Fortinet
Fortinet Fortiwan: vulnerabilidades y CVE
Fortinet Fortiwan tiene 16 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE16
Últimos 12 meses0
Críticas3
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2021-26102 | Crítica (9.1) | 20% | — | 19 dic 2024 | A relative path traversal vulnerability (CWE-23) in FortiWAN version 4.5.7 and below, 4.4 all versions may allow a remote non-authenticated attacker to delete files on the system by sending a crafted POST request. In… |
| CVE-2021-26115 | Alta (7.8) | 0.79% | — | 19 dic 2024 | An OS command injection (CWE-78) vulnerability in FortiWAN version 4.5.7 and below Command Line Interface may allow a local, authenticated and unprivileged attacker to escalate their privileges to root via executing a… |
| CVE-2023-44252 | Alta (8.8) | 0.72% | — | 13 dic 2023 | ** UNSUPPORTED WHEN ASSIGNED **An improper authentication vulnerability [CWE-287] in Fortinet FortiWAN version 5.2.0 through 5.2.1 and version 5.1.1 through 5.1.2 may allow an authenticated attacker to escalate his… |
| CVE-2023-44251 | Alta (8.8) | 0.84% | — | 13 dic 2023 | ** UNSUPPORTED WHEN ASSIGNED **A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability [CWE-22] in Fortinet FortiWAN version 5.2.0 through 5.2.1 and version 5.1.1. through 5.1.2… |
| CVE-2022-33869 | Alta (8.8) | 1.3% | — | 16 feb 2023 | An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in the management interface of FortiWAN 4.0.0 through 4.5.9 may allow an authenticated attacker to execute unauthorized… |
| CVE-2021-32585 | Media (6.1) | 0.71% | — | 6 abr 2022 | An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiWAN before 4.5.9 may allow an attacker to perform a stored cross-site scripting attack via specifically crafted HTTP requests. |
| CVE-2021-26113 | Alta (7.5) | 0.41% | — | 6 abr 2022 | A use of a one-way hash with a predictable salt vulnerability [CWE-760] in FortiWAN before 4.5.9 may allow an attacker who has previously come in possession of the password file to potentially guess passwords therein… |
| CVE-2021-32593 | Media (6.5) | 0.57% | — | 6 abr 2022 | A use of a broken or risky cryptographic algorithm vulnerability [CWE-327] in the Dynamic Tunnel Protocol of FortiWAN before 4.5.9 may allow an unauthenticated remote attacker to decrypt and forge protocol communication… |
| CVE-2021-26114 | Crítica (9.8) | 1.6% | — | 6 abr 2022 | Multiple improper neutralization of special elements used in an SQL command vulnerabilities in FortiWAN before 4.5.9 may allow an unauthenticated attacker to execute unauthorized code or commands via specifically… |
| CVE-2021-26112 | Crítica (9.8) | 1.7% | — | 6 abr 2022 | Multiple stack-based buffer overflow vulnerabilities [CWE-121] both in network daemons and in the command line interpreter of FortiWAN before 4.5.9 may allow an unauthenticated attacker to potentially corrupt control… |
| CVE-2021-24009 | Alta (8.8) | 1.5% | — | 6 abr 2022 | Multiple improper neutralization of special elements used in an OS command vulnerabilities (CWE-78) in the Web GUI of FortiWAN before 4.5.9 may allow an authenticated attacker to execute arbitrary commands on the… |
| CVE-2016-4969 | Media (6.1) | 2.3% | — | 21 sept 2016 | Cross-site scripting (XSS) vulnerability in Fortinet FortiWan (formerly AscernLink) before 4.2.5 allows remote attackers to inject arbitrary web script or HTML via the IP parameter to script/statistics/getconn.php. |
| CVE-2016-4968 | Media (6.5) | 2.7% | — | 21 sept 2016 | The linkreport/tmp/admin_global page in Fortinet FortiWan (formerly AscernLink) before 4.2.5 allows remote authenticated users to discover administrator cookies via a GET request. |
| CVE-2016-4967 | Media (6.5) | 2.7% | — | 21 sept 2016 | Fortinet FortiWan (formerly AscernLink) before 4.2.5 allows remote authenticated users to obtain sensitive information from (1) a backup of the device configuration via script/cfg_show.php or (2) PCAP files via… |
| CVE-2016-4966 | Media (6.5) | 2.2% | — | 21 sept 2016 | The diagnosis_control.php page in Fortinet FortiWan (formerly AscernLink) before 4.2.5 allows remote authenticated users to download PCAP files via vectors related to the UserName GET parameter. |
| CVE-2016-4965 | Alta (8.8) | 4.1% | — | 21 sept 2016 | Fortinet FortiWan (formerly AscernLink) before 4.2.5 allows remote authenticated users with access to the nslookup functionality to execute arbitrary commands with root privileges via the graph parameter to… |