4.10, 7.0.5 16.01.2025 SB2025011650
SB2025011651
SB2025011652
and 3 more
#VU102874 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2024-48884
CWE-22 Low
No
No
6.4.10, 7.0.5 16.01.2025 SB2025011650
SB2025011651
SB2025011652
and 3 more
#VU102680 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2023-37931
CWE-89 Medium
No
No
6.4.9, 7.0.2 14.01.2025 SB2025011462
#VU93513 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2024-6387
CWE-362 High
Available
No
6.4.10, 7.0.3 01.07.2024 SB2024070144
SB2024070145
SB2024070152
and 89 more
#VU89597 - Authorization Bypass Through User-Controlled Key
CVE-2023-40720
CWE-639 Low
No
No
6.4.9, 7.0.2 16.05.2024 SB2024051625
#VU85214 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2023-37932
CWE-22 Medium
No
No
6.4.8, 7.0.1 09.01.2024 SB2024010975
#VU84453 - Cross-Site Request Forgery (CSRF)
CVE-2022-27488
CWE-352 Medium
No
No
6.0.12, 6.4.8 15.12.2023 SB2023121510
SB2023121511
SB2023121512
and 2 more


Showing elements 1 - 20 out of 23