PatchSiren

Fortinet CVE debriefs · Page 2

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Fortinet CVE published 2025-05-13

CVE-2025-53844

CVE-2025-53844 is an out-of-bounds write vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11. This vulnerability allows an attacker to execute unauthorized code or commands via specially crafted packets. The CVSS score for this vulnerability is 8.8, indicating a high severity.

Known exploited Fortinet CVE published 2025-03-18

CVE-2025-24472

CVE-2025-24472 is a Fortinet FortiOS and FortiProxy authentication bypass vulnerability. CISA added it to the Known Exploited Vulnerabilities catalog on 2025-03-18 and marked it as associated with known ransomware campaign use, so affected deployments should be treated as urgent.

HIGH Fortinet CVE published 2025-02-11

CVE-2025-58325

The supplied CISA CSAF advisory for CVE-2025-58325 describes a CWE-684 "Incorrect Provision of Specified Functionality" issue with an 8.2 High CVSS score. In the CVE text, a local authenticated attacker with high privileges can execute system commands through crafted CLI commands. The same source corpus also associates the CVE with Siemens RUGGEDCOM APE1808, but the vulnerability description and remediati [truncated]

HIGH Fortinet CVE published 2025-01-14

CVE-2024-48884

CVE-2024-48884 is described as a path traversal issue that can let an attacker trigger privilege escalation with specially crafted packets. The supplied advisory corpus is internally inconsistent, however: the CVE text names Fortinet products, while the source advisory metadata is filed under Siemens RUGGEDCOM APE1808. Treat the CVE as high priority, but verify the affected product mapping before taking r [truncated]

Known exploited Fortinet CVE published 2025-01-14

CVE-2024-55591

CVE-2024-55591 is a Fortinet FortiOS and FortiProxy authentication bypass vulnerability that CISA added to the Known Exploited Vulnerabilities catalog on 2025-01-14. Because it is a KEV-listed issue and marked as having known ransomware campaign use, organizations should treat it as an urgent remediation priority and follow Fortinet’s vendor guidance immediately.

Known exploited Fortinet CVE published 2024-10-23

CVE-2024-47575

CVE-2024-47575 is a Fortinet FortiManager missing authentication vulnerability that CISA added to the Known Exploited Vulnerabilities catalog on 2024-10-23. Because it is KEV-listed, defenders should treat it as a high-priority issue. The supplied corpus does not include vendor remediation specifics beyond CISA’s instruction to apply mitigations per vendor guidance or discontinue use of the product if mit [truncated]

Known exploited Fortinet CVE published 2024-10-09

CVE-2024-23113

CVE-2024-23113 is a Fortinet multiple-products format string vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2024-10-09. That KEV listing means defenders should treat it as a high-priority issue. The supplied corpus does not include Fortinet’s full advisory text or affected version list, so remediation should follow the vendor guidance referenced by CISA and be applied acro [truncated]

Known exploited Fortinet CVE published 2024-03-25

CVE-2023-48788

CVE-2023-48788 is a Fortinet FortiClient EMS SQL injection vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2024-03-25. The KEV entry marks it as actively exploited and notes known ransomware campaign use, so this issue should be treated as an urgent remediation item rather than a routine patch. CISA’s guidance is to apply vendor mitigations or discontinue use of the product [truncated]

Known exploited Fortinet CVE published 2024-02-09

CVE-2024-21762

CVE-2024-21762 is a Fortinet FortiOS out-of-bound write vulnerability that CISA added to the Known Exploited Vulnerabilities catalog on 2024-02-09. Because it is listed as known exploited, defenders should treat it as urgent and follow vendor mitigation guidance as soon as possible. CISA also marks it as associated with known ransomware campaign use.

Known exploited Fortinet CVE published 2023-06-13

CVE-2023-27997

CVE-2023-27997 is a heap-based buffer overflow in Fortinet FortiOS and FortiProxy SSL-VPN. CISA added it to the Known Exploited Vulnerabilities catalog on 2023-06-13 and set a remediation due date of 2023-07-04. Because it is publicly tracked as known exploited and flagged for known ransomware campaign use, it should be treated as an immediate patch-and-verify priority for any organization operating the a [truncated]

Known exploited Fortinet CVE published 2023-03-14

CVE-2022-41328

CVE-2022-41328 is a Fortinet FortiOS path traversal vulnerability that CISA added to the Known Exploited Vulnerabilities catalog on 2023-03-14. Because it is listed in KEV, defenders should treat it as a real-world exploited issue and prioritize vendor-guided remediation.

Known exploited Fortinet CVE published 2022-12-13

CVE-2022-42475

CVE-2022-42475 is a Fortinet FortiOS heap-based buffer overflow that CISA added to the Known Exploited Vulnerabilities catalog on 2022-12-13. The KEV listing indicates known exploitation, and CISA also marks the issue as having known ransomware campaign use. Organizations running FortiOS should treat this as an urgent patching and exposure-reduction priority.

Known exploited Fortinet CVE published 2022-10-11

CVE-2022-40684

CVE-2022-40684 is a Fortinet authentication bypass vulnerability affecting multiple products. CISA added it to the Known Exploited Vulnerabilities catalog on 2022-10-11, indicating active exploitation, and also marked it as associated with known ransomware campaign use. Fortinet and CISA both direct defenders to apply vendor updates and follow vendor remediation guidance.

Known exploited Fortinet CVE published 2022-09-08

CVE-2018-13374

CVE-2018-13374 is an improper access control issue affecting Fortinet FortiOS and FortiADC. In the supplied official records dated 2022-09-08, CISA lists the issue in its Known Exploited Vulnerabilities catalog, which means it is known to be actively exploited. CISA also marks the vulnerability as associated with known ransomware campaign use and directs organizations to apply updates per vendor instructions.

Known exploited Fortinet CVE published 2022-01-10

CVE-2018-13383

CVE-2018-13383 is an out-of-bounds write affecting Fortinet FortiOS and FortiProxy. CISA added it to the Known Exploited Vulnerabilities catalog on 2022-01-10 and marked known ransomware campaign use as "Known". Defenders should prioritize the vendor-recommended update path and verify that affected Fortinet deployments are remediated.

Known exploited Fortinet CVE published 2022-01-10

CVE-2018-13382

CVE-2018-13382 is an improper authorization weakness affecting Fortinet FortiOS and FortiProxy. CISA lists it in the Known Exploited Vulnerabilities catalog and marks it as having known ransomware campaign use, which makes it a high-priority remediation item for organizations running affected Fortinet products.

Known exploited Fortinet CVE published 2021-12-10

CVE-2021-44168

CVE-2021-44168 is a Fortinet FortiOS arbitrary file download issue that CISA has listed in its Known Exploited Vulnerabilities catalog. That makes this a high-priority remediation item for any organization running FortiOS, especially where devices are externally reachable or operationally critical. The vendor guidance referenced by CISA is to apply updates per Fortinet’s instructions.

Known exploited Fortinet CVE published 2021-11-03

CVE-2020-12812

CVE-2020-12812 is a Fortinet FortiOS SSL VPN improper authentication issue that CISA added to its Known Exploited Vulnerabilities catalog on 2021-11-03. Because CISA marked it as known exploited and noted known ransomware campaign use, organizations should treat it as an urgent remediation item and follow Fortinet’s update guidance.

Known exploited Fortinet CVE published 2021-11-03

CVE-2019-5591

CVE-2019-5591 is a Fortinet FortiOS vulnerability identified by CISA as known to be exploited and added to the Known Exploited Vulnerabilities catalog on 2021-11-03. The supplied corpus describes it as a Fortinet FortiOS default configuration vulnerability and directs defenders to apply updates per vendor instructions. Because CISA lists it in KEV, organizations using FortiOS should treat it as a high-pri [truncated]

Known exploited Fortinet CVE published 2021-11-03

CVE-2018-13379

CVE-2018-13379 is a Fortinet FortiOS SSL VPN path traversal vulnerability that CISA lists in its Known Exploited Vulnerabilities catalog. Because the official metadata also marks it as associated with known ransomware campaign use, defenders should treat exposed FortiOS SSL VPN deployments as a high-priority remediation item.

HIGH Fortinet CVE published 2017-02-13

CVE-2016-8495

CVE-2016-8495 affects Fortinet FortiManager and is described as an improper certificate validation issue in the FortiSandbox devices probing feature. A remote attacker able to position for a man-in-the-middle attack could spoof a trusted entity, risking confidentiality and integrity for management traffic.

HIGH Fortinet CVE published 2017-02-09

CVE-2016-8494

CVE-2016-8494 is a Fortinet Connect vulnerability in the web UI theme upload path. Because uploaded files are not sufficiently verified, an attacker with webui administrator privileges can abuse theme upload functionality to achieve arbitrary code execution. NVD rates the issue HIGH with a 7.2 CVSS score, reflecting network exposure, no user interaction, and severe confidentiality, integrity, and availabi [truncated]

MEDIUM Fortinet CVE published 2017-02-08

CVE-2016-8492

CVE-2016-8492 is a Fortinet FortiGate/FortiOS information-disclosure issue tied to an ANSI X9.31 random number generator implementation. According to the CVE record and NVD, the weakness can enable unauthorized read access to data handled by the device via IPSec/TLS decryption. The CVE was published on 2017-02-08.

CRITICAL Fortinet CVE published 2017-02-01

CVE-2016-8491

CVE-2016-8491 is a critical Fortinet FortiWLC weakness tied to a hardcoded account named "core." According to the NVD record, an attacker can leverage this condition to gain unauthorized read/write access via a remote shell. The issue is network-exploitable, requires no user interaction, and is rated CVSS 9.1 with high confidentiality and integrity impact.