4151
|
- |
|
-
|
-
|
A out-of-bounds write in Fortinet FortiManager version 7.4.0 through 7.4.2, FortiAnalyzer version 7.4.0 through 7.4.2 allows attacker to escalation of privilege via specially crafted http requests.
|
CWE-787
Out-of-bounds Write
|
CVE-2024-35273
|
2025-01-14 23:15 |
2025-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
4152
|
- |
|
-
|
-
|
A improper privilege management in Fortinet FortiManager version 7.4.0 through 7.4.3, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14, FortiAnalyzer version 7.4.0 through 7.4.2, 7.2.0…
|
CWE-266
Incorrect Privilege Assignment
|
CVE-2024-33503
|
2025-01-14 23:15 |
2025-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
4153
|
- |
|
-
|
-
|
An improper neutralization of special elements used in an OS Command vulnerability [CWE-78] in Fortinet FortiSandbox version 4.4.0 through 4.4.4, 4.2.0 through 4.2.6 and below 4.0.4 allows an authent…
|
CWE-78
OS Command
|
CVE-2024-27778
|
2025-01-14 23:15 |
2025-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
4154
|
- |
|
-
|
-
|
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiAP-S 6.2 all verisons, and 6.4.0 through 6.4.9, FortiAP-W2 6.4 all versions, 7.0 all vers…
|
CWE-78
OS Command
|
CVE-2024-26012
|
2025-01-14 23:15 |
2025-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
4155
|
- |
|
-
|
-
|
Specifically crafted SCMI messages sent to an SCP running SCP-Firmware release versions up to and including 2.15.0 may lead to a Usage Fault and crash the SCP
|
-
|
CVE-2024-11863
|
2025-01-14 23:15 |
2025-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
4156
|
8.8 |
HIGH
Network
|
-
|
-
|
An authenticated attacker can use this vulnerability to perform a privilege escalation to gain root access.
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2024-11497
|
2025-01-14 23:15 |
2025-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
4157
|
- |
|
-
|
-
|
An origin validation error [CWE-346] vulnerability in Fortinet FortiOS IPSec VPN version 7.4.0 through 7.4.1 and version 7.2.6 and below allows an authenticated IPSec VPN user with dynamic IP addres…
|
CWE-346
Origin Validation Error
|
CVE-2023-46715
|
2025-01-14 23:15 |
2025-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
4158
|
- |
|
-
|
-
|
An improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiSwitch version 7.4.0 and 7.2.0 through 7.2.5 and 7.0.0 through 7.0.7 and 6.4.0 through 6…
|
CWE-78
OS Command
|
CVE-2023-37937
|
2025-01-14 23:15 |
2025-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
4159
|
- |
|
-
|
-
|
A use of hard-coded cryptographic key in Fortinet FortiSwitch version 7.4.0 and 7.2.0 through 7.2.5 and 7.0.0 through 7.0.7 and 6.4.0 through 6.4.13 and 6.2.0 through 6.2.7 and 6.0.0 through 6.0.7 al…
|
CWE-321
Use of Hard-coded Cryptographic Key
|
CVE-2023-37936
|
2025-01-14 23:15 |
2025-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
4160
|
7.4 |
HIGH
Network
|
-
|
-
|
A vulnerability has been identified in Mendix LDAP (All versions < V1.1.2). Affected versions of the module are vulnerable to LDAP injection. This could allow an unauthenticated remote attacker to by…
|
CWE-90
LDAP Injection
|
CVE-2024-56841
|
2025-01-14 20:15 |
2025-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|