![](/assets/img/cve_300x82_sin_bg.png)
CVE-2024-23107
https://notcve.org/view.php?id=CVE-2024-23107
03 Jun 2024 — An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiWeb version 7.4.0, version 7.2.4 and below, version 7.0.8 and below, 6.3 all versions may allow an authenticated attacker to read password hashes of other administrators via CLI commands. Una exposición de información confidencial a una vulnerabilidad de actor no autorizado [CWE-200] en FortiWeb versión 7.4.0, versión 7.2.4 e inferiores, versión 7.0.8 e inferiores, 6.3 todas las versiones puede permitir que un atac... • https://fortiguard.fortinet.com/psirt/FG-IR-23-191 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2023-36640
https://notcve.org/view.php?id=CVE-2023-36640
14 May 2024 — A use of externally-controlled format string in Fortinet FortiProxy versions 7.2.0 through 7.2.4, 7.0.0 through 7.0.10, 2.0.0 through 2.0.13, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6, 1.0.0 through 1.0.7, FortiPAM versions 1.0.0 through 1.0.3, FortiOS versions 7.2.0, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, 6.0.0 through 6.0.16 allows attacker to execute unauthorized code or commands via specially crafted commands Un uso de cadena de formato controlada externamente en las versiones... • https://fortiguard.com/psirt/FG-IR-23-137 • CWE-134: Use of Externally-Controlled Format String •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2023-45583
https://notcve.org/view.php?id=CVE-2023-45583
14 May 2024 — A use of externally-controlled format string in Fortinet FortiProxy versions 7.2.0 through 7.2.5, 7.0.0 through 7.0.11, 2.0.0 through 2.0.13, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6 FortiPAM versions 1.1.0, 1.0.0 through 1.0.3 FortiOS versions 7.4.0, 7.2.0 through 7.2.5, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15 FortiSwitchManager versions 7.2.0 through 7.2.2, 7.0.0 through 7.0.2 allows attacker to execute unauthorized code or commands via specially crafted cli commands and http req... • https://fortiguard.com/psirt/FG-IR-23-137 • CWE-134: Use of Externally-Controlled Format String •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2024-23105
https://notcve.org/view.php?id=CVE-2024-23105
14 May 2024 — A Use Of Less Trusted Source [CWE-348] vulnerability in Fortinet FortiPortal version 7.0.0 through 7.0.6 and version 7.2.0 through 7.2.1 allows an unauthenticated attack to bypass IP protection through crafted HTTP or HTTPS packets. Una vulnerabilidad de uso de fuente menos confiable [CWE-348] en Fortinet FortiPortal versión 7.0.0 a 7.0.6 y versión 7.2.0 a 7.2.1 permite que un ataque no autenticado evite la protección IP a través de paquetes HTTP o HTTPS manipulados. • https://fortiguard.com/psirt/FG-IR-24-021 • CWE-348: Use of Less Trusted Source •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2023-50180
https://notcve.org/view.php?id=CVE-2023-50180
14 May 2024 — An exposure of sensitive system information to an unauthorized control sphere vulnerability [CWE-497] in FortiADC version 7.4.1 and below, version 7.2.3 and below, version 7.1.4 and below, version 7.0.5 and below, version 6.2.6 and below may allow a read-only admin to view data pertaining to other admins. Una exposición de información confidencial del sistema a una vulnerabilidad de esfera de control no autorizada [CWE-497] en FortiADC versión 7.4.1 e inferior, versión 7.2.3 e inferior, versión 7.1.4 e infe... • https://fortiguard.com/psirt/FG-IR-23-433 • CWE-497: Exposure of Sensitive System Information to an Unauthorized Control Sphere •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2023-46714
https://notcve.org/view.php?id=CVE-2023-46714
14 May 2024 — A stack-based buffer overflow [CWE-121] vulnerability in Fortinet FortiOS version 7.2.1 through 7.2.6 and version 7.4.0 through 7.4.1 allows a privileged attacker over the administrative interface to execute arbitrary code or commands via crafted HTTP or HTTPs requests. Una vulnerabilidad de desbordamiento de búfer en la región stack de la memoria [CWE-121] en Fortinet FortiOS versión 7.2.1 a 7.2.6 y versión 7.4.0 a 7.4.1 permite a un atacante privilegiado sobre la interfaz administrativa ejecutar código o ... • https://fortiguard.com/psirt/FG-IR-23-415 • CWE-121: Stack-based Buffer Overflow •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2023-44247
https://notcve.org/view.php?id=CVE-2023-44247
14 May 2024 — A double free vulnerability [CWE-415] in Fortinet FortiOS before 7.0.0 may allow a privileged attacker to execute code or commands via crafted HTTP or HTTPs requests. Una doble vulnerabilidad gratuita [CWE-415] en Fortinet FortiOS anterior a 7.0.0 puede permitir a un atacante privilegiado ejecutar código o comandos a través de solicitudes HTTP o HTTPs manipuladas. • https://fortiguard.com/psirt/FG-IR-23-195 • CWE-415: Double Free •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2023-40720
https://notcve.org/view.php?id=CVE-2023-40720
14 May 2024 — An authorization bypass through user-controlled key vulnerability [CWE-639] in FortiVoiceEntreprise version 7.0.0 through 7.0.1 and before 6.4.8 allows an authenticated attacker to read the SIP configuration of other users via crafted HTTP or HTTPS requests. Una omisión de autorización a través de una vulnerabilidad de clave controlada por el usuario [CWE-639] en FortiVoiceEntreprise versión 7.0.0 a 7.0.1 y anteriores a 6.4.8 permite a un atacante autenticado leer la configuración SIP de otros usuarios a tr... • https://fortiguard.com/psirt/FG-IR-23-282 • CWE-639: Authorization Bypass Through User-Controlled Key •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2023-45586
https://notcve.org/view.php?id=CVE-2023-45586
14 May 2024 — An insufficient verification of data authenticity vulnerability [CWE-345] in Fortinet FortiOS SSL-VPN tunnel mode version 7.4.0 through 7.4.1, version 7.2.0 through 7.2.7 and before 7.0.12 & FortiProxy SSL-VPN tunnel mode version 7.4.0 through 7.4.1, version 7.2.0 through 7.2.7 and before 7.0.13 allows an authenticated VPN user to send (but not receive) packets spoofing the IP of another user via crafted network packets. Una verificación insuficiente de la vulnerabilidad de autenticidad de datos [CWE-345] e... • https://fortiguard.com/psirt/FG-IR-23-225 • CWE-345: Insufficient Verification of Data Authenticity •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2024-26007
https://notcve.org/view.php?id=CVE-2024-26007
14 May 2024 — An improper check or handling of exceptional conditions vulnerability [CWE-703] in Fortinet FortiOS version 7.4.1 allows an unauthenticated attacker to provoke a denial of service on the administrative interface via crafted HTTP requests. Una verificación o manejo inadecuado de la vulnerabilidad de condiciones excepcionales [CWE-703] en Fortinet FortiOS versión 7.4.1 permite que un atacante no autenticado provoque una denegación de servicio en la interfaz administrativa a través de solicitudes HTTP manipula... • https://fortiguard.com/psirt/FG-IR-24-017 • CWE-703: Improper Check or Handling of Exceptional Conditions •