Fortinet
Fortinet Fortiportal: vulnerabilidades y CVE
Fortinet Fortiportal tiene 45 vulnerabilidades publicadas, 3 de ellas en los últimos 12 meses. 5 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE45
Últimos 12 meses3
Críticas5
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-49938 | Media (6.5) | 0.34% | — | 9 jun 2026 | A improper access control vulnerability in Fortinet FortiPortal 7.4.0 through 7.4.7, FortiPortal 7.2.0 through 7.2.8, FortiPortal 7.0 all versions may allow attacker to improper access control via <insert attack vector… |
| CVE-2024-40593 | Media (4.4) | 0.11% | — | 11 dic 2025 | A key management errors vulnerability in Fortinet FortiAnalyzer 7.4.0 through 7.4.2, FortiAnalyzer 7.2.0 through 7.2.5, FortiAnalyzer 7.0 all versions, FortiAnalyzer 6.4 all versions, FortiManager 7.4.0 through 7.4.2,… |
| CVE-2025-54838 | Media (6.5) | 0.31% | — | 9 dic 2025 | An Incorrect Authorization vulnerability [CWE-863] in FortiPortal 7.4.0 through 7.4.5 may allow an authenticated attacker to reboot a shared FortiGate device via crafted HTTP requests. |
| CVE-2024-45329 | Media (4.3) | 0.32% | — | 10 jun 2025 | A authorization bypass through user-controlled key in Fortinet FortiPortal versions 7.4.0, versions 7.2.0 through 7.2.5, and versions 7.0.0 through 7.0.8 may allow an authenticated attacker to view unauthorized device… |
| CVE-2025-46777 | Baja (2.7) | 0.24% | — | 28 may 2025 | A insertion of sensitive information into log file in Fortinet FortiPortal versions 7.4.0, versions 7.2.0 through 7.2.5, and versions 7.0.0 through 7.0.9 may allow an authenticated attacker with at least read-only admin… |
| CVE-2024-40590 | Media (4.8) | 0.16% | — | 14 mar 2025 | An improper certificate validation vulnerability [CWE-295] in FortiPortal version 7.4.0, version 7.2.4 and below, version 7.0.8 and below, version 6.0.15 and below when connecting to a FortiManager device, a… |
| CVE-2025-24470 | Alta (8.6) | 1.3% | — | 11 feb 2025 | An Improper Resolution of Path Equivalence vulnerability [CWE-41] in FortiPortal 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.11 may allow a remote unauthenticated attacker to retrieve source code via… |
| CVE-2024-52967 | Media (4.8) | 0.36% | — | 14 ene 2025 | An improper neutralization of script-related html tags in a web page (basic xss) in Fortinet FortiPortal 6.0.0 through 6.0.14 allows attacker to execute unauthorized code or commands via html injection. |
| CVE-2024-35278 | Media (4.3) | 0.37% | — | 14 ene 2025 | A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiPortal versions 7.2.4 through 7.2.0 and 7.0.0 through 7.2.8 may allow an authenticated attacker to view the SQL… |
| CVE-2021-32589 | Crítica (9.8) | 8.9% | — | 19 dic 2024 | A Use After Free (CWE-416) vulnerability in FortiManager version 7.0.0, version 6.4.5 and below, version 6.2.7 and below, version 6.0.10 and below, version 5.6.10 and below, version 5.4.7 and below, version 5.2.10 and… |
| CVE-2024-26011 | Crítica (9.8) | 0.60% | — | 12 nov 2024 | A missing authentication for critical function in Fortinet FortiManager version 7.4.0 through 7.4.2, 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through 6.4.14, FortiPAM version 1.2.0, 1.1.0 through 1.1.2, 1.0.0… |
| CVE-2023-47543 | Alta (8.1) | 0.39% | — | 12 nov 2024 | An authorization bypass through user-controlled key vulnerability [CWE-639] in Fortinet FortiPortal version 7.0.0 through 7.0.3 allows an authenticated attacker to interact with ressources of other organizations via… |
| CVE-2024-21759 | Media (4.3) | 0.29% | — | 9 jul 2024 | An authorization bypass through user-controlled key in Fortinet FortiPortal version 7.2.0, and versions 7.0.0 through 7.0.6 allows attacker to view unauthorized resources via HTTP or HTTPS requests. |
| CVE-2024-31495 | Baja (2.7) | 0.53% | — | 11 jun 2024 | A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiPortal versions 7.0.0 through 7.0.6 and version 7.2.0 allows privileged user to obtain unauthorized information via… |
| CVE-2023-48789 | Media (6.5) | 0.48% | — | 3 jun 2024 | A client-side enforcement of server-side security in Fortinet FortiPortal version 6.0.0 through 6.0.14 allows attacker to improper access control via crafted HTTP requests. |
