Search

Find a vulnerability

Search criteria

    32 vulnerabilities found for FortiClientEMS by Fortinet

    CERTFR-2026-AVI-0879

    Vulnerability from certfr_avis - Published: 2026-07-15 - Updated: 2026-07-15

    De multiples vulnérabilités ont été découvertes dans les produits Fortinet. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire, une élévation de privilèges et une atteinte à la confidentialité des données.

    Solutions

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    Impacted products
    Vendor Product Description
    Fortinet FortiAuthenticator FortiAuthenticator versions 6.6.x antérieures à 6.6.3
    Fortinet FortiPAM FortiPAM versions antérieures 1.7.3
    Fortinet FortiProxy FortiProxy versions antérieures à 7.6.6
    Fortinet FortiSandbox FortiSandbox versions 5.0.x antérieures à 5.0.3
    Fortinet FortiPAM FortiPAM versions 1.8.x antérieures à 1.8.3
    Fortinet FortiOS FortiOS versions antérieures à 7.6.7
    Fortinet FortiSIEM FortiSIEM versions 7.4.x antérieures à 7.4.1
    Fortinet FortiSIEM FortiSIEM versions 7.3.x antérieures à 7.3.5
    Fortinet FortiAuthenticator FortiAuthenticator versions à 6.5.x et antérieures 6.5.8
    Fortinet FortiClientEMS FortiClientEMS antérieures à 7.4.6
    Fortinet FortiSandbox FortiSandbox versions 4.4.x et antérieures à 4.4.9
    Fortinet FortiSIEM FortiSIEMWindowsAgent versions 7.4.x antérieures à 7.4.2
    Fortinet FortiSIEM FortiSIEM versions antérieures à 7.2.7
    References

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "FortiAuthenticator versions 6.6.x ant\u00e9rieures \u00e0 6.6.3",
          "product": {
            "name": "FortiAuthenticator",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiPAM versions ant\u00e9rieures 1.7.3",
          "product": {
            "name": "FortiPAM",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiProxy versions ant\u00e9rieures \u00e0 7.6.6",
          "product": {
            "name": "FortiProxy",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiSandbox versions 5.0.x ant\u00e9rieures \u00e0 5.0.3",
          "product": {
            "name": "FortiSandbox",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiPAM versions 1.8.x ant\u00e9rieures \u00e0 1.8.3",
          "product": {
            "name": "FortiPAM",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiOS versions ant\u00e9rieures \u00e0 7.6.7",
          "product": {
            "name": "FortiOS",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiSIEM versions 7.4.x ant\u00e9rieures \u00e0 7.4.1",
          "product": {
            "name": "FortiSIEM",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiSIEM versions 7.3.x ant\u00e9rieures \u00e0 7.3.5",
          "product": {
            "name": "FortiSIEM",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiAuthenticator versions \u00e0 6.5.x et ant\u00e9rieures 6.5.8",
          "product": {
            "name": "FortiAuthenticator",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiClientEMS ant\u00e9rieures \u00e0 7.4.6",
          "product": {
            "name": "FortiClientEMS",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiSandbox versions 4.4.x et ant\u00e9rieures \u00e0 4.4.9",
          "product": {
            "name": "FortiSandbox",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiSIEMWindowsAgent versions 7.4.x ant\u00e9rieures \u00e0 7.4.2",
          "product": {
            "name": "FortiSIEM",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiSIEM versions ant\u00e9rieures \u00e0 7.2.7",
          "product": {
            "name": "FortiSIEM",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": "",
      "content": "## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des correctifs (cf. section Documentation).",
      "cves": [
        {
          "name": "CVE-2025-43892",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-43892"
        },
        {
          "name": "CVE-2025-53379",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-53379"
        },
        {
          "name": "CVE-2025-62826",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-62826"
        },
        {
          "name": "CVE-2026-59839",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-59839"
        },
        {
          "name": "CVE-2026-23573",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-23573"
        },
        {
          "name": "CVE-2026-59840",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-59840"
        },
        {
          "name": "CVE-2026-59836",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-59836"
        },
        {
          "name": "CVE-2026-59835",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-59835"
        },
        {
          "name": "CVE-2026-59838",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-59838"
        },
        {
          "name": "CVE-2025-62675",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-62675"
        },
        {
          "name": "CVE-2026-59837",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-59837"
        },
        {
          "name": "CVE-2026-59841",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-59841"
        }
      ],
      "initial_release_date": "2026-07-15T00:00:00",
      "last_revision_date": "2026-07-15T00:00:00",
      "links": [],
      "reference": "CERTFR-2026-AVI-0879",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2026-07-15T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "Injection de code indirecte \u00e0 distance (XSS)"
        },
        {
          "description": "Atteinte \u00e0 l\u0027int\u00e9grit\u00e9 des donn\u00e9es"
        },
        {
          "description": "Ex\u00e9cution de code arbitraire"
        },
        {
          "description": "Contournement de la politique de s\u00e9curit\u00e9"
        },
        {
          "description": "Atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es"
        },
        {
          "description": "\u00c9l\u00e9vation de privil\u00e8ges"
        }
      ],
      "summary": "De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans les produits Fortinet. Certaines d\u0027entre elles permettent \u00e0 un attaquant de provoquer une ex\u00e9cution de code arbitraire, une \u00e9l\u00e9vation de privil\u00e8ges et une atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es.",
      "title": "Multiples vuln\u00e9rabilit\u00e9s dans les produits Fortinet",
      "vendor_advisories": [
        {
          "published_at": "2026-07-14",
          "title": "Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-26-152",
          "url": "https://www.fortiguard.com/psirt/FG-IR-26-152"
        },
        {
          "published_at": "2026-07-14",
          "title": "Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-26-150",
          "url": "https://www.fortiguard.com/psirt/FG-IR-26-150"
        },
        {
          "published_at": "2026-07-14",
          "title": "Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-26-149",
          "url": "https://www.fortiguard.com/psirt/FG-IR-26-149"
        },
        {
          "published_at": "2026-07-14",
          "title": "Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-26-148",
          "url": "https://www.fortiguard.com/psirt/FG-IR-26-148"
        },
        {
          "published_at": "2026-07-14",
          "title": "Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-26-145",
          "url": "https://www.fortiguard.com/psirt/FG-IR-26-145"
        },
        {
          "published_at": "2026-07-14",
          "title": "Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-26-151",
          "url": "https://www.fortiguard.com/psirt/FG-IR-26-151"
        },
        {
          "published_at": "2026-07-14",
          "title": "Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-26-146",
          "url": "https://www.fortiguard.com/psirt/FG-IR-26-146"
        },
        {
          "published_at": "2026-07-14",
          "title": "Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-26-154",
          "url": "https://www.fortiguard.com/psirt/FG-IR-26-154"
        },
        {
          "published_at": "2026-07-14",
          "title": "Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-26-153",
          "url": "https://www.fortiguard.com/psirt/FG-IR-26-153"
        },
        {
          "published_at": "2026-07-14",
          "title": "Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-26-147",
          "url": "https://www.fortiguard.com/psirt/FG-IR-26-147"
        },
        {
          "published_at": "2026-07-14",
          "title": "Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-26-155",
          "url": "https://www.fortiguard.com/psirt/FG-IR-26-155"
        }
      ]
    }

    CERTFR-2026-AVI-0440

    Vulnerability from certfr_avis - Published: 2026-04-15 - Updated: 2026-04-15

    De multiples vulnérabilités ont été découvertes dans les produits Fortinet. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un déni de service à distance.

    Fortinet indique que la vulnérabilité CVE-2025-61624 est activement exploitée.

    Solutions

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    Impacted products
    Vendor Product Description
    Fortinet FortiSOAR FortiSOAR on-premise versions 7.6.x antérieures à 7.6.5 avec File Content Extraction Connector versions antérieures à 1.3.1
    Fortinet FortiNDR FortiNDR versions 7.x antérieures à 7.4.9
    Fortinet FortiNAC FortiNAC-F versions 7.6.x antérieures à 7.6.6
    Fortinet FortiAnalyzer FortiAnalyzer versions 7.6.x antérieures à 7.6.5
    Fortinet FortiManager FortiManager Cloud versions 7.x antérieures à 7.4.9
    Fortinet FortiWeb FortiWeb versions 7.x antérieures à 7.6.7
    Fortinet FortiSwitch FortiSwitchManager versions 7.0.x antérieures à 7.0.7
    Fortinet FortiSOAR FortiSOAR PaaS versions 7.3.x, 7.4.x et 7.5.x antérieures à 7.5.3 avec File Content Extraction Connector versions antérieures à 1.3.1
    Fortinet FortiNDR FortiNDR versions 7.6.x antérieures à 7.6.1
    Fortinet FortiSandbox FortiSandbox PaaS versions 5.0.x antérieures à 5.0.6
    Fortinet FortiManager FortiManager Cloud versions 7.6.x antérieures à 7.6.5
    Fortinet FortiSandbox FortiSandbox versions 5.0.x antérieures à 5.0.6
    Fortinet FortiOS FortiOS versions antérieures à 7.4.10
    Fortinet FortiDDoS FortiDDoS-F versions 7.2.x antérieures à 7.2.3
    Fortinet FortiAnalyzer FortiAnalyzer versions 7.x antérieures à 7.4.9
    Fortinet FortiManager FortiManager versions 7.6.x antérieures à 7.6.5
    Fortinet FortiAnalyzer FortiAnalyzer Cloud versions 7.x antérieures à 7.4.9
    Fortinet FortiOS FortiOS versions 7.6.x antérieures à 7.6.5
    Fortinet FortiPAM FortiPAM versions antérieures à 1.7.1
    Fortinet FortiWeb FortiWeb versions 8.0.x antérieures à 8.0.4
    Fortinet FortiManager FortiManager versions 7.x antérieures à 7.4.9
    Fortinet FortiProxy FortiProxy versions 7.x antérieures à 7.4.12
    Fortinet FortiSOAR FortiSOAR on-premise versions 7.3.x, 7.4.x et 7.5.x antérieures à 7.5.3 avec File Content Extraction Connector versions antérieures à 1.3.1
    Fortinet FortiSwitch FortiSwitchManager versions 7.2.x antérieures à 7.2.8
    Fortinet FortiSandbox FortiSandbox PaaS versions 4.2.x et 4.4.x antérieures à 4.4.9
    Fortinet FortiAnalyzer FortiAnalyzer Cloud versions 7.6.x antérieures à 7.6.5
    Fortinet FortiProxy FortiProxy versions 7.6.x antérieures à 7.6.5
    Fortinet FortiClientEMS FortiClientEMS versions 7.x antérieures à 7.2.13
    Fortinet FortiSandbox FortiSandbox versions 4.2.x et 4.4.x antérieures à 4.4.9 (cette version reste affectée par la vulnérabilité CVE-2026-27316)
    Fortinet FortiVoice FortiVoice versions 7.0.x antérieures à 7.0.2
    Fortinet FortiClientEMS FortiClientEMS versions 7.4.x antérieures à 7.4.6
    Fortinet FortiSOAR FortiSOAR PaaS versions 7.6.x antérieures à 7.6.5 avec File Content Extraction Connector versions antérieures à 1.3.1
    References
    Bulletin de sécurité Fortinet FG-IR-26-111 2026-04-14 vendor-advisory
    Bulletin de sécurité Fortinet FG-IR-26-110 2026-04-14 vendor-advisory
    Bulletin de sécurité Fortinet FG-IR-26-101 2026-04-14 vendor-advisory
    Bulletin de sécurité Fortinet FG-IR-26-120 2026-04-14 vendor-advisory
    Bulletin de sécurité Fortinet FG-IR-26-105 2026-04-14 vendor-advisory
    Bulletin de sécurité Fortinet FG-IR-26-106 2026-04-14 vendor-advisory
    Bulletin de sécurité Fortinet FG-IR-26-102 2026-04-14 vendor-advisory
    Bulletin de sécurité Fortinet FG-IR-26-114 2026-04-14 vendor-advisory
    Bulletin de sécurité Fortinet FG-IR-26-107 2026-04-14 vendor-advisory
    Bulletin de sécurité Fortinet FG-IR-26-109 2026-04-14 vendor-advisory
    Bulletin de sécurité Fortinet FG-IR-26-115 2026-04-14 vendor-advisory
    Bulletin de sécurité Fortinet FG-IR-26-119 2026-04-14 vendor-advisory
    Bulletin de sécurité Fortinet FG-IR-26-103 2026-04-14 vendor-advisory
    Bulletin de sécurité Fortinet FG-IR-26-108 2026-04-14 vendor-advisory
    Bulletin de sécurité Fortinet FG-IR-26-125 2026-04-14 vendor-advisory
    Bulletin de sécurité Fortinet FG-IR-26-121 2026-04-14 vendor-advisory
    Bulletin de sécurité Fortinet FG-IR-26-100 2026-04-14 vendor-advisory
    Bulletin de sécurité Fortinet FG-IR-26-118 2026-04-14 vendor-advisory
    Bulletin de sécurité Fortinet FG-IR-26-124 2026-04-14 vendor-advisory
    Bulletin de sécurité Fortinet FG-IR-26-113 2026-04-14 vendor-advisory
    Bulletin de sécurité Fortinet FG-IR-26-127 2026-04-15 vendor-advisory
    Bulletin de sécurité Fortinet FG-IR-26-117 2026-04-14 vendor-advisory
    Bulletin de sécurité Fortinet FG-IR-26-122 2026-04-14 vendor-advisory
    Bulletin de sécurité Fortinet FG-IR-26-104 2026-04-14 vendor-advisory
    Bulletin de sécurité Fortinet FG-IR-26-112 2026-04-14 vendor-advisory
    Bulletin de sécurité Fortinet FG-IR-26-126 2026-04-14 vendor-advisory
    Bulletin de sécurité Fortinet FG-IR-26-116 2026-04-14 vendor-advisory

