Seinwacht

Meldingen

34 meldingen uit primaire bronnen. Filter op ernst, type of vendor, of zoek op een CVE-nummer of productnaam. Bulkpublicaties (BSI-updates, Patch Tuesday) staan als één regel.

Ernst
Type
Soort bron
Vendor
Sorteren
Wissen

Alleen bron fortinet-psirt. Toon alles

Koppelen

RSS-feed met deze filtersDownload als CSV

Zet de feed in je RSS-lezer, of in Slack (/feed subscribe) of Teams (RSS-connector), dan komen nieuwe meldingen vanzelf in je teamkanaal.

Liever zelf bouwen? Dezelfde selectie als JSON, of de volledige API-specificatie (OpenAPI).

  • Improper limitation of a pathname to a restricted directory

    Fortinet PSIRTKwetsbaarheid

    CVSSv3 Score: 9.8 An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') [CWE-22] and Improper Neutralization of NULL Byte or NULL Character [CWE-158] vulnerability may…

    0laag
  • ZTNA Portal Improper Certificate Validation

    Fortinet PSIRTKwetsbaarheid

    CVSSv3 Score: 7.3 An improper certificate validation vulnerability [CWE-295] in FortiOS and FortiProxy Agentless ZTNA portal may allow a remote and unauthenticated attacker to perform a…

    0laag
  • Uncontrolled Resource Consumption in SNMP

    Fortinet PSIRTKwetsbaarheid

    CVSSv3 Score: 5.9 A Use of Uninitialized Variable [CWE-457] vulnerability in Fortinet FortiAnalyzer SNMP daemon may allow a remote authenticated attacker with user permission to cause a denial of…

    0laag
  • Broken Access control on Websocket streams

    Fortinet PSIRTKwetsbaarheid

    CVSSv3 Score: 4.9 An Improper Access control vulnerability [CWE-284] in FortiSOAR may allow an authenticated attacker with zero permissions to subscribe to websocket streams and topics and to inject…

    0laag
  • JWT used for authentication in web GUI signed with static key

    Fortinet PSIRTKwetsbaarheid

    CVSSv3 Score: 9.6 An Inclusion of Sensitive Information in Source Code vulnerability [CWE-540] in FortiMonitorOnSight web portal may allow a remote unauthenticated attacker to bypass authentication…

    0laag
  • Arbitrary process termination from exposed minifilter communication port

    Fortinet PSIRTKwetsbaarheid

    CVSSv3 Score: 4.7 An Unverified Ownership Vulnerability [CWE-283] in FortiClient Windows fortimon3 driver may allow an authenticated attacker to terminate arbitrary processes via an exposed…

    0laag
  • Unauthenticated Control of NAT Rules Leading to Exposure of Sensitive Information

    Fortinet PSIRTKwetsbaarheid

    CVSSv3 Score: 8.9 An improper access control vulnerability [CWE-284] in FortiSandbox, FortiSandbox Cloud and FortiSandbox PaaS WEB UI may allow an unauthenticated attacker to access sensitive…

    0laag
  • Improper Authentication of FortiPAM Server

    Fortinet PSIRTKwetsbaarheid

    CVSSv3 Score: 9.1 An improper authentication vulnerability [CWE-287] in the Fortinet Privileged Access Agent Chrome Extension may allow a remote unauthenticated attacker to proxy a user's browser…

    0laag
  • Cron Job Injection in Remote Backup

    Fortinet PSIRTKwetsbaarheid

    CVSSv3 Score: 6.7 An Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability [CWE-77] in FortiSandbox may allow a privileged attacker to execute…

    0laag
  • Null Pointer Dereference in Log Report

    Fortinet PSIRTKwetsbaarheid

    CVSSv3 Score: 2.5 A NULL Pointer Dereference vulnerability [CWE-476] in FortiOS, FortiProxy and FortiPAM may allow an authenticated attacker to crash the httpsd daemon via crafted HTTP requests.…

    0laag
  • Open Redirect on FortiSIEM

    Fortinet PSIRTKwetsbaarheid

    CVSSv3 Score: 2.8 An URL redirection to untrusted site ('open redirect') [CWE-601] vulnerability in FortiSIEM may allow an authenticated attacker to cause a redirection to any website via specially…

    0laag
  • Workflow session email approval process bypass

    Fortinet PSIRTKwetsbaarheid

    CVSSv3 Score: 4.7 An improper access control vulnerability [CWE-284] in FortiManager may allow an administrator to bypass the approval process for workflow sessions via crafted HTTP or HTTPs…

    0laag
  • UI DoS attack

    Fortinet PSIRTKwetsbaarheid

    CVSSv3 Score: 5.0 An Allocation of Resources Without Limits or Throttling vulnerability [CWE-770] in FortiOS may allow an unauthenticated attacker to perform a slow HTTP DoS attack on the web…