| CVE-2024-23105 | Alta (7.5) | 0.45% | — | 14 may 2024 | A Use Of Less Trusted Source [CWE-348] vulnerability in Fortinet FortiPortal version 7.0.0 through 7.0.6 and version 7.2.0 through 7.2.1 allows an unauthenticated attack to bypass IP protection through crafted HTTP or… |
| CVE-2024-21761 | Media (4.3) | 0.43% | — | 12 mar 2024 | An improper authorization vulnerability [CWE-285] in FortiPortal version 7.2.0, and versions 7.0.6 and below reports may allow a user to download other organizations reports via modification in the request payload. |
| CVE-2023-41842 | Media (6.7) | 0.22% | — | 12 mar 2024 | A use of externally-controlled format string vulnerability [CWE-134] vulnerability in Fortinet allows a privileged attacker to execute unauthorized code or commands via specially crafted command arguments. |
| CVE-2023-48783 | Media (5.4) | 22% | — | 10 ene 2024 | An Authorization Bypass Through User-Controlled Key vulnerability [CWE-639] affecting PortiPortal version 7.2.1 and below, version 7.0.6 and below, version 6.0.14 and below, version 5.3.8 and below may allow a remote… |
| CVE-2023-46712 | Alta (8.8) | 0.74% | — | 10 ene 2024 | A improper access control in Fortinet FortiPortal version 7.0.0 through 7.0.6, Fortinet FortiPortal version 7.2.0 through 7.2.1 allows attacker to escalate its privilege via specifically crafted HTTP requests. |
| CVE-2023-48791 | Alta (8.8) | 1.3% | — | 13 dic 2023 | An improper neutralization of special elements used in a command ('Command Injection') vulnerability [CWE-77] in FortiPortal version 7.2.0, version 7.0.6 and below may allow a remote authenticated attacker with at least… |
| CVE-2022-27490 | Media (6.5) | 0.47% | — | 7 mar 2023 | A exposure of sensitive information to an unauthorized actor in Fortinet FortiManager version 6.0.0 through 6.0.4, FortiAnalyzer version 6.0.0 through 6.0.4, FortiPortal version 6.0.0 through 6.0.9, 5.3.0 through 5.3.8,… |
| CVE-2022-43954 | Media (6.5) | 0.69% | — | 16 feb 2023 | An insertion of sensitive information into log file vulnerability [CWE-532] in the FortiPortal management interface 7.0.0 through 7.0.2 may allow a remote authenticated attacker to read other devices' passwords in the… |
| CVE-2022-41336 | Media (4.8) | 0.57% | — | 3 ene 2023 | An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiPortal versions 6.0.0 through 6.0.11 and all versions of 5.3, 5.2, 5.1, 5.0 management interface may allow a remote… |
| CVE-2021-26104 | Alta (7.8) | 3.0% | — | 6 abr 2022 | Multiple OS command injection (CWE-78) vulnerabilities in the command line interface of FortiManager 6.2.7 and below, 6.4.5 and below and all versions of 6.2.x, 6.0.x and 5.6.x, FortiAnalyzer 6.2.7 and below, 6.4.5 and… |
| CVE-2021-36171 | Alta (8.1) | 1.2% | — | 1 mar 2022 | The use of a cryptographically weak pseudo-random number generator in the password reset feature of FortiPortal before 6.0.6 may allow a remote unauthenticated attacker to predict parts of or the whole newly generated… |
| CVE-2021-42757 | Media (6.7) | 0.52% | — | 8 dic 2021 | A buffer overflow [CWE-121] in the TFTP client library of FortiOS before 6.4.7 and FortiOS 7.0.0 through 7.0.2, may allow an authenticated local attacker to achieve arbitrary code execution via specially crafted command… |
| CVE-2021-36176 | Media (6.1) | 0.58% | — | 2 nov 2021 | Multiple uncontrolled resource consumption vulnerabilities in the web interface of FortiPortal before 6.0.6 may allow a single low-privileged user to induce a denial of service via multiple HTTP requests. |
| CVE-2021-36174 | Alta (7.5) | 0.78% | — | 2 nov 2021 | A memory allocation with excessive size value vulnerability in the license verification function of FortiPortal before 6.0.6 may allow an attacker to perform a denial of service attack via specially crafted license… |
| CVE-2021-36181 | Baja (3.1) | 0.45% | — | 2 nov 2021 | A concurrent execution using shared resource with improper Synchronization vulnerability ('Race Condition') in the customer database interface of FortiPortal before 6.0.6 may allow an authenticated, low-privilege user… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.