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "FortiSOAR on-premise versions 7.6.x ant\u00e9rieures \u00e0 7.6.5 avec File Content Extraction Connector versions ant\u00e9rieures \u00e0 1.3.1",
          "product": {
            "name": "FortiSOAR",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiNDR versions 7.x ant\u00e9rieures \u00e0 7.4.9",
          "product": {
            "name": "FortiNDR",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiNAC-F versions 7.6.x ant\u00e9rieures \u00e0 7.6.6",
          "product": {
            "name": "FortiNAC",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiAnalyzer versions 7.6.x ant\u00e9rieures \u00e0 7.6.5",
          "product": {
            "name": "FortiAnalyzer",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiManager Cloud versions 7.x ant\u00e9rieures \u00e0 7.4.9",
          "product": {
            "name": "FortiManager",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiWeb versions 7.x ant\u00e9rieures \u00e0 7.6.7",
          "product": {
            "name": "FortiWeb",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiSwitchManager versions 7.0.x ant\u00e9rieures \u00e0 7.0.7",
          "product": {
            "name": "FortiSwitch",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiSOAR PaaS versions 7.3.x, 7.4.x et 7.5.x ant\u00e9rieures \u00e0 7.5.3 avec File Content Extraction Connector versions ant\u00e9rieures \u00e0 1.3.1",
          "product": {
            "name": "FortiSOAR",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiNDR versions 7.6.x ant\u00e9rieures \u00e0 7.6.1",
          "product": {
            "name": "FortiNDR",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiSandbox PaaS versions 5.0.x ant\u00e9rieures \u00e0 5.0.6",
          "product": {
            "name": "FortiSandbox",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiManager Cloud versions 7.6.x ant\u00e9rieures \u00e0 7.6.5",
          "product": {
            "name": "FortiManager",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiSandbox versions 5.0.x ant\u00e9rieures \u00e0 5.0.6",
          "product": {
            "name": "FortiSandbox",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiOS versions ant\u00e9rieures \u00e0 7.4.10",
          "product": {
            "name": "FortiOS",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiDDoS-F versions 7.2.x ant\u00e9rieures \u00e0 7.2.3",
          "product": {
            "name": "FortiDDoS",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiAnalyzer versions 7.x ant\u00e9rieures \u00e0 7.4.9",
          "product": {
            "name": "FortiAnalyzer",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiManager versions 7.6.x ant\u00e9rieures \u00e0 7.6.5",
          "product": {
            "name": "FortiManager",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiAnalyzer Cloud versions 7.x ant\u00e9rieures \u00e0 7.4.9",
          "product": {
            "name": "FortiAnalyzer",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiOS versions 7.6.x ant\u00e9rieures \u00e0 7.6.5",
          "product": {
            "name": "FortiOS",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiPAM versions ant\u00e9rieures \u00e0 1.7.1",
          "product": {
            "name": "FortiPAM",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiWeb versions 8.0.x ant\u00e9rieures \u00e0 8.0.4",
          "product": {
            "name": "FortiWeb",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiManager versions 7.x ant\u00e9rieures \u00e0 7.4.9",
          "product": {
            "name": "FortiManager",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiProxy versions 7.x ant\u00e9rieures \u00e0 7.4.12",
          "product": {
            "name": "FortiProxy",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiSOAR on-premise versions 7.3.x, 7.4.x et 7.5.x ant\u00e9rieures \u00e0 7.5.3 avec File Content Extraction Connector versions ant\u00e9rieures \u00e0 1.3.1",
          "product": {
            "name": "FortiSOAR",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiSwitchManager versions 7.2.x ant\u00e9rieures \u00e0 7.2.8",
          "product": {
            "name": "FortiSwitch",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiSandbox PaaS versions 4.2.x et 4.4.x ant\u00e9rieures \u00e0 4.4.9",
          "product": {
            "name": "FortiSandbox",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiAnalyzer Cloud versions 7.6.x ant\u00e9rieures \u00e0 7.6.5",
          "product": {
            "name": "FortiAnalyzer",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiProxy versions 7.6.x ant\u00e9rieures \u00e0 7.6.5",
          "product": {
            "name": "FortiProxy",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiClientEMS versions 7.x ant\u00e9rieures \u00e0 7.2.13",
          "product": {
            "name": "FortiClientEMS",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiSandbox versions 4.2.x et 4.4.x ant\u00e9rieures \u00e0 4.4.9 (cette version reste affect\u00e9e par la vuln\u00e9rabilit\u00e9 CVE-2026-27316)",
          "product": {
            "name": "FortiSandbox",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiVoice versions 7.0.x ant\u00e9rieures \u00e0 7.0.2",
          "product": {
            "name": "FortiVoice",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiClientEMS versions 7.4.x ant\u00e9rieures \u00e0 7.4.6",
          "product": {
            "name": "FortiClientEMS",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiSOAR PaaS versions 7.6.x ant\u00e9rieures \u00e0 7.6.5 avec File Content Extraction Connector versions ant\u00e9rieures \u00e0 1.3.1",
          "product": {
            "name": "FortiSOAR",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": "",
      "content": "## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des correctifs (cf. section Documentation).",
      "cves": [
        {
          "name": "CVE-2026-39809",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-39809"
        },
        {
          "name": "CVE-2025-61848",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-61848"
        },
        {
          "name": "CVE-2026-22155",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-22155"
        },
        {
          "name": "CVE-2026-39812",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-39812"
        },
        {
          "name": "CVE-2026-21741",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-21741"
        },
        {
          "name": "CVE-2026-27316",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-27316"
        },
        {
          "name": "CVE-2025-61624",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-61624"
        },
        {
          "name": "CVE-2026-39808",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-39808"
        },
        {
          "name": "CVE-2026-22574",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-22574"
        },
        {
          "name": "CVE-2025-61886",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-61886"
        },
        {
          "name": "CVE-2024-23104",
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-23104"
        },
        {
          "name": "CVE-2026-39811",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-39811"
        },
        {
          "name": "CVE-2026-39814",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-39814"
        },
        {
          "name": "CVE-2026-39810",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-39810"
        },
        {
          "name": "CVE-2026-25691",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-25691"
        },
        {
          "name": "CVE-2026-22576",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-22576"
        },
        {
          "name": "CVE-2026-22573",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-22573"
        },
        {
          "name": "CVE-2026-39815",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-39815"
        },
        {
          "name": "CVE-2026-21742",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-21742"
        },
        {
          "name": "CVE-2026-22828",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-22828"
        },
        {
          "name": "CVE-2026-22154",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-22154"
        },
        {
          "name": "CVE-2026-23708",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-23708"
        },
        {
          "name": "CVE-2025-53847",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-53847"
        },
        {
          "name": "CVE-2026-39813",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-39813"
        },
        {
          "name": "CVE-2025-68649",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-68649"
        },
        {
          "name": "CVE-2025-59809",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-59809"
        },
        {
          "name": "CVE-2026-40688",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-40688"
        }
      ],
      "initial_release_date": "2026-04-15T00:00:00",
      "last_revision_date": "2026-04-15T00:00:00",
      "links": [],
      "reference": "CERTFR-2026-AVI-0440",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2026-04-15T00:00:00.000000"
        },
        {
          "description": "La vuln\u00e9rabilit\u00e9 CVE-2025-61624 est activement exploit\u00e9e.",
          "revision_date": "2026-04-15T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "Ex\u00e9cution de code arbitraire \u00e0 distance"
        },
        {
          "description": "\u00c9l\u00e9vation de privil\u00e8ges"
        },
        {
          "description": "D\u00e9ni de service \u00e0 distance"
        },
        {
          "description": "Atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es"
        },
        {
          "description": "Atteinte \u00e0 l\u0027int\u00e9grit\u00e9 des donn\u00e9es"
        },
        {
          "description": "Contournement de la politique de s\u00e9curit\u00e9"
        },
        {
          "description": "Injection de code indirecte \u00e0 distance (XSS)"
        },
        {
          "description": "Non sp\u00e9cifi\u00e9 par l\u0027\u00e9diteur"
        },
        {
          "description": "Falsification de requ\u00eates c\u00f4t\u00e9 serveur (SSRF)"
        },
        {
          "description": "Injection SQL (SQLi)"
        }
      ],
      "summary": "De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans les produits Fortinet. Certaines d\u0027entre elles permettent \u00e0 un attaquant de provoquer une ex\u00e9cution de code arbitraire \u00e0 distance, une \u00e9l\u00e9vation de privil\u00e8ges et un d\u00e9ni de service \u00e0 distance.\n\nFortinet indique que la vuln\u00e9rabilit\u00e9 CVE-2025-61624 est activement exploit\u00e9e.",
      "title": "Multiples vuln\u00e9rabilit\u00e9s dans les produits Fortinet",
      "vendor_advisories": [
        {
          "published_at": "2026-04-14",
          "title": "Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-26-111",
          "url": "https://www.fortiguard.com/psirt/FG-IR-26-111"
        },
        {
          "published_at": "2026-04-14",
          "title": "Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-26-110",
          "url": "https://www.fortiguard.com/psirt/FG-IR-26-110"
        },
        {
          "published_at": "2026-04-14",
          "title": "Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-26-101",
          "url": "https://www.fortiguard.com/psirt/FG-IR-26-101"
        },
        {
          "published_at": "2026-04-14",
          "title": "Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-26-120",
          "url": "https://www.fortiguard.com/psirt/FG-IR-26-120"
        },
        {
          "published_at": "2026-04-14",
          "title": "Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-26-105",
          "url": "https://www.fortiguard.com/psirt/FG-IR-26-105"
        },
        {
          "published_at": "2026-04-14",
          "title": "Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-26-106",
          "url": "https://www.fortiguard.com/psirt/FG-IR-26-106"
        },
        {
          "published_at": "2026-04-14",
          "title": "Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-26-102",
          "url": "https://www.fortiguard.com/psirt/FG-IR-26-102"
        },
        {
          "published_at": "2026-04-14",
          "title": "Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-26-114",
          "url": "https://www.fortiguard.com/psirt/FG-IR-26-114"
        },
        {
          "published_at": "2026-04-14",
          "title": "Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-26-107",
          "url": "https://www.fortiguard.com/psirt/FG-IR-26-107"
        },
        {
          "published_at": "2026-04-14",
          "title": "Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-26-109",
          "url": "https://www.fortiguard.com/psirt/FG-IR-26-109"
        },
        {
          "published_at": "2026-04-14",
          "title": "Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-26-115",
          "url": "https://www.fortiguard.com/psirt/FG-IR-26-115"
        },
        {
          "published_at": "2026-04-14",
          "title": "Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-26-119",
          "url": "https://www.fortiguard.com/psirt/FG-IR-26-119"
        },
        {
          "published_at": "2026-04-14",
          "title": "Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-26-103",
          "url": "https://www.fortiguard.com/psirt/FG-IR-26-103"
        },
        {
          "published_at": "2026-04-14",
          "title": "Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-26-108",
          "url": "https://www.fortiguard.com/psirt/FG-IR-26-108"
        },
        {
          "published_at": "2026-04-14",
          "title": "Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-26-125",
          "url": "https://www.fortiguard.com/psirt/FG-IR-26-125"
        },
        {
          "published_at": "2026-04-14",
          "title": "Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-26-121",
          "url": "https://www.fortiguard.com/psirt/FG-IR-26-121"
        },
        {
          "published_at": "2026-04-14",
          "title": "Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-26-100",
          "url": "https://www.fortiguard.com/psirt/FG-IR-26-100"
        },
        {
          "published_at": "2026-04-14",
          "title": "Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-26-118",
          "url": "https://www.fortiguard.com/psirt/FG-IR-26-118"
        },
        {
          "published_at": "2026-04-14",
          "title": "Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-26-124",
          "url": "https://www.fortiguard.com/psirt/FG-IR-26-124"
        },
        {
          "published_at": "2026-04-14",
          "title": "Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-26-113",
          "url": "https://www.fortiguard.com/psirt/FG-IR-26-113"
        },
        {
          "published_at": "2026-04-15",
          "title": "Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-26-127",
          "url": "https://www.fortiguard.com/psirt/FG-IR-26-127"
        },
        {
          "published_at": "2026-04-14",
          "title": "Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-26-117",
          "url": "https://www.fortiguard.com/psirt/FG-IR-26-117"
        },
        {
          "published_at": "2026-04-14",
          "title": "Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-26-122",
          "url": "https://www.fortiguard.com/psirt/FG-IR-26-122"
        },
        {
          "published_at": "2026-04-14",
          "title": "Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-26-104",
          "url": "https://www.fortiguard.com/psirt/FG-IR-26-104"
        },
        {
          "published_at": "2026-04-14",
          "title": "Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-26-112",
          "url": "https://www.fortiguard.com/psirt/FG-IR-26-112"
        },
        {
          "published_at": "2026-04-14",
          "title": "Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-26-126",
          "url": "https://www.fortiguard.com/psirt/FG-IR-26-126"
        },
        {
          "published_at": "2026-04-14",
          "title": "Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-26-116",
          "url": "https://www.fortiguard.com/psirt/FG-IR-26-116"
        }
      ]
    }

    CERTFR-2026-AVI-0400

    Vulnerability from certfr_avis - Published: 2026-04-07 - Updated: 2026-04-07

    Une vulnérabilité a été découverte dans Fortinet FortiClientEMS. Elle permet à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un contournement de la politique de sécurité.

    Fortinet indique que la vulnérabilité CVE-2026-35616 est activement exploitée.

    Solutions

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    Impacted products
    Vendor Product Description
    Fortinet FortiClientEMS FortiClientEMS versions 7.4.x postérieures ou égales à 7.4.5 sans les derniers correctifs de sécurité
    References

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "FortiClientEMS versions 7.4.x post\u00e9rieures ou \u00e9gales \u00e0 7.4.5 sans les derniers correctifs de s\u00e9curit\u00e9",
          "product": {
            "name": "FortiClientEMS",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": "",
      "content": "## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des correctifs (cf. section Documentation).",
      "cves": [
        {
          "name": "CVE-2026-35616",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-35616"
        }
      ],
      "initial_release_date": "2026-04-07T00:00:00",
      "last_revision_date": "2026-04-07T00:00:00",
      "links": [],
      "reference": "CERTFR-2026-AVI-0400",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2026-04-07T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "Ex\u00e9cution de code arbitraire \u00e0 distance"
        },
        {
          "description": "Contournement de la politique de s\u00e9curit\u00e9"
        },
        {
          "description": "\u00c9l\u00e9vation de privil\u00e8ges"
        }
      ],
      "summary": "Une vuln\u00e9rabilit\u00e9 a \u00e9t\u00e9 d\u00e9couverte dans Fortinet FortiClientEMS. Elle permet \u00e0 un attaquant de provoquer une ex\u00e9cution de code arbitraire \u00e0 distance, une \u00e9l\u00e9vation de privil\u00e8ges et un contournement de la politique de s\u00e9curit\u00e9.\n\nFortinet indique que la vuln\u00e9rabilit\u00e9 CVE-2026-35616 est activement exploit\u00e9e.",
      "title": "Vuln\u00e9rabilit\u00e9 dans Fortinet FortiClientEMS",
      "vendor_advisories": [
        {
          "published_at": "2026-04-04",
          "title": "Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-26-099",
          "url": "https://www.fortiguard.com/psirt/FG-IR-26-099"
        }
      ]
    }

    CERTFR-2026-AVI-0136

    Vulnerability from certfr_avis - Published: 2026-02-09 - Updated: 2026-02-09

    Une vulnérabilité a été découverte dans Fortinet FortiClientEMS. Elle permet à un attaquant de provoquer une injection SQL (SQLi).

    Solutions

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    Impacted products
    Vendor Product Description
    Fortinet FortiClientEMS FortiClientEMS versions 7.4.x antérieures à 7.4.5
    References

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "FortiClientEMS versions 7.4.x ant\u00e9rieures \u00e0 7.4.5",
          "product": {
            "name": "FortiClientEMS",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": "",
      "content": "## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des correctifs (cf. section Documentation).",
      "cves": [
        {
          "name": "CVE-2026-21643",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-21643"
        }
      ],
      "initial_release_date": "2026-02-09T00:00:00",
      "last_revision_date": "2026-02-09T00:00:00",
      "links": [],
      "reference": "CERTFR-2026-AVI-0136",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2026-02-09T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "Injection SQL (SQLi)"
        }
      ],
      "summary": "Une vuln\u00e9rabilit\u00e9 a \u00e9t\u00e9 d\u00e9couverte dans Fortinet FortiClientEMS. Elle permet \u00e0 un attaquant de provoquer une injection SQL (SQLi).",
      "title": "Vuln\u00e9rabilit\u00e9 dans Fortinet FortiClientEMS",
      "vendor_advisories": [
        {
          "published_at": "2026-02-06",
          "title": "Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-25-1142",
          "url": "https://www.fortiguard.com/psirt/FG-IR-25-1142"
        }
      ]
    }

    CERTFR-2025-AVI-0399

    Vulnerability from certfr_avis - Published: 2025-05-13 - Updated: 2025-05-13

    De multiples vulnérabilités ont été découvertes dans les produits Fortinet. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un déni de service à distance.

    Fortinet indique que la vulnérabilité CVE-2025-32756 est activement exploitée.

    Solutions

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    Impacted products
    Vendor Product Description
    Fortinet FortiClient FortiClientMac versions 7.4.x antérieures à 7.4.3
    Fortinet FortiPortal FortiPortal versions 7.0.x antérieures à 7.0.10
    Fortinet FortiMail FortiMail versions 7.4.x antérieures à 7.4.5
    Fortinet FortiOS FortiOS versions 7.4.x antérieures à 7.4.7
    Fortinet FortiNDR FortiNDR versions 7.1.x à 7.2.x antérieures à 7.2.5
    Fortinet FortiNDR FortiNDR versions 7.6.x antérieures à 7.6.1
    Fortinet FortiManager FortiManager versions 7.2.x antérieures à 7.2.2
    Fortinet FortiMail FortiMail versions 7.6.x antérieures à 7.6.3
    Fortinet FortiClientEMS FortiClientEMS Cloud versions 7.4.x antérieures à 7.4.3
    Fortinet FortiRecorder FortiRecorder versions 7.0.x antérieures à 7.0.6
    Fortinet FortiManager FortiManager versions 7.0.x antérieures à 7.0.8
    Fortinet FortiVoice FortiVoice versions 7.2.x antérieures à 7.2.1
    Fortinet FortiRecorder FortiRecorder versions 7.2.x antérieures à 7.2.4
    Fortinet FortiNDR FortiNDR versions antérieures à 7.0.7
    Fortinet FortiOS FortiOS versions 7.2.x antérieures à 7.2.8
    Fortinet FortiProxy FortiProxy versions 7.6.x antérieures à 7.6.2
    Fortinet FortiOS FortiOS versions 7.6.x antérieures à 7.6.1
    Fortinet FortiVoice FortiVoice versions 7.0.x antérieures à 7.0.7
    Fortinet FortiClient FortiClientMac versions 7.x antérieures à 7.2.9
    Fortinet FortiRecorder FortiRecorder versions 6.4.x antérieures à 6.4.6
    Fortinet FortiClient FortiClientWindows versions 7.2.x antérieures à 7.2.2
    Fortinet FortiCamera FortiCamera versions antérieures à 2.1.4
    Fortinet FortiPortal FortiPortal versions 7.4.x antérieures à 7.4.2
    Fortinet FortiClientEMS FortiClientEMS versions 7.4.x antérieures à 7.4.3
    Fortinet FortiSwitch FortiSwitchManager versions 7.2.x antérieures à 7.2.6
    Fortinet FortiOS FortiOS versions antérieures à 7.0.15
    Fortinet FortiMail FortiMail versions 7.2.x antérieures à 7.2.8
    Fortinet FortiVoice FortiVoiceUCDesktop versions antérieures à 7.0
    Fortinet FortiVoice FortiVoice versions 6.4.x antérieures à 6.4.11
    Fortinet FortiNDR FortiNDR versions 7.4.x antérieures à 7.4.8
    Fortinet FortiMail FortiMail versions 7.0.x antérieures à 7.0.9
    Fortinet FortiPortal FortiPortal versions 7.2.x antérieures à 7.2.6
    References

