Page 54 of 797 results (0.012 seconds)

CVSS: 7.0EPSS: 0%CPEs: 3EXPL: 0

An unauthorized configuration download vulnerability in FortiWeb 6.3.6 through 6.3.21, 6.4.0 through 6.4.2 and 7.0.0 through 7.0.4 may allow a local attacker to access confidential configuration files via a crafted http request. • https://fortiguard.com/psirt/FG-IR-22-460 • CWE-285: Improper Authorization •

CVSS: 8.8EPSS: 0%CPEs: 14EXPL: 0

An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in the management interface of FortiWAN 4.0.0 through 4.5.9 may allow an authenticated attacker to execute unauthorized commands via specifically crafted arguments to existing commands. • https://fortiguard.com/psirt/FG-IR-22-157 • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •

CVSS: 3.3EPSS: 0%CPEs: 11EXPL: 0

A missing cryptographic steps vulnerability [CWE-325] in the functions that encrypt the DHCP and DNS keys in Fortinet FortiOS version 7.2.0, 7.0.0 through 7.0.5, 6.4.0 through 6.4.9, 6.2.x and 6.0.x may allow an attacker in possession of the encrypted key to decipher it. • https://fortiguard.com/psirt/FG-IR-22-080 • CWE-329: Generation of Predictable IV with CBC Mode •

CVSS: 7.5EPSS: 0%CPEs: 7EXPL: 0

A use of password hash with insufficient computational effort vulnerability [CWE-916] in FortiSandbox before 4.2.0 may allow an attacker with access to the password database to efficiently mount bulk guessing attacks to recover the passwords. • https://fortiguard.com/psirt/FG-IR-20-220 • CWE-916: Use of Password Hash With Insufficient Computational Effort •

CVSS: 7.1EPSS: 0%CPEs: 9EXPL: 0

Several improper neutralization of inputs during web page generation vulnerability [CWE-79] in FortiNAC 9.4.1 and below, 9.2.6 and below, 9.1.8 and below, 8.8.11 and below, 8.7.6 and below, 8.6.5 and below, 8.5.4 and below, 8.3.7 and below may allow an authenticated attacker to perform several XSS attacks via crafted HTTP GET requests. • https://fortiguard.com/psirt/FG-IR-22-260 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •