Known vulnerabilities in FortiWAN

Software: FortiWAN
Software CPE: cpe:2.3:h:fortinet:fortiwan:*:*:*:*:*:*:*:*
Total vulnerabilities: 11
Public exploits: 1
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting FortiWAN FortiWAN is affected by 11 known vulnerabilities: 3 high, 4 medium, 4 low Critical High Medium Low

Vulnerabilities (11)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU83274 - Improper Authentication
CVE-2023-44252
CWE-287 Medium
No
No
- 20.11.2023 SB2023112016
#VU83273 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2023-44251
CWE-22 Medium
No
No
- 20.11.2023 SB2023112016
#VU72363 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2022-33869
CWE-78 Medium
No
No
4.5.10 17.02.2023 SB2023021736
#VU61904 - Use of a Broken or Risky Cryptographic Algorithm
CVE-2021-32593
CWE-327 Low
No
No
4.5.9 05.04.2022 SB2022040534
#VU61903 - Stack-based buffer overflow
CVE-2021-26112
CWE-121 High
No
No
4.5.9 05.04.2022 SB2022040534
#VU61902 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2021-26114
CWE-89 High
No
No
4.5.9 05.04.2022 SB2022040534
#VU61901 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-32585
CWE-79 Low
No
No
4.5.9 05.04.2022 SB2022040534
#VU61900 - Use of Hard-coded Credentials
CVE-2021-26113
CWE-798 Low
No
No
4.5.9 05.04.2022 SB2022040534
#VU61899 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2021-24009
CWE-78 Medium
No
No
4.5.9 05.04.2022 SB2022040534
#VU54725 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2021-26115
CWE-78 Low
No
No
4.5.8 13.07.2021 SB2021071327
#VU52680 - Improper Authentication
CVE-2021-26102
CWE-287 High
Available
No
5.1.1 28.04.2021 SB2021042805