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "FortiClientMac versions 7.4.x ant\u00e9rieures \u00e0 7.4.3",
          "product": {
            "name": "FortiClient",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiPortal versions 7.0.x ant\u00e9rieures \u00e0 7.0.10",
          "product": {
            "name": "FortiPortal",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiMail versions 7.4.x ant\u00e9rieures \u00e0 7.4.5",
          "product": {
            "name": "FortiMail",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiOS versions 7.4.x ant\u00e9rieures \u00e0 7.4.7",
          "product": {
            "name": "FortiOS",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiNDR versions 7.1.x \u00e0 7.2.x ant\u00e9rieures \u00e0 7.2.5",
          "product": {
            "name": "FortiNDR",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiNDR versions 7.6.x ant\u00e9rieures \u00e0 7.6.1",
          "product": {
            "name": "FortiNDR",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiManager versions 7.2.x ant\u00e9rieures \u00e0 7.2.2",
          "product": {
            "name": "FortiManager",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiMail versions 7.6.x ant\u00e9rieures \u00e0 7.6.3",
          "product": {
            "name": "FortiMail",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiClientEMS Cloud versions 7.4.x ant\u00e9rieures \u00e0 7.4.3",
          "product": {
            "name": "FortiClientEMS",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiRecorder versions 7.0.x ant\u00e9rieures \u00e0 7.0.6",
          "product": {
            "name": "FortiRecorder",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiManager versions 7.0.x ant\u00e9rieures \u00e0 7.0.8",
          "product": {
            "name": "FortiManager",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiVoice versions 7.2.x ant\u00e9rieures \u00e0 7.2.1",
          "product": {
            "name": "FortiVoice",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiRecorder versions 7.2.x ant\u00e9rieures \u00e0 7.2.4",
          "product": {
            "name": "FortiRecorder",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiNDR versions ant\u00e9rieures \u00e0 7.0.7",
          "product": {
            "name": "FortiNDR",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiOS versions 7.2.x ant\u00e9rieures \u00e0 7.2.8",
          "product": {
            "name": "FortiOS",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiProxy versions 7.6.x ant\u00e9rieures \u00e0 7.6.2",
          "product": {
            "name": "FortiProxy",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiOS versions 7.6.x ant\u00e9rieures \u00e0 7.6.1",
          "product": {
            "name": "FortiOS",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiVoice versions 7.0.x ant\u00e9rieures \u00e0 7.0.7",
          "product": {
            "name": "FortiVoice",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiClientMac versions 7.x ant\u00e9rieures \u00e0 7.2.9",
          "product": {
            "name": "FortiClient",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiRecorder versions 6.4.x ant\u00e9rieures \u00e0 6.4.6",
          "product": {
            "name": "FortiRecorder",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiClientWindows versions 7.2.x ant\u00e9rieures \u00e0 7.2.2",
          "product": {
            "name": "FortiClient",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiCamera versions ant\u00e9rieures \u00e0 2.1.4",
          "product": {
            "name": "FortiCamera",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiPortal versions 7.4.x ant\u00e9rieures \u00e0 7.4.2",
          "product": {
            "name": "FortiPortal",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiClientEMS versions 7.4.x ant\u00e9rieures \u00e0 7.4.3",
          "product": {
            "name": "FortiClientEMS",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiSwitchManager versions 7.2.x ant\u00e9rieures \u00e0 7.2.6",
          "product": {
            "name": "FortiSwitch",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiOS versions ant\u00e9rieures \u00e0 7.0.15",
          "product": {
            "name": "FortiOS",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiMail versions 7.2.x ant\u00e9rieures \u00e0 7.2.8",
          "product": {
            "name": "FortiMail",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiVoiceUCDesktop versions ant\u00e9rieures \u00e0 7.0",
          "product": {
            "name": "FortiVoice",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiVoice versions 6.4.x ant\u00e9rieures \u00e0 6.4.11",
          "product": {
            "name": "FortiVoice",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiNDR versions 7.4.x ant\u00e9rieures \u00e0 7.4.8",
          "product": {
            "name": "FortiNDR",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiMail versions 7.0.x ant\u00e9rieures \u00e0 7.0.9",
          "product": {
            "name": "FortiMail",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiPortal versions 7.2.x ant\u00e9rieures \u00e0 7.2.6",
          "product": {
            "name": "FortiPortal",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": "",
      "content": "## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des correctifs (cf. section Documentation).",
      "cves": [
        {
          "name": "CVE-2025-25251",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-25251"
        },
        {
          "name": "CVE-2025-47294",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-47294"
        },
        {
          "name": "CVE-2025-24473",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-24473"
        },
        {
          "name": "CVE-2024-54020",
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-54020"
        },
        {
          "name": "CVE-2025-46777",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-46777"
        },
        {
          "name": "CVE-2024-35281",
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-35281"
        },
        {
          "name": "CVE-2025-32756",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-32756"
        },
        {
          "name": "CVE-2025-22252",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-22252"
        },
        {
          "name": "CVE-2025-47295",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-47295"
        },
        {
          "name": "CVE-2025-22859",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-22859"
        }
      ],
      "initial_release_date": "2025-05-13T00:00:00",
      "last_revision_date": "2025-05-13T00:00:00",
      "links": [],
      "reference": "CERTFR-2025-AVI-0399",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2025-05-13T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "D\u00e9ni de service \u00e0 distance"
        },
        {
          "description": "Ex\u00e9cution de code arbitraire \u00e0 distance"
        },
        {
          "description": "Atteinte \u00e0 l\u0027int\u00e9grit\u00e9 des donn\u00e9es"
        },
        {
          "description": "Contournement de la politique de s\u00e9curit\u00e9"
        },
        {
          "description": "Atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es"
        },
        {
          "description": "\u00c9l\u00e9vation de privil\u00e8ges"
        }
      ],
      "summary": "De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans les produits Fortinet. Certaines d\u0027entre elles permettent \u00e0 un attaquant de provoquer une ex\u00e9cution de code arbitraire \u00e0 distance, une \u00e9l\u00e9vation de privil\u00e8ges et un d\u00e9ni de service \u00e0 distance.\n\nFortinet indique que la vuln\u00e9rabilit\u00e9 CVE-2025-32756 est activement exploit\u00e9e.",
      "title": "Multiples vuln\u00e9rabilit\u00e9s dans les produits Fortinet",
      "vendor_advisories": [
        {
          "published_at": "2025-05-13",
          "title": "Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-24-472",
          "url": "https://www.fortiguard.com/psirt/FG-IR-24-472"
        },
        {
          "published_at": "2025-05-13",
          "title": "Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-24-552",
          "url": "https://www.fortiguard.com/psirt/FG-IR-24-552"
        },
        {
          "published_at": "2025-05-13",
          "title": "Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-24-381",
          "url": "https://www.fortiguard.com/psirt/FG-IR-24-381"
        },
        {
          "published_at": "2025-05-13",
          "title": "Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-24-548",
          "url": "https://www.fortiguard.com/psirt/FG-IR-24-548"
        },
        {
          "published_at": "2025-05-13",
          "title": "Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-24-025",
          "url": "https://www.fortiguard.com/psirt/FG-IR-24-025"
        },
        {
          "published_at": "2025-05-13",
          "title": "Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-24-388",
          "url": "https://www.fortiguard.com/psirt/FG-IR-24-388"
        },
        {
          "published_at": "2025-05-13",
          "title": "Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-24-380",
          "url": "https://www.fortiguard.com/psirt/FG-IR-24-380"
        },
        {
          "published_at": "2025-05-13",
          "title": "Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-25-016",
          "url": "https://www.fortiguard.com/psirt/FG-IR-25-016"
        },
        {
          "published_at": "2025-05-13",
          "title": "Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-25-254",
          "url": "https://www.fortiguard.com/psirt/FG-IR-25-254"
        },
        {
          "published_at": "2025-05-13",
          "title": "Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-24-023",
          "url": "https://www.fortiguard.com/psirt/FG-IR-24-023"
        }
      ]
    }

    CERTFR-2024-AVI-0212

    Vulnerability from certfr_avis - Published: 2024-03-13 - Updated: 2024-03-13

    De multiples vulnérabilités ont été découvertes dans les produits Fortinet. Elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, un contournement de la politique de sécurité et une élévation de privilèges.

    Solution

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    Contournement provisoire

    S’il n’est pas possible de procéder à l’installation d’une version corrigeant la vulnérabilité, se référer aux mesures de contournement proposées par l’éditeur à la section Workaround.

    None
    Impacted products
    Vendor Product Description
    Fortinet FortiClientEMS FortiClientEMS 6.2 toutes versions
    Fortinet FortiManager FortiManager versions 6.4.x antérieures à 6.4.14
    Fortinet FortiProxy FortiProxy versions 7.4.x antérieures à 7.4.3
    Fortinet FortiOS FortiOS versions 7.0.x antérieures à 7.0.14
    Fortinet FortiManager FortiManager versions 7.4.x antérieures à 7.4.2
    Fortinet FortiAnalyzer FortiAnalyzer versions 7.2.x antérieures à 7.2.4
    Fortinet FortiProxy FortiProxy versions 7.0.x antérieures à 7.0.15
    Fortinet FortiPortal FortiPortal versions 7.2.x antérieures à 7.2.1
    Fortinet FortiClientEMS FortiClientEMS 6.0 toutes versions
    Fortinet FortiAnalyzer FortiAnalyzer versions 7.4.x antérieures à 7.4.2
    Fortinet FortiAnalyzer FortiAnalyzer-BigData versions 7.2.x antérieures à 7.2.6
    Fortinet FortiAnalyzer FortiAnalyzer versions 7.0.x antérieures à 7.0.10
    Fortinet FortiClientEMS FortiClientEMS 6.4 toutes versions
    Fortinet FortiOS FortiOS versions 6.2.x antérieures à 6.2.16
    Fortinet FortiManager FortiManager versions 7.2.x antérieures à 7.2.4
    Fortinet FortiOS FortiOS versions 7.2.x antérieures à 7.2.7
    Fortinet FortiPortal FortiPortal versions 7.0.x antérieures à 7.0.7
    Fortinet FortiOS FortiOS versions 7.4.x antérieures à 7.4.2
    Fortinet FortiPortal FortiPortal versions antérieures à 7.0.0
    Fortinet FortiClientEMS FortiClientEMS versions 7.0.x antérieures à 7.0.11
    Fortinet FortiClientEMS FortiClientEMS versions 7.2.x antérieures à 7.2.3
    Fortinet FortiAnalyzer FortiAnalyzer-BigData versions 7.4.x antérieures à 7.4.0
    Fortinet FortiManager FortiManager versions 7.0.x. antérieures à 7.0.11
    Fortinet FortiProxy FortiProxy versions 7.2.x antérieures à 7.2.9
    Fortinet FortiProxy FortiProxy versions 2.0.x antérieures à 2.0.14
    Fortinet FortiOS FortiOS versions 6.4.x antérieures à 6.4.15

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "FortiClientEMS 6.2 toutes versions",
          "product": {
            "name": "FortiClientEMS",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiManager versions 6.4.x ant\u00e9rieures \u00e0 6.4.14",
          "product": {
            "name": "FortiManager",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiProxy versions 7.4.x ant\u00e9rieures \u00e0 7.4.3",
          "product": {
            "name": "FortiProxy",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiOS versions 7.0.x ant\u00e9rieures \u00e0 7.0.14",
          "product": {
            "name": "FortiOS",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiManager versions 7.4.x ant\u00e9rieures \u00e0 7.4.2",
          "product": {
            "name": "FortiManager",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiAnalyzer versions 7.2.x ant\u00e9rieures \u00e0 7.2.4",
          "product": {
            "name": "FortiAnalyzer",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiProxy versions 7.0.x ant\u00e9rieures \u00e0 7.0.15",
          "product": {
            "name": "FortiProxy",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiPortal versions 7.2.x ant\u00e9rieures \u00e0 7.2.1",
          "product": {
            "name": "FortiPortal",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiClientEMS 6.0 toutes versions",
          "product": {
            "name": "FortiClientEMS",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiAnalyzer versions 7.4.x ant\u00e9rieures \u00e0 7.4.2",
          "product": {
            "name": "FortiAnalyzer",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiAnalyzer-BigData versions 7.2.x ant\u00e9rieures \u00e0 7.2.6",
          "product": {
            "name": "FortiAnalyzer",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiAnalyzer versions 7.0.x ant\u00e9rieures \u00e0 7.0.10",
          "product": {
            "name": "FortiAnalyzer",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiClientEMS 6.4 toutes versions",
          "product": {
            "name": "FortiClientEMS",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiOS versions 6.2.x ant\u00e9rieures \u00e0 6.2.16",
          "product": {
            "name": "FortiOS",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiManager versions 7.2.x ant\u00e9rieures \u00e0 7.2.4",
          "product": {
            "name": "FortiManager",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiOS versions 7.2.x ant\u00e9rieures \u00e0 7.2.7",
          "product": {
            "name": "FortiOS",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiPortal versions 7.0.x ant\u00e9rieures \u00e0 7.0.7",
          "product": {
            "name": "FortiPortal",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiOS versions 7.4.x ant\u00e9rieures \u00e0 7.4.2",
          "product": {
            "name": "FortiOS",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiPortal versions ant\u00e9rieures \u00e0 7.0.0",
          "product": {
            "name": "FortiPortal",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiClientEMS versions 7.0.x ant\u00e9rieures \u00e0 7.0.11",
          "product": {
            "name": "FortiClientEMS",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiClientEMS versions 7.2.x ant\u00e9rieures \u00e0 7.2.3",
          "product": {
            "name": "FortiClientEMS",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiAnalyzer-BigData versions 7.4.x ant\u00e9rieures \u00e0 7.4.0",
          "product": {
            "name": "FortiAnalyzer",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiManager versions 7.0.x. ant\u00e9rieures \u00e0 7.0.11",
          "product": {
            "name": "FortiManager",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiProxy versions 7.2.x ant\u00e9rieures \u00e0 7.2.9",
          "product": {
            "name": "FortiProxy",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiProxy versions 2.0.x ant\u00e9rieures \u00e0 2.0.14",
          "product": {
            "name": "FortiProxy",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiOS versions 6.4.x ant\u00e9rieures \u00e0 6.4.15",
          "product": {
            "name": "FortiOS",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": null,
      "content": "## Solution\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des\ncorrectifs (cf. section Documentation).\n\n## Contournement provisoire\n\nS\u2019il n\u2019est pas possible de proc\u00e9der \u00e0 l\u2019installation d\u2019une version\ncorrigeant la vuln\u00e9rabilit\u00e9, se r\u00e9f\u00e9rer aux mesures de contournement\npropos\u00e9es par l\u2019\u00e9diteur \u00e0 la section *Workaround*.\n",
      "cves": [
        {
          "name": "CVE-2024-21761",
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-21761"
        },
        {
          "name": "CVE-2023-42790",
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-42790"
        },
        {
          "name": "CVE-2023-41842",
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-41842"
        },
        {
          "name": "CVE-2023-48788",
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-48788"
        },
        {
          "name": "CVE-2024-23112",
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-23112"
        },
        {
          "name": "CVE-2023-46717",
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-46717"
        },
        {
          "name": "CVE-2023-42789",
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-42789"
        },
        {
          "name": "CVE-2023-47534",
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-47534"
        },
        {
          "name": "CVE-2023-36554",
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-36554"
        }
      ],
      "initial_release_date": "2024-03-13T00:00:00",
      "last_revision_date": "2024-03-13T00:00:00",
      "links": [],
      "reference": "CERTFR-2024-AVI-0212",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2024-03-13T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "Atteinte \u00e0 l\u0027int\u00e9grit\u00e9 des donn\u00e9es"
        },
        {
          "description": "Ex\u00e9cution de code arbitraire"
        },
        {
          "description": "Contournement de la politique de s\u00e9curit\u00e9"
        },
        {
          "description": "\u00c9l\u00e9vation de privil\u00e8ges"
        }
      ],
      "summary": "De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans \u003cspan\nclass=\"textit\"\u003eles produits Fortinet\u003c/span\u003e. Elles permettent \u00e0 un\nattaquant de provoquer une ex\u00e9cution de code arbitraire \u00e0 distance, un\ncontournement de la politique de s\u00e9curit\u00e9 et une \u00e9l\u00e9vation de\nprivil\u00e8ges.\n",
      "title": "Multiples vuln\u00e9rabilit\u00e9s dans les produits Fortinet",
      "vendor_advisories": [
        {
          "published_at": null,
          "title": "Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-24-007 du 12 mars 2024",
          "url": "https://www.fortiguard.com/psirt/FG-IR-24-007"
        },
        {
          "published_at": null,
          "title": "Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-23-304 du 12 mars 2024",
          "url": "https://www.fortiguard.com/psirt/FG-IR-23-304"
        },
        {
          "published_at": null,
          "title": "Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-24-016 du 12 mars 2024",
          "url": "https://www.fortiguard.com/psirt/FG-IR-24-016"
        },
        {
          "published_at": null,
          "title": "Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-23-328 du 12 mars 2024",
          "url": "https://www.fortiguard.com/psirt/FG-IR-23-328"
        },
        {
          "published_at": null,
          "title": "Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-23-424 du 12 mars 2024",
          "url": "https://www.fortiguard.com/psirt/FG-IR-23-424"
        },
        {
          "published_at": null,
          "title": "Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-23-390 du 12 mars 2024",
          "url": "https://www.fortiguard.com/psirt/FG-IR-23-390"
        },
        {
          "published_at": null,
          "title": "Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-23-103 du 12 mars 2024",
          "url": "https://www.fortiguard.com/psirt/FG-IR-23-103"
        },
        {
          "published_at": null,
          "title": "Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-24-013 du 12 mars 2024",
          "url": "https://www.fortiguard.com/psirt/FG-IR-24-013"
        }
      ]
    }

    CERTFR-2024-AVI-0108

    Vulnerability from certfr_avis - Published: 2024-02-09 - Updated: 2024-04-10

    De multiples vulnérabilités ont été découvertes dans les produits Fortinet. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, un déni de service à distance et un contournement de la politique de sécurité.

    Solution

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    None
    Impacted products
    Vendor Product Description
    Fortinet FortiOS FortiOS versions 7.4.x antérieures à 7.4.3
    Fortinet FortiProxy FortiProxy versions 7.4.x antérieures à 7.4.3
    Fortinet FortiManager FortiManager versions 7.4.x antérieures à 7.4.2
    Fortinet FortiAnalyzer FortiAnalyzer versions 7.2.x antérieures à 7.2.4
    Fortinet FortiNAC FortiNAC 8.3, 8.5, 8.6, 8.7, 8.8, 9.1 et 9.2 toutes versions
    Fortinet FortiProxy FortiProxy 1.1 toutes versions
    Fortinet FortiNAC FortiNAC versions 7.2.x antérieures à 7.2.3
    Fortinet FortiOS FortiOS versions 7.0.x antérieures à 7.0.14 (Cette version reste affectée par la vulnérabilité CVE-2023-47537)
    Fortinet FortiAnalyzer FortiAnalyzer versions 7.4.x antérieures à 7.4.2
    Fortinet FortiAnalyzer FortiAnalyzer-BigData versions 7.2.x antérieures à 7.2.6
    Fortinet FortiPAM FortiPAM 1.0 toutes versions
    Fortinet FortiProxy FortiProxy 1.2 toutes versions
    Fortinet FortiOS FortiOS versions 6.2.x antérieures à 6.2.16
    Fortinet FortiManager FortiManager versions 7.2.x antérieures à 7.2.4
    Fortinet FortiOS FortiOS versions 7.2.x antérieures à 7.2.7
    Fortinet FortiPAM FortiPAM 1.2 toutes versions
    Fortinet FortiProxy FortiProxy 1.0 toutes versions
    Fortinet FortiClientEMS FortiClientEMS versions 7.0.x antérieures à 7.0.11
    Fortinet FortiClientEMS FortiClientEMS versions 7.2.x antérieures à 7.2.3
    Fortinet FortiOS FortiOS 6.0 toutes versions
    Fortinet FortiWeb FortiWeb versions 7.4.x antérieures à 7.4.3
    Fortinet FortiClientEMS FortiClientEMS 6.2 et 6.4 toutes versions
    Fortinet FortiNAC FortiNAC versions 9.4.x antérieures à 9.4.4
    Fortinet FortiProxy FortiProxy 7.0 toutes versions
    Fortinet FortiPAM FortiPAM 1.1 toutes versions
    Fortinet FortiManager FortiManager 6.2, 6.4 et 7.0 toutes versions
    Fortinet FortiProxy FortiProxy versions 7.2.x antérieures à 7.2.9
    Fortinet FortiAnalyzer FortiAnalyzer-BigData 6.2, 6.4 et 7.0 toutes versions
    Fortinet FortiProxy FortiProxy versions 2.0.x antérieures à 2.0.14
    Fortinet FortiOS FortiOS versions 6.4.x antérieures à 6.4.15
    Fortinet FortiAnalyzer FortiAnalyzer 6.2, 6.4 et 7.0 toutes versions

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "FortiOS versions 7.4.x ant\u00e9rieures \u00e0 7.4.3",
          "product": {
            "name": "FortiOS",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiProxy versions 7.4.x ant\u00e9rieures \u00e0 7.4.3",
          "product": {
            "name": "FortiProxy",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiManager versions 7.4.x ant\u00e9rieures \u00e0 7.4.2",
          "product": {
            "name": "FortiManager",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiAnalyzer versions 7.2.x ant\u00e9rieures \u00e0 7.2.4",
          "product": {
            "name": "FortiAnalyzer",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiNAC 8.3, 8.5, 8.6, 8.7, 8.8, 9.1 et 9.2 toutes versions",
          "product": {
            "name": "FortiNAC",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiProxy 1.1 toutes versions",
          "product": {
            "name": "FortiProxy",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiNAC versions 7.2.x ant\u00e9rieures \u00e0 7.2.3",
          "product": {
            "name": "FortiNAC",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiOS versions 7.0.x ant\u00e9rieures \u00e0 7.0.14 (Cette version reste affect\u00e9e par la vuln\u00e9rabilit\u00e9 CVE-2023-47537)",
          "product": {
            "name": "FortiOS",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiAnalyzer versions 7.4.x ant\u00e9rieures \u00e0 7.4.2",
          "product": {
            "name": "FortiAnalyzer",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiAnalyzer-BigData versions 7.2.x ant\u00e9rieures \u00e0 7.2.6",
          "product": {
            "name": "FortiAnalyzer",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiPAM 1.0 toutes versions",
          "product": {
            "name": "FortiPAM",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiProxy 1.2 toutes versions",
          "product": {
            "name": "FortiProxy",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiOS versions 6.2.x ant\u00e9rieures \u00e0 6.2.16",
          "product": {
            "name": "FortiOS",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiManager versions 7.2.x ant\u00e9rieures \u00e0 7.2.4",
          "product": {
            "name": "FortiManager",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiOS versions 7.2.x ant\u00e9rieures \u00e0 7.2.7",
          "product": {
            "name": "FortiOS",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiPAM 1.2 toutes versions",
          "product": {
            "name": "FortiPAM",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiProxy 1.0 toutes versions",
          "product": {
            "name": "FortiProxy",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiClientEMS versions 7.0.x ant\u00e9rieures \u00e0 7.0.11",
          "product": {
            "name": "FortiClientEMS",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiClientEMS versions 7.2.x ant\u00e9rieures \u00e0 7.2.3",
          "product": {
            "name": "FortiClientEMS",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiOS 6.0 toutes versions",
          "product": {
            "name": "FortiOS",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiWeb versions 7.4.x ant\u00e9rieures \u00e0 7.4.3",
          "product": {
            "name": "FortiWeb",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiClientEMS 6.2 et 6.4 toutes versions",
          "product": {
            "name": "FortiClientEMS",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiNAC versions 9.4.x ant\u00e9rieures \u00e0 9.4.4",
          "product": {
            "name": "FortiNAC",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiProxy 7.0 toutes versions",
          "product": {
            "name": "FortiProxy",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiPAM 1.1 toutes versions",
          "product": {
            "name": "FortiPAM",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiManager 6.2, 6.4 et 7.0 toutes versions",
          "product": {
            "name": "FortiManager",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiProxy versions 7.2.x ant\u00e9rieures \u00e0 7.2.9",
          "product": {
            "name": "FortiProxy",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiAnalyzer-BigData 6.2, 6.4 et 7.0 toutes versions",
          "product": {
            "name": "FortiAnalyzer",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiProxy versions 2.0.x ant\u00e9rieures \u00e0 2.0.14",
          "product": {
            "name": "FortiProxy",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiOS versions 6.4.x ant\u00e9rieures \u00e0 6.4.15",
          "product": {
            "name": "FortiOS",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiAnalyzer 6.2, 6.4 et 7.0 toutes versions",
          "product": {
            "name": "FortiAnalyzer",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": null,
      "content": "## Solution\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des\ncorrectifs (cf. section Documentation).\n",
      "cves": [
        {
          "name": "CVE-2023-44487",
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-44487"
        },
        {
          "name": "CVE-2023-45581",
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-45581"
        },
        {
          "name": "CVE-2023-47537",
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-47537"
        },
        {
          "name": "CVE-2024-21762",
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-21762"
        },
        {
          "name": "CVE-2023-26206",
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-26206"
        },
        {
          "name": "CVE-2023-44253",
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-44253"
        },
        {
          "name": "CVE-2024-23113",
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-23113"
        }
      ],
      "initial_release_date": "2024-02-09T00:00:00",
      "last_revision_date": "2024-04-10T00:00:00",
      "links": [],
      "reference": "CERTFR-2024-AVI-0108",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2024-02-09T00:00:00.000000"
        },
        {
          "description": "Ajout des syst\u00e8mes affect\u00e9s",
          "revision_date": "2024-02-15T00:00:00.000000"
        },
        {
          "description": "Ajout des syst\u00e8mes affect\u00e9s",
          "revision_date": "2024-04-10T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "D\u00e9ni de service \u00e0 distance"
        },
        {
          "description": "Injection de code indirecte \u00e0 distance (XSS)"
        },
        {
          "description": "Ex\u00e9cution de code arbitraire \u00e0 distance"
        },
        {
          "description": "Atteinte \u00e0 l\u0027int\u00e9grit\u00e9 des donn\u00e9es"
        },
        {
          "description": "Contournement de la politique de s\u00e9curit\u00e9"
        },
        {
          "description": "Atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es"
        }
      ],
      "summary": "De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans \u003cspan\nclass=\"textit\"\u003eles produits Fortinet\u003c/span\u003e. Certaines d\u0027entre elles\npermettent \u00e0 un attaquant de provoquer une ex\u00e9cution de code arbitraire\n\u00e0 distance, un d\u00e9ni de service \u00e0 distance et un contournement de la\npolitique de s\u00e9curit\u00e9.\n",
      "title": "Multiples vuln\u00e9rabilit\u00e9s dans les produits Fortinet",
      "vendor_advisories": [
        {
          "published_at": null,
          "title": "Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-23-268 du 08 f\u00e9vrier 2024",
          "url": "https://www.fortiguard.com/psirt/FG-IR-23-268"
        },
        {
          "published_at": null,
          "title": "Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-23-301 du 08 f\u00e9vrier 2024",
          "url": "https://www.fortiguard.com/psirt/FG-IR-23-301"
        },
        {
          "published_at": null,
          "title": "Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-23-063 du 08 f\u00e9vrier 2024",
          "url": "https://www.fortiguard.com/psirt/FG-IR-23-063"
        },
        {
          "published_at": null,
          "title": "Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-23-357 du 08 f\u00e9vrier 2024",
          "url": "https://www.fortiguard.com/psirt/FG-IR-23-357"
        },
        {
          "published_at": null,
          "title": "Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-23-397 du 08 f\u00e9vrier 2024",
          "url": "https://www.fortiguard.com/psirt/FG-IR-23-397"
        },
        {
          "published_at": null,
          "title": "Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-24-029 du 08 f\u00e9vrier 2024",
          "url": "https://www.fortiguard.com/psirt/FG-IR-24-029"
        },
        {
          "published_at": null,
          "title": "Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-24-015 du 08 f\u00e9vrier 2024",
          "url": "https://www.fortiguard.com/psirt/FG-IR-24-015"
        }
      ]
    }

    CERTFR-2021-AVI-927

    Vulnerability from certfr_avis - Published: 2021-12-08 - Updated: 2021-12-08

    De multiples vulnérabilités ont été découvertes dans les produits Fortinet. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une atteinte à l'intégrité des données, une atteinte à la confidentialité des données et un contournement de la politique de sécurité.

    Solution

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    None
    Impacted products
    Vendor Product Description
    Fortinet FortiGate FortiGate versions 7.0.x antérieures à 7.0.2
    Fortinet FortiClient FortiClient pour Linux, Mac et Windows versions 7.0.x antérieures à 7.0.2
    Fortinet FortiGate FortiGate versions 6.4.x antérieures à 6.4.7
    Fortinet FortiProxy FortiProxy versions 1.x antérieures à 1.2.12
    Fortinet FortiOS FortiOS versions 6.2.x antérieures à 6.2.10
    Fortinet FortiNAC FortiNAC versions 8.8.x antérieures à 8.8.10
    Fortinet FortiWeb FortiWeb versions 6.4.x antérieures à 6.4.2
    Fortinet FortiOS FortiOS versions 7.0.x antérieures à 7.0.3
    Fortinet FortiADC FortiADC versions 6.1.x antérieures à 6.1.4
    Fortinet FortiWeb FortiWeb versions 6.2.x antérieures à 6.2.6
    Fortinet FortiSandbox FortiSandbox versions 3.x antérieures à 3.2.3
    Fortinet FortiGate FortiGate versions 6.2.x antérieures à 6.2.10
    Fortinet FortiOS FortiOS versions 5.6.x antérieures à 5.6.14
    Fortinet FortiOS FortiOS versions 6.4.x antérieures à 6.4.8
    Fortinet FortiOS FortiOS versions 6.0.x antérieures à 6.0.14
    Fortinet FortiADC FortiADC version 6.2.x antérieures à 6.2.1
    Fortinet FortiClient FortiClient pour Linux, Mac et Windows versions 6.4.x antérieures à 6.4.7
    Fortinet FortiProxy FortiProxy versions 2.x antérieures à 2.0.4
    Fortinet FortiWeb FortiWeb versions 6.3.x antérieures à 6.3.16
    Fortinet FortiOS FortiOS-6K7K versions 6.4.x antérieures à 6.4.3
    Fortinet FortiSandbox FortiSandbox versions 4.x antérieures à 4.0.1
    Fortinet FortiClientEMS FortiClientEMS versions 7.0.x antérieures à 7.0.2
    Fortinet FortiClientEMS FortiClientEMS versions 6.4.x antérieures à 6.4.7
    Fortinet N/A Meru AP versions antérieures à 8.6.2
    Fortinet FortiProxy FortiProxy versions 7.x antérieures à 7.0.1
    Fortinet N/A FortiWLC versions antérieures à 8.6.2
    Fortinet FortiNAC FortiNAC versions 9.2.x antérieures à 9.2.1
    Fortinet FortiNAC FortiNAC versions 9.1.x antérieures à 9.1.4
    Fortinet N/A FortiAuthenticator versions antérieures à 6.4.1
    Fortinet FortiOS FortiOS-6K7K versions 6.2.x antérieures à 6.2.8
    References
    Bulletin de sécurité Fortinet FG-IR-21-201 du 8 décembre 2021 None vendor-advisory
    Bulletin de sécurité Fortinet FG-IR-21-130 du 8 décembre 2021 None vendor-advisory
    Bulletin de sécurité Fortinet FG-IR-21-134 du 8 décembre 2021 None vendor-advisory
    Bulletin de sécurité Fortinet FG-IR-21-049 du 8 décembre 2021 None vendor-advisory
    Bulletin de sécurité Fortinet FG-IR-21-075 du 8 décembre 2021 None vendor-advisory
    Bulletin de sécurité Fortinet FG-IR-21-122 du 8 décembre 2021 None vendor-advisory
    Bulletin de sécurité Fortinet FG-IR-21-140 du 8 décembre 2021 None vendor-advisory
    Bulletin de sécurité Fortinet FG-IR-21-051 du 8 décembre 2021 None vendor-advisory
    Bulletin de sécurité Fortinet FG-IR-21-192 du 8 décembre 2021 None vendor-advisory
    Bulletin de sécurité Fortinet FG-IR-21-138 du 8 décembre 2021 None vendor-advisory
    Bulletin de sécurité Fortinet FG-IR-21-152 du 8 décembre 2021 None vendor-advisory
    Bulletin de sécurité Fortinet FG-IR-20-127 du 8 décembre 2021 None vendor-advisory
    Bulletin de sécurité Fortinet FG-IR-21-120 du 8 décembre 2021 None vendor-advisory
    Bulletin de sécurité Fortinet FG-IR-20-222 du 8 décembre 2021 None vendor-advisory
    Bulletin de sécurité Fortinet FG-IR-21-118 du 8 décembre 2021 None vendor-advisory
    Bulletin de sécurité Fortinet FG-IR-21-212 du 8 décembre 2021 None vendor-advisory
    Bulletin de sécurité Fortinet FG-IR-21-133 du 8 décembre 2021 None vendor-advisory
    Bulletin de sécurité Fortinet FG-IR-20-131 du 8 décembre 2021 None vendor-advisory
    Bulletin de sécurité Fortinet FG-IR-21-173 du 8 décembre 2021 None vendor-advisory
    Bulletin de sécurité Fortinet FG-IR-21-182 du 8 décembre 2021 None vendor-advisory
    Bulletin de sécurité Fortinet FG-IR-21-114 du 8 décembre 2021 None vendor-advisory
    Bulletin de sécurité Fortinet FG-IR-21-111 du 8 décembre 2021 None vendor-advisory
    Bulletin de sécurité Fortinet FG-IR-21-115 du 8 décembre 2021 None vendor-advisory
    Bulletin de sécurité Fortinet FG-IR-21-123 du 8 décembre 2021 None vendor-advisory
    Bulletin de sécurité Fortinet FG-IR-21-181 du 8 décembre 2021 None vendor-advisory
    Bulletin de sécurité Fortinet FG-IR-21-160 du 8 décembre 2021 None vendor-advisory
    Bulletin de sécurité Fortinet FG-IR-21-129 du 8 décembre 2021 None vendor-advisory
    Bulletin de sécurité Fortinet FG-IR-21-200 du 8 décembre 2021 None vendor-advisory
    Bulletin de sécurité Fortinet FG-IR-21-167 du 8 décembre 2021 None vendor-advisory
    Bulletin de sécurité Fortinet FG-IR-21-157 du 8 décembre 2021 None vendor-advisory
    Bulletin de sécurité Fortinet FG-IR-21-139 du 8 décembre 2021 None vendor-advisory
    Bulletin de sécurité Fortinet FG-IR-21-168 du 8 décembre 2021 None vendor-advisory
    Bulletin de sécurité Fortinet FG-IR-21-156 du 8 décembre 2021 None vendor-advisory
    Bulletin de sécurité Fortinet FG-IR-21-188 du 8 décembre 2021 None vendor-advisory
    Bulletin de sécurité Fortinet FG-IR-20-158 du 8 décembre 2021 None vendor-advisory
    Bulletin de sécurité Fortinet FG-IR-21-178 du 8 décembre 2021 None vendor-advisory
    Bulletin de sécurité Fortinet FG-IR-21-131 du 8 décembre 2021 None vendor-advisory
    Bulletin de sécurité Fortinet FG-IR-21-004 du 8 décembre 2021 None vendor-advisory

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "FortiGate versions 7.0.x ant\u00e9rieures \u00e0 7.0.2",
          "product": {
            "name": "FortiGate",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiClient pour Linux, Mac et Windows versions 7.0.x ant\u00e9rieures \u00e0 7.0.2",
          "product": {
            "name": "FortiClient",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiGate versions 6.4.x ant\u00e9rieures \u00e0 6.4.7",
          "product": {
            "name": "FortiGate",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiProxy versions 1.x ant\u00e9rieures \u00e0 1.2.12",
          "product": {
            "name": "FortiProxy",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiOS versions 6.2.x ant\u00e9rieures \u00e0 6.2.10",
          "product": {
            "name": "FortiOS",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiNAC versions 8.8.x ant\u00e9rieures \u00e0 8.8.10",
          "product": {
            "name": "FortiNAC",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiWeb versions 6.4.x ant\u00e9rieures \u00e0 6.4.2",
          "product": {
            "name": "FortiWeb",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiOS versions 7.0.x ant\u00e9rieures \u00e0 7.0.3",
          "product": {
            "name": "FortiOS",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiADC versions 6.1.x ant\u00e9rieures \u00e0 6.1.4",
          "product": {
            "name": "FortiADC",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiWeb versions 6.2.x ant\u00e9rieures \u00e0 6.2.6",
          "product": {
            "name": "FortiWeb",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiSandbox versions 3.x ant\u00e9rieures \u00e0 3.2.3",
          "product": {
            "name": "FortiSandbox",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiGate versions 6.2.x ant\u00e9rieures \u00e0 6.2.10",
          "product": {
            "name": "FortiGate",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiOS versions 5.6.x ant\u00e9rieures \u00e0 5.6.14",
          "product": {
            "name": "FortiOS",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiOS versions 6.4.x ant\u00e9rieures \u00e0 6.4.8",
          "product": {
            "name": "FortiOS",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiOS versions 6.0.x ant\u00e9rieures \u00e0 6.0.14",
          "product": {
            "name": "FortiOS",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiADC version 6.2.x ant\u00e9rieures \u00e0 6.2.1",
          "product": {
            "name": "FortiADC",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiClient pour Linux, Mac et Windows versions 6.4.x ant\u00e9rieures \u00e0 6.4.7",
          "product": {
            "name": "FortiClient",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiProxy versions 2.x ant\u00e9rieures \u00e0 2.0.4",
          "product": {
            "name": "FortiProxy",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiWeb versions 6.3.x ant\u00e9rieures \u00e0 6.3.16",
          "product": {
            "name": "FortiWeb",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiOS-6K7K versions 6.4.x ant\u00e9rieures \u00e0 6.4.3",
          "product": {
            "name": "FortiOS",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiSandbox versions 4.x ant\u00e9rieures \u00e0 4.0.1",
          "product": {
            "name": "FortiSandbox",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiClientEMS versions 7.0.x ant\u00e9rieures \u00e0 7.0.2",
          "product": {
            "name": "FortiClientEMS",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiClientEMS versions 6.4.x ant\u00e9rieures \u00e0 6.4.7",
          "product": {
            "name": "FortiClientEMS",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "Meru AP versions ant\u00e9rieures \u00e0 8.6.2",
          "product": {
            "name": "N/A",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiProxy versions 7.x ant\u00e9rieures \u00e0 7.0.1",
          "product": {
            "name": "FortiProxy",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiWLC versions ant\u00e9rieures \u00e0 8.6.2",
          "product": {
            "name": "N/A",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiNAC versions 9.2.x ant\u00e9rieures \u00e0 9.2.1",
          "product": {
            "name": "FortiNAC",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiNAC versions 9.1.x ant\u00e9rieures \u00e0 9.1.4",
          "product": {
            "name": "FortiNAC",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiAuthenticator versions ant\u00e9rieures \u00e0 6.4.1",
          "product": {
            "name": "N/A",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiOS-6K7K versions 6.2.x ant\u00e9rieures \u00e0 6.2.8",
          "product": {
            "name": "FortiOS",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": null,
      "content": "## Solution\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des\ncorrectifs (cf. section Documentation).\n",
      "cves": [
        {
          "name": "CVE-2021-43068",
          "url": "https://www.cve.org/CVERecord?id=CVE-2021-43068"
        },
        {
          "name": "CVE-2021-44168",
          "url": "https://www.cve.org/CVERecord?id=CVE-2021-44168"
        },
        {
          "name": "CVE-2021-36194",
          "url": "https://www.cve.org/CVERecord?id=CVE-2021-36194"
        },
        {
          "name": "CVE-2021-41028",
          "url": "https://www.cve.org/CVERecord?id=CVE-2021-41028"
        },
        {
          "name": "CVE-2021-36195",
          "url": "https://www.cve.org/CVERecord?id=CVE-2021-36195"
        },
        {
          "name": "CVE-2021-41014",
          "url": "https://www.cve.org/CVERecord?id=CVE-2021-41014"
        },
        {
          "name": "CVE-2021-41030",
          "url": "https://www.cve.org/CVERecord?id=CVE-2021-41030"
        },
        {
          "name": "CVE-2021-43067",
          "url": "https://www.cve.org/CVERecord?id=CVE-2021-43067"
        },
        {
          "name": "CVE-2021-41017",
          "url": "https://www.cve.org/CVERecord?id=CVE-2021-41017"
        },
        {
          "name": "CVE-2021-43064",
          "url": "https://www.cve.org/CVERecord?id=CVE-2021-43064"
        },
        {
          "name": "CVE-2021-41021",
          "url": "https://www.cve.org/CVERecord?id=CVE-2021-41021"
        },
        {
          "name": "CVE-2021-42759",
          "url": "https://www.cve.org/CVERecord?id=CVE-2021-42759"
        },
        {
          "name": "CVE-2021-43071",
          "url": "https://www.cve.org/CVERecord?id=CVE-2021-43071"
        },
        {
          "name": "CVE-2021-36173",
          "url": "https://www.cve.org/CVERecord?id=CVE-2021-36173"
        },
        {
          "name": "CVE-2021-41024",
          "url": "https://www.cve.org/CVERecord?id=CVE-2021-41024"
        },
        {
          "name": "CVE-2021-42752",
          "url": "https://www.cve.org/CVERecord?id=CVE-2021-42752"
        },
        {
          "name": "CVE-2021-41025",
          "url": "https://www.cve.org/CVERecord?id=CVE-2021-41025"
        },
        {
          "name": "CVE-2021-41015",
          "url": "https://www.cve.org/CVERecord?id=CVE-2021-41015"
        },
        {
          "name": "CVE-2021-43065",
          "url": "https://www.cve.org/CVERecord?id=CVE-2021-43065"
        },
        {
          "name": "CVE-2021-26110",
          "url": "https://www.cve.org/CVERecord?id=CVE-2021-26110"
        },
        {
          "name": "CVE-2021-41013",
          "url": "https://www.cve.org/CVERecord?id=CVE-2021-41013"
        },
        {
          "name": "CVE-2021-26108",
          "url": "https://www.cve.org/CVERecord?id=CVE-2021-26108"
        },
        {
          "name": "CVE-2021-43204",
          "url": "https://www.cve.org/CVERecord?id=CVE-2021-43204"
        },
        {
          "name": "CVE-2021-42758",
          "url": "https://www.cve.org/CVERecord?id=CVE-2021-42758"
        },
        {
          "name": "CVE-2021-41029",
          "url": "https://www.cve.org/CVERecord?id=CVE-2021-41029"
        },
        {
          "name": "CVE-2021-42760",
          "url": "https://www.cve.org/CVERecord?id=CVE-2021-42760"
        },
        {
          "name": "CVE-2021-41026",
          "url": "https://www.cve.org/CVERecord?id=CVE-2021-41026"
        },
        {
          "name": "CVE-2021-41027",
          "url": "https://www.cve.org/CVERecord?id=CVE-2021-41027"
        },
        {
          "name": "CVE-2021-36189",
          "url": "https://www.cve.org/CVERecord?id=CVE-2021-36189"
        },
        {
          "name": "CVE-2021-36180",
          "url": "https://www.cve.org/CVERecord?id=CVE-2021-36180"
        },
        {
          "name": "CVE-2021-36191",
          "url": "https://www.cve.org/CVERecord?id=CVE-2021-36191"
        },
        {
          "name": "CVE-2021-42757",
          "url": "https://www.cve.org/CVERecord?id=CVE-2021-42757"
        },
        {
          "name": "CVE-2021-32591",
          "url": "https://www.cve.org/CVERecord?id=CVE-2021-32591"
        },
        {
          "name": "CVE-2021-36190",
          "url": "https://www.cve.org/CVERecord?id=CVE-2021-36190"
        },
        {
          "name": "CVE-2021-26109",
          "url": "https://www.cve.org/CVERecord?id=CVE-2021-26109"
        },
        {
          "name": "CVE-2021-26103",
          "url": "https://www.cve.org/CVERecord?id=CVE-2021-26103"
        },
        {
          "name": "CVE-2021-36167",
          "url": "https://www.cve.org/CVERecord?id=CVE-2021-36167"
        },
        {
          "name": "CVE-2021-43063",
          "url": "https://www.cve.org/CVERecord?id=CVE-2021-43063"
        },
        {
          "name": "CVE-2021-36188",
          "url": "https://www.cve.org/CVERecord?id=CVE-2021-36188"
        }
      ],
      "initial_release_date": "2021-12-08T00:00:00",
      "last_revision_date": "2021-12-08T00:00:00",
      "links": [],
      "reference": "CERTFR-2021-AVI-927",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2021-12-08T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "D\u00e9ni de service \u00e0 distance"
        },
        {
          "description": "Injection de code indirecte \u00e0 distance (XSS)"
        },
        {
          "description": "Injection de requ\u00eates ill\u00e9gitimes par rebond (CSRF)"
        },
        {
          "description": "Ex\u00e9cution de code arbitraire \u00e0 distance"
        },
        {
          "description": "Atteinte \u00e0 l\u0027int\u00e9grit\u00e9 des donn\u00e9es"
        },
        {
          "description": "Contournement de la politique de s\u00e9curit\u00e9"
        },
        {
          "description": "Atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es"
        },
        {
          "description": "\u00c9l\u00e9vation de privil\u00e8ges"
        }
      ],
      "summary": "De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans les produits\nFortinet. Certaines d\u0027entre elles permettent \u00e0 un attaquant de provoquer\nune ex\u00e9cution de code arbitraire \u00e0 distance, une atteinte \u00e0 l\u0027int\u00e9grit\u00e9\ndes donn\u00e9es, une atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es et un\ncontournement de la politique de s\u00e9curit\u00e9.\n",
      "title": "Multiples vuln\u00e9rabilit\u00e9s dans les produits Fortinet",
      "vendor_advisories": [
        {
          "published_at": null,
          "title": "Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-21-201 du 8 d\u00e9cembre 2021",
          "url": "https://www.fortiguard.com/psirt/FG-IR-21-201"
        },
        {
          "published_at": null,
          "title": "Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-21-130 du 8 d\u00e9cembre 2021",
          "url": "https://www.fortiguard.com/psirt/FG-IR-21-130"
        },
        {
          "published_at": null,
          "title": "Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-21-134 du 8 d\u00e9cembre 2021",
          "url": "https://www.fortiguard.com/psirt/FG-IR-21-134"
        },
        {
          "published_at": null,
          "title": "Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-21-049 du 8 d\u00e9cembre 2021",
          "url": "https://www.fortiguard.com/psirt/FG-IR-21-049"
        },
        {
          "published_at": null,
          "title": "Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-21-075 du 8 d\u00e9cembre 2021",
          "url": "https://www.fortiguard.com/psirt/FG-IR-21-075"
        },
        {
          "published_at": null,
          "title": "Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-21-122 du 8 d\u00e9cembre 2021",
          "url": "https://www.fortiguard.com/psirt/FG-IR-21-122"
        },
        {
          "published_at": null,
          "title": "Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-21-140 du 8 d\u00e9cembre 2021",
          "url": "https://www.fortiguard.com/psirt/FG-IR-21-140"
        },
        {
          "published_at": null,
          "title": "Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-21-051 du 8 d\u00e9cembre 2021",
          "url": "https://www.fortiguard.com/psirt/FG-IR-21-051"
        },
        {
          "published_at": null,
          "title": "Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-21-192 du 8 d\u00e9cembre 2021",
          "url": "https://www.fortiguard.com/psirt/FG-IR-21-192"
        },
        {
          "published_at": null,
          "title": "Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-21-138 du 8 d\u00e9cembre 2021",
          "url": "https://www.fortiguard.com/psirt/FG-IR-21-138"
        },
        {
          "published_at": null,
          "title": "Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-21-152 du 8 d\u00e9cembre 2021",
          "url": "https://www.fortiguard.com/psirt/FG-IR-21-152"
        },
        {
          "published_at": null,
          "title": "Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-20-127 du 8 d\u00e9cembre 2021",
          "url": "https://www.fortiguard.com/psirt/FG-IR-20-127"
        },
        {
          "published_at": null,
          "title": "Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-21-120 du 8 d\u00e9cembre 2021",
          "url": "https://www.fortiguard.com/psirt/FG-IR-21-120"
        },
        {
          "published_at": null,
          "title": "Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-20-222 du 8 d\u00e9cembre 2021",
          "url": "https://www.fortiguard.com/psirt/FG-IR-20-222"
        },
        {
          "published_at": null,
          "title": "Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-21-118 du 8 d\u00e9cembre 2021",
          "url": "https://www.fortiguard.com/psirt/FG-IR-21-118"
        },
        {
          "published_at": null,
          "title": "Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-21-212 du 8 d\u00e9cembre 2021",
          "url": "https://www.fortiguard.com/psirt/FG-IR-21-212"
        },
        {
          "published_at": null,
          "title": "Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-21-133 du 8 d\u00e9cembre 2021",
          "url": "https://www.fortiguard.com/psirt/FG-IR-21-133"
        },
        {
          "published_at": null,
          "title": "Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-20-131 du 8 d\u00e9cembre 2021",
          "url": "https://www.fortiguard.com/psirt/FG-IR-20-131"
        },
        {
          "published_at": null,
          "title": "Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-21-173 du 8 d\u00e9cembre 2021",
          "url": "https://www.fortiguard.com/psirt/FG-IR-21-173"
        },
        {
          "published_at": null,
          "title": "Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-21-182 du 8 d\u00e9cembre 2021",
          "url": "https://www.fortiguard.com/psirt/FG-IR-21-182"
        },
        {
          "published_at": null,
          "title": "Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-21-114 du 8 d\u00e9cembre 2021",
          "url": "https://www.fortiguard.com/psirt/FG-IR-21-114"
        },
        {
          "published_at": null,
          "title": "Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-21-111 du 8 d\u00e9cembre 2021",
          "url": "https://www.fortiguard.com/psirt/FG-IR-21-111"
        },
        {
          "published_at": null,
          "title": "Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-21-115 du 8 d\u00e9cembre 2021",
          "url": "https://www.fortiguard.com/psirt/FG-IR-21-115"
        },
        {
          "published_at": null,
          "title": "Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-21-123 du 8 d\u00e9cembre 2021",
          "url": "https://www.fortiguard.com/psirt/FG-IR-21-123"
        },
        {
          "published_at": null,
          "title": "Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-21-181 du 8 d\u00e9cembre 2021",
          "url": "https://www.fortiguard.com/psirt/FG-IR-21-181"
        },
        {
          "published_at": null,
          "title": "Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-21-160 du 8 d\u00e9cembre 2021",
          "url": "https://www.fortiguard.com/psirt/FG-IR-21-160"
        },
        {
          "published_at": null,
          "title": "Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-21-129 du 8 d\u00e9cembre 2021",
          "url": "https://www.fortiguard.com/psirt/FG-IR-21-129"
        },
        {
          "published_at": null,
          "title": "Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-21-200 du 8 d\u00e9cembre 2021",
          "url": "https://www.fortiguard.com/psirt/FG-IR-21-200"
        },
        {
          "published_at": null,
          "title": "Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-21-167 du 8 d\u00e9cembre 2021",
          "url": "https://www.fortiguard.com/psirt/FG-IR-21-167"
        },
        {
          "published_at": null,
          "title": "Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-21-157 du 8 d\u00e9cembre 2021",
          "url": "https://www.fortiguard.com/psirt/FG-IR-21-157"
        },
        {
          "published_at": null,
          "title": "Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-21-139 du 8 d\u00e9cembre 2021",
          "url": "https://www.fortiguard.com/psirt/FG-IR-21-139"
        },
        {
          "published_at": null,
          "title": "Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-21-168 du 8 d\u00e9cembre 2021",
          "url": "https://www.fortiguard.com/psirt/FG-IR-21-168"
        },
        {
          "published_at": null,
          "title": "Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-21-156 du 8 d\u00e9cembre 2021",
          "url": "https://www.fortiguard.com/psirt/FG-IR-21-156"
        },
        {
          "published_at": null,
          "title": "Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-21-188 du 8 d\u00e9cembre 2021",
          "url": "https://www.fortiguard.com/psirt/FG-IR-21-188"
        },
        {
          "published_at": null,
          "title": "Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-20-158 du 8 d\u00e9cembre 2021",
          "url": "https://www.fortiguard.com/psirt/FG-IR-20-158"
        },
        {
          "published_at": null,
          "title": "Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-21-178 du 8 d\u00e9cembre 2021",
          "url": "https://www.fortiguard.com/psirt/FG-IR-21-178"
        },
        {
          "published_at": null,
          "title": "Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-21-131 du 8 d\u00e9cembre 2021",
          "url": "https://www.fortiguard.com/psirt/FG-IR-21-131"
        },
        {
          "published_at": null,
          "title": "Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-21-004 du 8 d\u00e9cembre 2021",
          "url": "https://www.fortiguard.com/psirt/FG-IR-21-004"
        }
      ]
    }

    CERTFR-2021-AVI-845

    Vulnerability from certfr_avis - Published: 2021-11-04 - Updated: 2021-11-04

    De multiples vulnérabilités ont été découvertes dans les produits Fortinet. Certaines d'entre elles permettent à un attaquant de provoquer un déni de service à distance, un contournement de la politique de sécurité et une atteinte à la confidentialité des données.

    Solution

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    None
    Impacted products
    Vendor Product Description
    Fortinet N/A FortiClientMac versions antérieures à 6.4.6, 7.0.1
    Fortinet FortiADC FortiADC versions antérieures à 5.4.4, 6.0.1
    Fortinet FortiSIEM FortiSIEM Windows Agent versions antérieures à 4.1.5
    Fortinet N/A FortiClientWindows versions antérieures à 6.4.3, 7.0.2
    Fortinet FortiAnalyzer FortiAnalyzer versions antérieures à 6.0.7, 6.4.5
    Fortinet FortiSIEM FortiSIEM versions antérieures à 6.3.0
    Fortinet FortiClientEMS FortiClientEMS versions antérieures à 6.4.2, 7.0.0
    Fortinet FortiDDoS FortiDDoS-F versions antérieures à 6.2.0
    Fortinet FortiPortal FortiPortal versions antérieures à 5.2.7, 5.3.7, 6.0.6, 7.0.0
    Fortinet FortiDDoS FortiDDoS versions antérieures à 5.5.0
    Fortinet FortiManager FortiManager versions antérieures à 6.4.7, 7.0.2
    Fortinet FortiGate FortiGate versions antérieures à 6.4.7

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "FortiClientMac versions ant\u00e9rieures \u00e0 6.4.6, 7.0.1",
          "product": {
            "name": "N/A",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiADC versions ant\u00e9rieures \u00e0 5.4.4, 6.0.1",
          "product": {
            "name": "FortiADC",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiSIEM Windows Agent versions ant\u00e9rieures \u00e0 4.1.5",
          "product": {
            "name": "FortiSIEM",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiClientWindows versions ant\u00e9rieures \u00e0 6.4.3, 7.0.2",
          "product": {
            "name": "N/A",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiAnalyzer versions ant\u00e9rieures \u00e0 6.0.7, 6.4.5",
          "product": {
            "name": "FortiAnalyzer",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiSIEM versions ant\u00e9rieures \u00e0 6.3.0",
          "product": {
            "name": "FortiSIEM",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiClientEMS versions ant\u00e9rieures \u00e0 6.4.2, 7.0.0",
          "product": {
            "name": "FortiClientEMS",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiDDoS-F versions ant\u00e9rieures \u00e0 6.2.0",
          "product": {
            "name": "FortiDDoS",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiPortal versions ant\u00e9rieures \u00e0 5.2.7, 5.3.7, 6.0.6, 7.0.0",
          "product": {
            "name": "FortiPortal",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiDDoS versions ant\u00e9rieures \u00e0 5.5.0",
          "product": {
            "name": "FortiDDoS",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiManager versions ant\u00e9rieures \u00e0 6.4.7, 7.0.2",
          "product": {
            "name": "FortiManager",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        },
        {
          "description": "FortiGate versions ant\u00e9rieures \u00e0 6.4.7",
          "product": {
            "name": "FortiGate",
            "vendor": {
              "name": "Fortinet",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": null,
      "content": "## Solution\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des\ncorrectifs (cf. section Documentation).\n",
      "cves": [
        {
          "name": "CVE-2020-12814",
          "url": "https://www.cve.org/CVERecord?id=CVE-2020-12814"
        },
        {
          "name": "CVE-2021-26107",
          "url": "https://www.cve.org/CVERecord?id=CVE-2021-26107"
        },
        {
          "name": "CVE-2021-36176",
          "url": "https://www.cve.org/CVERecord?id=CVE-2021-36176"
        },
        {
          "name": "CVE-2020-15940",
          "url": "https://www.cve.org/CVERecord?id=CVE-2020-15940"
        },
        {
          "name": "CVE-2021-42754",
          "url": "https://www.cve.org/CVERecord?id=CVE-2021-42754"
        },
        {
          "name": "CVE-2020-15935",
          "url": "https://www.cve.org/CVERecord?id=CVE-2020-15935"
        },
        {
          "name": "CVE-2021-36174",
          "url": "https://www.cve.org/CVERecord?id=CVE-2021-36174"
        },
        {
          "name": "CVE-2021-36192",
          "url": "https://www.cve.org/CVERecord?id=CVE-2021-36192"
        },
        {
          "name": "CVE-2021-36183",
          "url": "https://www.cve.org/CVERecord?id=CVE-2021-36183"
        },
        {
          "name": "CVE-2021-36172",
          "url": "https://www.cve.org/CVERecord?id=CVE-2021-36172"
        },
        {
          "name": "CVE-2021-41019",
          "url": "https://www.cve.org/CVERecord?id=CVE-2021-41019"
        },
        {
          "name": "CVE-2021-36181",
          "url": "https://www.cve.org/CVERecord?id=CVE-2021-36181"
        },
        {
          "name": "CVE-2021-32595",
          "url": "https://www.cve.org/CVERecord?id=CVE-2021-32595"
        }
      ],
      "initial_release_date": "2021-11-04T00:00:00",
      "last_revision_date": "2021-11-04T00:00:00",
      "links": [],
      "reference": "CERTFR-2021-AVI-845",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2021-11-04T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "D\u00e9ni de service \u00e0 distance"
        },
        {
          "description": "Injection de code indirecte \u00e0 distance (XSS)"
        },
        {
          "description": "Contournement de la politique de s\u00e9curit\u00e9"
        },
        {
          "description": "Atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es"
        },
        {
          "description": "\u00c9l\u00e9vation de privil\u00e8ges"
        }
      ],
      "summary": "De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans les produits\nFortinet. Certaines d\u0027entre elles permettent \u00e0 un attaquant de provoquer\nun d\u00e9ni de service \u00e0 distance, un contournement de la politique de\ns\u00e9curit\u00e9 et une atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es.\n",
      "title": "Multiples vuln\u00e9rabilit\u00e9s dans les produits Fortinet",
      "vendor_advisories": [
        {
          "published_at": null,
          "title": "Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-20-092 du 02 novembre 2021",
          "url": "https://www.fortiguard.com/psirt/FG-IR-20-092"
        },
        {
          "published_at": null,
          "title": "Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-21-043 du 02 novembre 2021",
          "url": "https://www.fortiguard.com/psirt/FG-IR-21-043"
        },
        {
          "published_at": null,
          "title": "Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-20-079 du 02 novembre 2021",
          "url": "https://www.fortiguard.com/psirt/FG-IR-20-079"
        },
        {
          "published_at": null,
          "title": "Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-21-096 du 02 novembre 2021",
          "url": "https://www.fortiguard.com/psirt/FG-IR-21-096"
        },
        {
          "published_at": null,
          "title": "Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-21-104 du 02 novembre 2021",
          "url": "https://www.fortiguard.com/psirt/FG-IR-21-104"
        },
        {
          "published_at": null,
          "title": "Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-20-044 du 02 novembre 2021",
          "url": "https://www.fortiguard.com/psirt/FG-IR-20-044"
        },
        {
          "published_at": null,
          "title": "Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-21-103 du 02 novembre 2021",
          "url": "https://www.fortiguard.com/psirt/FG-IR-21-103"
        },
        {
          "published_at": null,
          "title": "Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-21-102 du 02 novembre 2021",
          "url": "https://www.fortiguard.com/psirt/FG-IR-21-102"
        },
        {
          "published_at": null,
          "title": "Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-21-100 du 02 novembre 2021",
          "url": "https://www.fortiguard.com/psirt/FG-IR-21-100"
        },
        {
          "published_at": null,
          "title": "Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-21-109 du 02 novembre 2021",
          "url": "https://www.fortiguard.com/psirt/FG-IR-21-109"
        },
        {
          "published_at": null,
          "title": "Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-21-074 du 02 novembre 2021",
          "url": "https://www.fortiguard.com/psirt/FG-IR-21-074"
        },
        {
          "published_at": null,
          "title": "Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-20-067 du 02 novembre 2021",
          "url": "https://www.fortiguard.com/psirt/FG-IR-20-067"
        },
        {
          "published_at": null,
          "title": "Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-21-079 du 02 novembre 2021",
          "url": "https://www.fortiguard.com/psirt/FG-IR-21-079"
        },
        {
          "published_at": null,
          "title": "Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-21-175 du 02 novembre 2021",
          "url": "https://www.fortiguard.com/psirt/FG-IR-21-175"
        }
      ]
    }

    CVE-2026-59836 (GCVE-0-2026-59836)

    Vulnerability from cvelistv5 – Published: 2026-07-14 15:15 – Updated: 2026-07-15 03:59
    VLAI
    Summary
    A improper certificate validation vulnerability in Fortinet FortiClientEMS 7.4.3 through 7.4.5, FortiClientEMS 7.4.0 through 7.4.1, FortiClientEMS 7.2 all versions may allow attacker to information disclosure via <insert attack vector here>
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-07-14 00:00 UTC
    CWE
    References
    Impacted products
    Vendor Product Version
    Fortinet FortiClientEMS Affected: 7.4.3 , ≤ 7.4.5 (semver)
    Affected: 7.4.0 , ≤ 7.4.1 (semver)
    Affected: 7.2.12 , ≤ 7.2.14 (semver)
    Affected: 7.2.0 , ≤ 7.2.10 (semver)
        cpe:2.3:a:fortinet:forticlientems:7.4.5:*:*:*:*:*:*:*
        cpe:2.3:a:fortinet:forticlientems:7.4.4:*:*:*:*:*:*:*
        cpe:2.3:a:fortinet:forticlientems:7.4.3:*:*:*:*:*:*:*
        cpe:2.3:a:fortinet:forticlientems:7.4.1:*:*:*:*:*:*:*
        cpe:2.3:a:fortinet:forticlientems:7.4.0:*:*:*:*:*:*:*
        cpe:2.3:a:fortinet:forticlientems:7.2.14:*:*:*:*:*:*:*
        cpe:2.3:a:fortinet:forticlientems:7.2.13:*:*:*:*:*:*:*
        cpe:2.3:a:fortinet:forticlientems:7.2.12:*:*:*:*:*:*:*
        cpe:2.3:a:fortinet:forticlientems:7.2.10:*:*:*:*:*:*:*
        cpe:2.3:a:fortinet:forticlientems:7.2.9:*:*:*:*:*:*:*
        cpe:2.3:a:fortinet:forticlientems:7.2.8:*:*:*:*:*:*:*
        cpe:2.3:a:fortinet:forticlientems:7.2.7:*:*:*:*:*:*:*
        cpe:2.3:a:fortinet:forticlientems:7.2.6:*:*:*:*:*:*:*
        cpe:2.3:a:fortinet:forticlientems:7.2.5:*:*:*:*:*:*:*
        cpe:2.3:a:fortinet:forticlientems:7.2.4:*:*:*:*:*:*:*
        cpe:2.3:a:fortinet:forticlientems:7.2.3:*:*:*:*:*:*:*
        cpe:2.3:a:fortinet:forticlientems:7.2.2:*:*:*:*:*:*:*
        cpe:2.3:a:fortinet:forticlientems:7.2.1:*:*:*:*:*:*:*
        cpe:2.3:a:fortinet:forticlientems:7.2.0:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-59836",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-07-14T00:00:00+00:00",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-07-15T03:59:06.023Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "cpes": [
                "cpe:2.3:a:fortinet:forticlientems:7.4.5:*:*:*:*:*:*:*",
                "cpe:2.3:a:fortinet:forticlientems:7.4.4:*:*:*:*:*:*:*",
                "cpe:2.3:a:fortinet:forticlientems:7.4.3:*:*:*:*:*:*:*",
                "cpe:2.3:a:fortinet:forticlientems:7.4.1:*:*:*:*:*:*:*",
                "cpe:2.3:a:fortinet:forticlientems:7.4.0:*:*:*:*:*:*:*",
                "cpe:2.3:a:fortinet:forticlientems:7.2.14:*:*:*:*:*:*:*",
                "cpe:2.3:a:fortinet:forticlientems:7.2.13:*:*:*:*:*:*:*",
                "cpe:2.3:a:fortinet:forticlientems:7.2.12:*:*:*:*:*:*:*",
                "cpe:2.3:a:fortinet:forticlientems:7.2.10:*:*:*:*:*:*:*",
                "cpe:2.3:a:fortinet:forticlientems:7.2.9:*:*:*:*:*:*:*",
                "cpe:2.3:a:fortinet:forticlientems:7.2.8:*:*:*:*:*:*:*",
                "cpe:2.3:a:fortinet:forticlientems:7.2.7:*:*:*:*:*:*:*",
                "cpe:2.3:a:fortinet:forticlientems:7.2.6:*:*:*:*:*:*:*",
                "cpe:2.3:a:fortinet:forticlientems:7.2.5:*:*:*:*:*:*:*",
                "cpe:2.3:a:fortinet:forticlientems:7.2.4:*:*:*:*:*:*:*",
                "cpe:2.3:a:fortinet:forticlientems:7.2.3:*:*:*:*:*:*:*",
                "cpe:2.3:a:fortinet:forticlientems:7.2.2:*:*:*:*:*:*:*",
                "cpe:2.3:a:fortinet:forticlientems:7.2.1:*:*:*:*:*:*:*",
                "cpe:2.3:a:fortinet:forticlientems:7.2.0:*:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "product": "FortiClientEMS",
              "vendor": "Fortinet",
              "versions": [
                {
                  "lessThanOrEqual": "7.4.5",
                  "status": "affected",
                  "version": "7.4.3",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.4.1",
                  "status": "affected",
                  "version": "7.4.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.2.14",
                  "status": "affected",
                  "version": "7.2.12",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.2.10",
                  "status": "affected",
                  "version": "7.2.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A improper certificate validation vulnerability in Fortinet FortiClientEMS 7.4.3 through 7.4.5, FortiClientEMS 7.4.0 through 7.4.1, FortiClientEMS 7.2 all versions may allow attacker to information disclosure via \u003cinsert attack vector here\u003e"
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 6.7,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-295",
                  "description": "Information disclosure",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-07-14T15:15:08.063Z",
            "orgId": "6abe59d8-c742-4dff-8ce8-9b0ca1073da8",
            "shortName": "fortinet"
          },
          "references": [
            {
              "name": "https://fortiguard.fortinet.com/psirt/FG-IR-26-147",
              "url": "https://fortiguard.fortinet.com/psirt/FG-IR-26-147"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "value": "Upgrade to upcoming  FortiClientEMS version 8.0.0 or above\nUpgrade to FortiClientEMS version 7.4.6 or above"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "6abe59d8-c742-4dff-8ce8-9b0ca1073da8",
        "assignerShortName": "fortinet",
        "cveId": "CVE-2026-59836",
        "datePublished": "2026-07-14T15:15:08.063Z",
        "dateReserved": "2026-07-07T15:21:26.614Z",
        "dateUpdated": "2026-07-15T03:59:06.023Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-39810 (GCVE-0-2026-39810)