    0laag
  • Stack buffer overflow in WAD

    Fortinet PSIRTKwetsbaarheid

    CVSSv3 Score: 5.1 A Stack-based Buffer Overflow vulnerability [CWE-121] in FortiOS explicit proxy may allow an unauthenticated attacker who can bypass stack protection and ASLR to execute arbitrary…

    0laag
  • Server-Side Request Forgery (SSRF)

    Fortinet PSIRTKwetsbaarheid

    CVSSv3 Score: 3.4 A Server-Side request forgery (SSRF) [CWE-918] vulnerability in FortiSIEM GUI may allow an authenticated attacker to send HTTP requests originating from the targeted device via…

    0laag
  • HTTP/2 Bomb CVE-2026-49975

    Fortinet PSIRTKwetsbaarheid

    CVSSv3 Score: 5.8 CVE-2026-49975Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service via malicious HTTP requests. This issue affects…

    0laag
  • Broken access control in the RADIUS type admin group

    Fortinet PSIRTKwetsbaarheid

    CVSSv3 Score: 8.8 An Improper Authentication vulnerability [CWE-287] in the FortiWeb Remote Radius Type Admin Authentication configured with specific, non-default settings may allow a remote…

    0laag
  • Content-Encoding WAF Evasion

    Fortinet PSIRTKwetsbaarheid

    CVSSv3 Score: 4.8 An incomplete list of disallowed inputs [CWE-184] in FortiWeb WAF may allow an unauthenticated attacker to bypass policies via specifically crafted requests. Revised on 2026-08-12…

    0laag
  • FGFM Authentication Weakening via CLI Configuration

    Fortinet PSIRTKwetsbaarheid

    CVSSv3 Score: 7.3 An Authentication Bypass Using an Alternate Path or Channel [CWE-288] vulnerability in FortiManager and FortiManager Cloud may allow a remote unauthenticated attacker to…

    0laag
  • Heap overflow in kernel driver due to missing size validation

    Fortinet PSIRTKwetsbaarheid

    CVSSv3 Score: 7.3 A buffer copy without checking size of input vulnerability [CWE-120] in FortiClient Windows may allow an unauthenticated attacker in a position to alter or craft DNS responses to…

    0laag
  • Unauthenticated VNC access exposed on all interfaces

    Fortinet PSIRTKwetsbaarheid

    CVSSv3 Score: 7.7 An Exposure of Resource to Wrong Sphere vulnerability [CWE-668] in FortiSandbox may allow an unauthenticated attacker to access the VNC server of VMs performing scanning via…

    0laag
  • Header injection in Web Filter warning page

    Fortinet PSIRTKwetsbaarheid

    CVSSv3 Score: 3.4 An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CWE-113] in FortiOS and FortiProxy may allow an attacker in possession of a…

    0laag
  • Header injection in captive portal authentication form

    Fortinet PSIRTKwetsbaarheid

    CVSSv3 Score: 3.1 An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CWE-113] in FortiOS and FortiProxy captive portal may allow an attacker able…

    0laag
  • Missed certificate verification in AD Connector communication with FortiClient EMS

    Fortinet PSIRTKwetsbaarheid

    CVSSv3 Score: 6.7 An Improper Certificate Validation vulnerability [CWE-295] in FortiClient EMS may allow a remote unauthenticated attacker to impersonate an AD Connector via a valid API Key.…

    0laag
  • Out of bounds read in GUI

    Fortinet PSIRTKwetsbaarheid

    CVSSv3 Score: 7.0 An out of bounds read [CWE-125] vulnerability in FortiAuthenticator may allow a remote unauthenticated attacker to retrieve sensitive information via a specially crafted request.…

    0laag
  • Path traversal in CLI command allows deletion of root file system

    Fortinet PSIRTKwetsbaarheid

    CVSSv3 Score: 5.0 An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in FortiOS, FortiPAM, FortiProxy and FortiSwitch Manager may allow a…

    0laag
  • SSL-VPN Reflected XSS

    Fortinet PSIRTKwetsbaarheid

    CVSSv3 Score: 6.1 An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiOS, FortiProxy, FortiPAM and FortiSwitch-Manager Agentless…

    0laag
  • Stack Buffer Overflow in Log Report

    Fortinet PSIRTKwetsbaarheid

    CVSSv3 Score: 5.9 A Stack-based Buffer Overflow vulnerability [CWE-121] in FortiOS, FortiProxy and FortiPAM may allow a privileged authenticated attacker who can bypass stack protection and ASLR to…

    0laag
  • Supers override fails to properly override supervisor address

    Fortinet PSIRTKwetsbaarheid

    CVSSv3 Score: 6.9 An Improper Restriction of Communication Channel to Intended Endpoints [CWE-923] vulnerability in FortiSIEM Windows Agent may allow an unauthorized attacker on the same local…

    0laag
  • Buffer overread in authd and wad daemon

    Fortinet PSIRTKwetsbaarheid

    CVSSv3 Score: 4.1 A buffer over-read vulnerability [CWE-126] in FortiOS, FortiProxy, and FortiSASE may allow an authenticated remote attacker to return a portion of device memory in the redirect…

    0laag