    Vulnerability from cvelistv5 – Published: 2026-04-14 15:38 – Updated: 2026-04-14 17:41
    VLAI
    Summary
    A use of hard-coded cryptographic key vulnerability in Fortinet FortiClientEMS 7.4.0 through 7.4.5 may allow attacker to information disclosure via decrypting database dump.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-04-14 16:25 UTC
    CWE
    References
    Impacted products
    Vendor Product Version
    Fortinet FortiClientEMS Affected: 7.4.3 , ≤ 7.4.5 (semver)
    Affected: 7.4.0 , ≤ 7.4.1 (semver)
        cpe:2.3:a:fortinet:forticlientems:7.4.5:*:*:*:*:*:*:*
        cpe:2.3:a:fortinet:forticlientems:7.4.4:*:*:*:*:*:*:*
        cpe:2.3:a:fortinet:forticlientems:7.4.3:*:*:*:*:*:*:*
        cpe:2.3:a:fortinet:forticlientems:7.4.1:*:*:*:*:*:*:*
        cpe:2.3:a:fortinet:forticlientems:7.4.0:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-39810",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-04-14T16:25:24.721264Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-04-14T16:46:15.215Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "cpes": [
                "cpe:2.3:a:fortinet:forticlientems:7.4.5:*:*:*:*:*:*:*",
                "cpe:2.3:a:fortinet:forticlientems:7.4.4:*:*:*:*:*:*:*",
                "cpe:2.3:a:fortinet:forticlientems:7.4.3:*:*:*:*:*:*:*",
                "cpe:2.3:a:fortinet:forticlientems:7.4.1:*:*:*:*:*:*:*",
                "cpe:2.3:a:fortinet:forticlientems:7.4.0:*:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "product": "FortiClientEMS",
              "vendor": "Fortinet",
              "versions": [
                {
                  "lessThanOrEqual": "7.4.5",
                  "status": "affected",
                  "version": "7.4.3",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.4.1",
                  "status": "affected",
                  "version": "7.4.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A use of hard-coded cryptographic key vulnerability in Fortinet FortiClientEMS 7.4.0 through 7.4.5 may allow attacker to information disclosure via decrypting database dump."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "NONE",
                "baseScore": 5.2,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "HIGH",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-321",
                  "description": "Information disclosure",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-04-14T17:41:54.082Z",
            "orgId": "6abe59d8-c742-4dff-8ce8-9b0ca1073da8",
            "shortName": "fortinet"
          },
          "references": [
            {
              "name": "https://fortiguard.fortinet.com/psirt/FG-IR-26-107",
              "url": "https://fortiguard.fortinet.com/psirt/FG-IR-26-107"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "value": "Upgrade to FortiClientEMS version 7.4.6 or above"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "6abe59d8-c742-4dff-8ce8-9b0ca1073da8",
        "assignerShortName": "fortinet",
        "cveId": "CVE-2026-39810",
        "datePublished": "2026-04-14T15:38:21.194Z",
        "dateReserved": "2026-04-07T15:24:09.072Z",
        "dateUpdated": "2026-04-14T17:41:54.082Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-39809 (GCVE-0-2026-39809)

    Vulnerability from cvelistv5 – Published: 2026-04-14 15:05 – Updated: 2026-04-15 03:58
    VLAI
    Summary
    A improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7.4.0 through 7.4.5, FortiClientEMS 7.2.0 through 7.2.12, FortiClientEMS 7.0 all versions may allow attacker to execute unauthorized code or commands via sending crafted requests
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-04-14 00:00 UTC
    CWE
    • CWE-89 - Execute unauthorized code or commands
    References
    Impacted products
    Vendor Product Version
    Fortinet FortiClientEMS Affected: 7.4.3 , ≤ 7.4.4 (semver)
    Affected: 7.4.0 , ≤ 7.4.1 (semver)
        cpe:2.3:a:fortinet:forticlientems:7.4.4:*:*:*:*:*:*:*
        cpe:2.3:a:fortinet:forticlientems:7.4.3:*:*:*:*:*:*:*
        cpe:2.3:a:fortinet:forticlientems:7.4.1:*:*:*:*:*:*:*
        cpe:2.3:a:fortinet:forticlientems:7.4.0:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-39809",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-04-14T00:00:00+00:00",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-04-15T03:58:18.867Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "cpes": [
                "cpe:2.3:a:fortinet:forticlientems:7.4.4:*:*:*:*:*:*:*",
                "cpe:2.3:a:fortinet:forticlientems:7.4.3:*:*:*:*:*:*:*",
                "cpe:2.3:a:fortinet:forticlientems:7.4.1:*:*:*:*:*:*:*",
                "cpe:2.3:a:fortinet:forticlientems:7.4.0:*:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "product": "FortiClientEMS",
              "vendor": "Fortinet",
              "versions": [
                {
                  "lessThanOrEqual": "7.4.4",
                  "status": "affected",
                  "version": "7.4.3",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.4.1",
                  "status": "affected",
                  "version": "7.4.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A improper neutralization of special elements used in an sql command (\u0027sql injection\u0027) vulnerability in Fortinet FortiClientEMS 7.4.0 through 7.4.5, FortiClientEMS 7.2.0 through 7.2.12, FortiClientEMS 7.0 all versions may allow attacker to execute unauthorized code or commands via sending crafted requests"
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "HIGH",
                "baseScore": 6.2,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "HIGH",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-89",
                  "description": "Execute unauthorized code or commands",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-04-14T17:38:34.503Z",
            "orgId": "6abe59d8-c742-4dff-8ce8-9b0ca1073da8",
            "shortName": "fortinet"
          },
          "references": [
            {
              "name": "https://fortiguard.fortinet.com/psirt/FG-IR-26-102",
              "url": "https://fortiguard.fortinet.com/psirt/FG-IR-26-102"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "value": "Upgrade to FortiClientEMS version 7.4.6 or above\nUpgrade to FortiClientEMS version 7.4.5 or above\nUpgrade to FortiClientEMS version 7.2.13 or above"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "6abe59d8-c742-4dff-8ce8-9b0ca1073da8",
        "assignerShortName": "fortinet",
        "cveId": "CVE-2026-39809",
        "datePublished": "2026-04-14T15:05:56.647Z",
        "dateReserved": "2026-04-07T15:24:05.925Z",
        "dateUpdated": "2026-04-15T03:58:18.867Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-35616 (GCVE-0-2026-35616)

    Vulnerability from cvelistv5 – Published: 2026-04-04 00:38 – Updated: 2026-07-08 12:52
    VLAI
    Summary
    A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests.
    SSVC
    Exploitation: active Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-04-03 00:00 UTC
    CWE
    • CWE-284 - Escalation of privilege
    Impacted products
    Vendor Product Version
    Fortinet FortiClientEMS Affected: 7.4.5 , ≤ 7.4.6 (semver)
        cpe:2.3:a:fortinet:forticlientems:7.4.6:*:*:*:*:*:*:*
        cpe:2.3:a:fortinet:forticlientems:7.4.5:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-35616",
                    "options": [
                      {
                        "Exploitation": "active"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-04-03T00:00:00+00:00",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              },
              {
                "other": {
                  "content": {
                    "dateAdded": "2026-04-06",
                    "reference": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-35616"
                  },
                  "type": "kev"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-04-07T03:55:31.536Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "government-resource"
                ],
                "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-35616"
              }
            ],
            "timeline": [
              {
                "lang": "en",
                "time": "2026-04-06T00:00:00.000Z",
                "value": "CVE-2026-35616 added to CISA KEV"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "cpes": [
                "cpe:2.3:a:fortinet:forticlientems:7.4.6:*:*:*:*:*:*:*",
                "cpe:2.3:a:fortinet:forticlientems:7.4.5:*:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "product": "FortiClientEMS",
              "vendor": "Fortinet",
              "versions": [
                {
                  "lessThanOrEqual": "7.4.6",
                  "status": "affected",
                  "version": "7.4.5",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 9.1,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-284",
                  "description": "Escalation of privilege",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-07-08T12:52:00.780Z",
            "orgId": "6abe59d8-c742-4dff-8ce8-9b0ca1073da8",
            "shortName": "fortinet"
          },
          "references": [
            {
              "name": "https://fortiguard.fortinet.com/psirt/FG-IR-26-099",
              "url": "https://fortiguard.fortinet.com/psirt/FG-IR-26-099"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "value": "Upgrade to upcoming  FortiClientEMS version 8.0.0 or above\nUpgrade to FortiClientEMS version 7.4.7 or above"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "6abe59d8-c742-4dff-8ce8-9b0ca1073da8",
        "assignerShortName": "fortinet",
        "cveId": "CVE-2026-35616",
        "datePublished": "2026-04-04T00:38:35.828Z",
        "dateReserved": "2026-04-03T23:49:34.986Z",
        "dateUpdated": "2026-07-08T12:52:00.780Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-21643 (GCVE-0-2026-21643)

    Vulnerability from cvelistv5 – Published: 2026-02-06 08:24 – Updated: 2026-04-14 03:55
    VLAI
    Summary
    An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7.4.4 may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests.
    SSVC
    Exploitation: active Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-02-06 00:00 UTC
    CWE
    • CWE-89 - Execute unauthorized code or commands
    Impacted products
    Vendor Product Version
    Fortinet FortiClientEMS Affected: 7.4.4
        cpe:2.3:a:fortinet:forticlientems:7.4.4:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-21643",
                    "options": [
                      {
                        "Exploitation": "active"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-02-06T00:00:00+00:00",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              },
              {
                "other": {
                  "content": {
                    "dateAdded": "2026-04-13",
                    "reference": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-21643"
                  },
                  "type": "kev"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-04-14T03:55:26.806Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "exploit"
                ],
                "url": "https://github.com/0xBlackash/CVE-2026-21643/blob/main/cve-2026-21643.py"
              },
              {
                "tags": [
                  "government-resource"
                ],
                "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-21643"
              }
            ],
            "timeline": [
              {
                "lang": "en",
                "time": "2026-04-13T00:00:00.000Z",
                "value": "CVE-2026-21643 added to CISA KEV"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "cpes": [
                "cpe:2.3:a:fortinet:forticlientems:7.4.4:*:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "product": "FortiClientEMS",
              "vendor": "Fortinet",
              "versions": [
                {
                  "status": "affected",
                  "version": "7.4.4"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "An improper neutralization of special elements used in an sql command (\u0027sql injection\u0027) vulnerability in Fortinet FortiClientEMS 7.4.4 may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 9.1,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-89",
                  "description": "Execute unauthorized code or commands",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-03-31T17:06:20.893Z",
            "orgId": "6abe59d8-c742-4dff-8ce8-9b0ca1073da8",
            "shortName": "fortinet"
          },
          "references": [
            {
              "name": "https://fortiguard.fortinet.com/psirt/FG-IR-25-1142",
              "url": "https://fortiguard.fortinet.com/psirt/FG-IR-25-1142"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "value": "Upgrade to upcoming  FortiClientEMS version 8.0.0 or above\nUpgrade to FortiClientEMS version 7.4.5 or above"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "6abe59d8-c742-4dff-8ce8-9b0ca1073da8",
        "assignerShortName": "fortinet",
        "cveId": "CVE-2026-21643",
        "datePublished": "2026-02-06T08:24:43.877Z",
        "dateReserved": "2026-01-02T08:41:26.514Z",
        "dateUpdated": "2026-04-14T03:55:26.806Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2025-59922 (GCVE-0-2025-59922)

    Vulnerability from cvelistv5 – Published: 2026-01-13 16:32 – Updated: 2026-01-14 09:16
    VLAI
    Summary
    An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerability in Fortinet FortiClientEMS 7.4.3 through 7.4.4, FortiClientEMS 7.4.0 through 7.4.1, FortiClientEMS 7.2.0 through 7.2.10, FortiClientEMS 7.0 all versions may allow an authenticated attacker with at least read-only admin permission to execute unauthorized SQL code or commands via crafted HTTP or HTTPs requests.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-01-13 21:39 UTC
    CWE
    • CWE-89 - Execute unauthorized code or commands
    References
    Impacted products
    Vendor Product Version
    Fortinet FortiClientEMS Affected: 7.4.3 , ≤ 7.4.4 (semver)
    Affected: 7.4.0 , ≤ 7.4.1 (semver)
    Affected: 7.2.0 , ≤ 7.2.10 (semver)
    Affected: 7.0.0 , ≤ 7.0.13 (semver)
        cpe:2.3:a:fortinet:forticlientems:7.4.4:*:*:*:*:*:*:*
        cpe:2.3:a:fortinet:forticlientems:7.4.3:*:*:*:*:*:*:*
        cpe:2.3:a:fortinet:forticlientems:7.4.1:*:*:*:*:*:*:*
        cpe:2.3:a:fortinet:forticlientems:7.4.0:*:*:*:*:*:*:*
        cpe:2.3:a:fortinet:forticlientems:7.2.10:*:*:*:*:*:*:*
        cpe:2.3:a:fortinet:forticlientems:7.2.9:*:*:*:*:*:*:*
        cpe:2.3:a:fortinet:forticlientems:7.2.8:*:*:*:*:*:*:*
        cpe:2.3:a:fortinet:forticlientems:7.2.7:*:*:*:*:*:*:*
        cpe:2.3:a:fortinet:forticlientems:7.2.6:*:*:*:*:*:*:*
        cpe:2.3:a:fortinet:forticlientems:7.2.5:*:*:*:*:*:*:*
        cpe:2.3:a:fortinet:forticlientems:7.2.4:*:*:*:*:*:*:*
        cpe:2.3:a:fortinet:forticlientems:7.2.3:*:*:*:*:*:*:*
        cpe:2.3:a:fortinet:forticlientems:7.2.2:*:*:*:*:*:*:*
        cpe:2.3:a:fortinet:forticlientems:7.2.1:*:*:*:*:*:*:*
        cpe:2.3:a:fortinet:forticlientems:7.2.0:*:*:*:*:*:*:*
        cpe:2.3:a:fortinet:forticlientems:7.0.13:*:*:*:*:*:*:*
        cpe:2.3:a:fortinet:forticlientems:7.0.12:*:*:*:*:*:*:*
        cpe:2.3:a:fortinet:forticlientems:7.0.11:*:*:*:*:*:*:*
        cpe:2.3:a:fortinet:forticlientems:7.0.10:*:*:*:*:*:*:*
        cpe:2.3:a:fortinet:forticlientems:7.0.9:*:*:*:*:*:*:*
        cpe:2.3:a:fortinet:forticlientems:7.0.8:*:*:*:*:*:*:*
        cpe:2.3:a:fortinet:forticlientems:7.0.7:*:*:*:*:*:*:*
        cpe:2.3:a:fortinet:forticlientems:7.0.6:*:*:*:*:*:*:*
        cpe:2.3:a:fortinet:forticlientems:7.0.5:*:*:*:*:*:*:*
        cpe:2.3:a:fortinet:forticlientems:7.0.4:*:*:*:*:*:*:*
        cpe:2.3:a:fortinet:forticlientems:7.0.3:*:*:*:*:*:*:*
        cpe:2.3:a:fortinet:forticlientems:7.0.2:*:*:*:*:*:*:*
        cpe:2.3:a:fortinet:forticlientems:7.0.1:*:*:*:*:*:*:*
        cpe:2.3:a:fortinet:forticlientems:7.0.0:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-59922",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-01-13T21:39:37.452586Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-01-13T21:39:42.935Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "cpes": [
                "cpe:2.3:a:fortinet:forticlientems:7.4.4:*:*:*:*:*:*:*",
                "cpe:2.3:a:fortinet:forticlientems:7.4.3:*:*:*:*:*:*:*",
                "cpe:2.3:a:fortinet:forticlientems:7.4.1:*:*:*:*:*:*:*",
                "cpe:2.3:a:fortinet:forticlientems:7.4.0:*:*:*:*:*:*:*",
                "cpe:2.3:a:fortinet:forticlientems:7.2.10:*:*:*:*:*:*:*",
                "cpe:2.3:a:fortinet:forticlientems:7.2.9:*:*:*:*:*:*:*",
                "cpe:2.3:a:fortinet:forticlientems:7.2.8:*:*:*:*:*:*:*",
                "cpe:2.3:a:fortinet:forticlientems:7.2.7:*:*:*:*:*:*:*",
                "cpe:2.3:a:fortinet:forticlientems:7.2.6:*:*:*:*:*:*:*",
                "cpe:2.3:a:fortinet:forticlientems:7.2.5:*:*:*:*:*:*:*",
                "cpe:2.3:a:fortinet:forticlientems:7.2.4:*:*:*:*:*:*:*",
                "cpe:2.3:a:fortinet:forticlientems:7.2.3:*:*:*:*:*:*:*",
                "cpe:2.3:a:fortinet:forticlientems:7.2.2:*:*:*:*:*:*:*",
                "cpe:2.3:a:fortinet:forticlientems:7.2.1:*:*:*:*:*:*:*",
                "cpe:2.3:a:fortinet:forticlientems:7.2.0:*:*:*:*:*:*:*",
                "cpe:2.3:a:fortinet:forticlientems:7.0.13:*:*:*:*:*:*:*",
                "cpe:2.3:a:fortinet:forticlientems:7.0.12:*:*:*:*:*:*:*",
                "cpe:2.3:a:fortinet:forticlientems:7.0.11:*:*:*:*:*:*:*",
                "cpe:2.3:a:fortinet:forticlientems:7.0.10:*:*:*:*:*:*:*",
                "cpe:2.3:a:fortinet:forticlientems:7.0.9:*:*:*:*:*:*:*",
                "cpe:2.3:a:fortinet:forticlientems:7.0.8:*:*:*:*:*:*:*",
                "cpe:2.3:a:fortinet:forticlientems:7.0.7:*:*:*:*:*:*:*",
                "cpe:2.3:a:fortinet:forticlientems:7.0.6:*:*:*:*:*:*:*",
                "cpe:2.3:a:fortinet:forticlientems:7.0.5:*:*:*:*:*:*:*",
                "cpe:2.3:a:fortinet:forticlientems:7.0.4:*:*:*:*:*:*:*",
                "cpe:2.3:a:fortinet:forticlientems:7.0.3:*:*:*:*:*:*:*",
                "cpe:2.3:a:fortinet:forticlientems:7.0.2:*:*:*:*:*:*:*",
                "cpe:2.3:a:fortinet:forticlientems:7.0.1:*:*:*:*:*:*:*",
                "cpe:2.3:a:fortinet:forticlientems:7.0.0:*:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "product": "FortiClientEMS",
              "vendor": "Fortinet",
              "versions": [
                {
                  "lessThanOrEqual": "7.4.4",
                  "status": "affected",
                  "version": "7.4.3",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.4.1",
                  "status": "affected",
                  "version": "7.4.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.2.10",
                  "status": "affected",
                  "version": "7.2.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.0.13",
                  "status": "affected",
                  "version": "7.0.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "An improper neutralization of special elements used in an SQL command (\u0027SQL Injection\u0027) vulnerability [CWE-89] vulnerability in Fortinet FortiClientEMS 7.4.3 through 7.4.4, FortiClientEMS 7.4.0 through 7.4.1, FortiClientEMS 7.2.0 through 7.2.10, FortiClientEMS 7.0 all versions may allow an authenticated attacker with at least read-only admin permission to execute unauthorized SQL code or commands via crafted HTTP or HTTPs requests."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 6.8,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "HIGH",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:P/RL:U/RC:C",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-89",
                  "description": "Execute unauthorized code or commands",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-01-14T09:16:14.334Z",
            "orgId": "6abe59d8-c742-4dff-8ce8-9b0ca1073da8",
            "shortName": "fortinet"
          },
          "references": [
            {
              "name": "https://fortiguard.fortinet.com/psirt/FG-IR-25-735",
              "url": "https://fortiguard.fortinet.com/psirt/FG-IR-25-735"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "value": "Upgrade to FortiClientEMS version 7.4.5 or above\nUpgrade to FortiClientEMS version 7.2.12 or above"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "6abe59d8-c742-4dff-8ce8-9b0ca1073da8",
        "assignerShortName": "fortinet",
        "cveId": "CVE-2025-59922",
        "datePublished": "2026-01-13T16:32:28.715Z",
        "dateReserved": "2025-09-23T12:51:54.672Z",
        "dateUpdated": "2026-01-14T09:16:14.334Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2023-48786 (GCVE-0-2023-48786)

    Vulnerability from cvelistv5 – Published: 2025-06-10 16:36 – Updated: 2025-06-11 14:43
    VLAI
    Summary
    A server-side request forgery vulnerability [CWE-918] in Fortinet FortiClientEMS version 7.4.0 through 7.4.2 and before 7.2.6 may allow an authenticated attacker to perform internal requests via crafted HTTP or HTTPS requests.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-06-11 14:43 UTC
    CWE
    • CWE-918 - Execute unauthorized code or commands
    References
    Impacted products
    Vendor Product Version
    Fortinet FortiClientEMS Affected: 7.2.0 , ≤ 7.2.2 (semver)
    Affected: 7.0.0 , ≤ 7.0.13 (semver)
    Affected: 6.4.7 , ≤ 6.4.9 (semver)
    Affected: 6.4.0 , ≤ 6.4.4 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-48786",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-06-11T14:43:35.642269Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-06-11T14:43:41.910Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "cpes": [],
              "defaultStatus": "unaffected",
              "product": "FortiClientEMS",
              "vendor": "Fortinet",
              "versions": [
                {
                  "lessThanOrEqual": "7.2.2",
                  "status": "affected",
                  "version": "7.2.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.0.13",
                  "status": "affected",
                  "version": "7.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.4.9",
                  "status": "affected",
                  "version": "6.4.7",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.4.4",
                  "status": "affected",
                  "version": "6.4.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A server-side request forgery vulnerability [CWE-918] in Fortinet FortiClientEMS version 7.4.0 through 7.4.2 and before 7.2.6 may allow an authenticated attacker to perform internal requests via crafted HTTP or HTTPS requests."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 4.1,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "LOW",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N/E:P/RL:X/RC:C",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-918",
                  "description": "Execute unauthorized code or commands",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-06-10T16:36:19.062Z",
            "orgId": "6abe59d8-c742-4dff-8ce8-9b0ca1073da8",
            "shortName": "fortinet"
          },
          "references": [
            {
              "name": "https://fortiguard.fortinet.com/psirt/FG-IR-23-342",
              "url": "https://fortiguard.fortinet.com/psirt/FG-IR-23-342"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "value": "Please upgrade to FortiClientEMS version 7.4.3 or above \nPlease upgrade to FortiClientEMS version 7.2.7 or above"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "6abe59d8-c742-4dff-8ce8-9b0ca1073da8",
        "assignerShortName": "fortinet",
        "cveId": "CVE-2023-48786",
        "datePublished": "2025-06-10T16:36:19.062Z",
        "dateReserved": "2023-11-19T19:58:38.554Z",
        "dateUpdated": "2025-06-11T14:43:41.910Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-32119 (GCVE-0-2024-32119)

    Vulnerability from cvelistv5 – Published: 2025-06-10 16:36 – Updated: 2025-06-10 19:39
    VLAI
    Summary
    An improper authentication vulnerability [CWE-287] in Fortinet FortiClientEMS version 7.4.0 and before 7.2.4 allows an unauthenticated attacker with the knowledge of the targeted user's FCTUID and VDOM to perform operations such as uploading or tagging on behalf of the targeted user via specially crafted TCP requests.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-06-10 19:29 UTC
    CWE
    • CWE-1390 - Execute unauthorized code or commands
    References
    Impacted products
    Vendor Product Version
    Fortinet FortiClientEMS Affected: 7.4.0
    Affected: 7.2.0 , ≤ 7.2.4 (semver)
    Affected: 7.0.0 , ≤ 7.0.13 (semver)
    Affected: 6.4.7 , ≤ 6.4.9 (semver)
    Affected: 6.4.0 , ≤ 6.4.4 (semver)
    Affected: 6.2.6 , ≤ 6.2.9 (semver)
    Affected: 6.2.0 , ≤ 6.2.4 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-32119",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-06-10T19:29:57.527258Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-06-10T19:39:57.140Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "cpes": [],
              "defaultStatus": "unaffected",
              "product": "FortiClientEMS",
              "vendor": "Fortinet",
              "versions": [
                {
                  "status": "affected",
                  "version": "7.4.0"
                },
                {
                  "lessThanOrEqual": "7.2.4",
                  "status": "affected",
                  "version": "7.2.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.0.13",
                  "status": "affected",
                  "version": "7.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.4.9",
                  "status": "affected",
                  "version": "6.4.7",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.4.4",
                  "status": "affected",
                  "version": "6.4.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.2.9",
                  "status": "affected",
                  "version": "6.2.6",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.2.4",
                  "status": "affected",
                  "version": "6.2.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "An improper authentication vulnerability [CWE-287] in Fortinet FortiClientEMS version 7.4.0 and before 7.2.4 allows an unauthenticated attacker with the knowledge of the targeted user\u0027s FCTUID and VDOM to perform operations such as uploading or tagging on behalf of the targeted user via specially crafted TCP requests."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "LOW",
                "baseScore": 4.6,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "LOW",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L/E:P/RL:U/RC:C",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-1390",
                  "description": "Execute unauthorized code or commands",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-06-10T16:36:15.059Z",
            "orgId": "6abe59d8-c742-4dff-8ce8-9b0ca1073da8",
            "shortName": "fortinet"
          },
          "references": [
            {
              "name": "https://fortiguard.fortinet.com/psirt/FG-IR-23-375",
              "url": "https://fortiguard.fortinet.com/psirt/FG-IR-23-375"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "value": "Please upgrade to FortiClientEMS version 7.4.1 or above \nPlease upgrade to FortiClientEMS version 7.2.5 or above"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "6abe59d8-c742-4dff-8ce8-9b0ca1073da8",
        "assignerShortName": "fortinet",
        "cveId": "CVE-2024-32119",
        "datePublished": "2025-06-10T16:36:15.059Z",
        "dateReserved": "2024-04-11T12:09:46.571Z",
        "dateUpdated": "2025-06-10T19:39:57.140Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2025-22859 (GCVE-0-2025-22859)

    Vulnerability from cvelistv5 – Published: 2025-05-13 14:46 – Updated: 2025-05-13 15:17
    VLAI
    Summary
    A Relative Path Traversal vulnerability [CWE-23] in FortiClientEMS 7.4.0 through 7.4.1 and FortiClientEMS Cloud 7.4.0 through 7.4.1 may allow a remote unauthenticated attacker to perform a limited arbitrary file write on the system via upload requests.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-05-13 15:17 UTC
    CWE
    • CWE-23 - Execute unauthorized code or commands
    References
    Impacted products
    Vendor Product Version
    Fortinet FortiClientEMS Affected: 7.4.0 , ≤ 7.4.1 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-22859",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-05-13T15:17:35.244022Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-05-13T15:17:40.699Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "cpes": [],
              "defaultStatus": "unaffected",
              "product": "FortiClientEMS",
              "vendor": "Fortinet",
              "versions": [
                {
                  "lessThanOrEqual": "7.4.1",
                  "status": "affected",
                  "version": "7.4.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A\u00a0Relative Path Traversal vulnerability [CWE-23] in FortiClientEMS 7.4.0 through 7.4.1 and FortiClientEMS Cloud 7.4.0 through 7.4.1 may allow a remote unauthenticated attacker to perform a limited arbitrary file write on the system via upload requests."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 5,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "LOW",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:P/RL:X/RC:C",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-23",
                  "description": "Execute unauthorized code or commands",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-05-13T14:46:42.743Z",
            "orgId": "6abe59d8-c742-4dff-8ce8-9b0ca1073da8",
            "shortName": "fortinet"
          },
          "references": [
            {
              "name": "https://fortiguard.fortinet.com/psirt/FG-IR-24-552",
              "url": "https://fortiguard.fortinet.com/psirt/FG-IR-24-552"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "value": "Please upgrade to FortiClientEMS Cloud version 7.4.3 or above \nPlease upgrade to FortiClientEMS version 7.4.3 or above"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "6abe59d8-c742-4dff-8ce8-9b0ca1073da8",
        "assignerShortName": "fortinet",
        "cveId": "CVE-2025-22859",
        "datePublished": "2025-05-13T14:46:42.743Z",
        "dateReserved": "2025-01-08T09:38:22.820Z",
        "dateUpdated": "2025-05-13T15:17:40.699Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2025-22855 (GCVE-0-2025-22855)

    Vulnerability from cvelistv5 – Published: 2025-04-08 14:02 – Updated: 2025-04-08 14:47
    VLAI
    Summary
    An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in Fortinet FortiClient before 7.4.1 may allow the EMS administrator to send messages containing javascript code.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-04-08 14:45 UTC
    CWE
    • CWE-79 - Execute unauthorized code or commands
    References
    Impacted products
    Vendor Product Version
    Fortinet FortiClientEMS Affected: 7.4.0 , ≤ 7.4.1 (semver)
    Affected: 7.2.1 , ≤ 7.2.8 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-22855",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-04-08T14:45:39.245375Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-04-08T14:47:47.378Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "cpes": [],
              "defaultStatus": "unaffected",
              "product": "FortiClientEMS",
              "vendor": "Fortinet",
              "versions": [
                {
                  "lessThanOrEqual": "7.4.1",
                  "status": "affected",
                  "version": "7.4.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.2.8",
                  "status": "affected",
                  "version": "7.2.1",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "An improper neutralization of input during web page generation (\u0027Cross-site Scripting\u0027) [CWE-79] vulnerability in Fortinet FortiClient before 7.4.1 may allow the EMS administrator to send messages containing javascript code."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 2.6,
                "baseSeverity": "LOW",
                "confidentialityImpact": "NONE",
                "integrityImpact": "LOW",
                "privilegesRequired": "HIGH",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N/E:P/RL:X/RC:C",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-79",
                  "description": "Execute unauthorized code or commands",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-04-08T14:02:44.119Z",
            "orgId": "6abe59d8-c742-4dff-8ce8-9b0ca1073da8",
            "shortName": "fortinet"
          },
          "references": [
            {
              "name": "https://fortiguard.fortinet.com/psirt/FG-IR-23-344",
              "url": "https://fortiguard.fortinet.com/psirt/FG-IR-23-344"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "value": "Please upgrade to FortiClientEMS version 7.4.3 or above"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "6abe59d8-c742-4dff-8ce8-9b0ca1073da8",
        "assignerShortName": "fortinet",
        "cveId": "CVE-2025-22855",
        "datePublished": "2025-04-08T14:02:44.119Z",
        "dateReserved": "2025-01-08T09:38:22.820Z",
        "dateUpdated": "2025-04-08T14:47:47.378Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2019-16149 (GCVE-0-2019-16149)

    Vulnerability from cvelistv5 – Published: 2025-03-28 09:07 – Updated: 2025-03-28 14:30
    VLAI
    Summary
    An Improper Neutralization of Input During Web Page Generation in FortiClientEMS version 6.2.0 may allow a remote attacker to execute unauthorized code by injecting malicious payload in the user profile of a FortiClient instance being managed by the vulnerable system.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-03-28 14:30 UTC
    CWE
    • CWE-79 - Execute unauthorized code or commands
    References
    Impacted products
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2019-16149",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-03-28T14:30:25.215073Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-03-28T14:30:50.994Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "cpes": [],
              "defaultStatus": "unaffected",
              "product": "FortiClientEMS",
              "vendor": "Fortinet",
              "versions": [
                {
                  "status": "affected",
                  "version": "6.2.0"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "An Improper Neutralization of Input During Web Page Generation in FortiClientEMS version 6.2.0 may allow a remote attacker to execute unauthorized code by injecting malicious payload in the user profile of a FortiClient instance being managed by the vulnerable system."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "LOW",
                "baseScore": 5.4,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "LOW",
                "integrityImpact": "LOW",
                "privilegesRequired": "LOW",
                "scope": "CHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:L/E:F/RL:X/RC:X",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-79",
                  "description": "Execute unauthorized code or commands",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-03-28T09:07:30.099Z",
            "orgId": "6abe59d8-c742-4dff-8ce8-9b0ca1073da8",
            "shortName": "fortinet"
          },
          "references": [
            {
              "name": "https://fortiguard.fortinet.com/psirt/FG-IR-19-072",
              "url": "https://fortiguard.fortinet.com/psirt/FG-IR-19-072"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "value": "Please upgrade to version 6.2.1 and above."
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "6abe59d8-c742-4dff-8ce8-9b0ca1073da8",
        "assignerShortName": "fortinet",
        "cveId": "CVE-2019-16149",
        "datePublished": "2025-03-28T09:07:30.099Z",
        "dateReserved": "2019-09-09T00:00:00.000Z",
        "dateUpdated": "2025-03-28T14:30:50.994Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-23106 (GCVE-0-2024-23106)

    Vulnerability from cvelistv5 – Published: 2025-01-14 14:10 – Updated: 2025-02-18 21:34
    VLAI
    Summary
    An improper restriction of excessive authentication attempts [CWE-307] in FortiClientEMS version 7.2.0 through 7.2.4 and before 7.0.10 allows an unauthenticated attacker to try a brute force attack against the FortiClientEMS console via crafted HTTP or HTTPS requests.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-01-14 14:18 UTC
    CWE
    • CWE-307 - Improper access control
    References
    Impacted products
    Vendor Product Version
    Fortinet FortiClientEMS Affected: 7.2.0 , ≤ 7.2.3 (semver)
    Affected: 7.0.0 , ≤ 7.0.10 (semver)
    Affected: 6.4.7 , ≤ 6.4.9 (semver)
    Affected: 6.4.0 , ≤ 6.4.4 (semver)
    Affected: 6.2.6 , ≤ 6.2.9 (semver)
    Affected: 6.2.0 , ≤ 6.2.4 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-23106",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-01-14T14:18:35.297797Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-02-18T21:34:28.472Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "cpes": [],
              "defaultStatus": "unaffected",
              "product": "FortiClientEMS",
              "vendor": "Fortinet",
              "versions": [
                {
                  "lessThanOrEqual": "7.2.3",
                  "status": "affected",
                  "version": "7.2.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.0.10",
                  "status": "affected",
                  "version": "7.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.4.9",
                  "status": "affected",
                  "version": "6.4.7",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.4.4",
                  "status": "affected",
                  "version": "6.4.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.2.9",
                  "status": "affected",
                  "version": "6.2.6",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.2.4",
                  "status": "affected",
                  "version": "6.2.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "An improper restriction of excessive authentication attempts [CWE-307] in FortiClientEMS version 7.2.0 through 7.2.4 and before 7.0.10 allows an unauthenticated attacker to try a brute force attack against the FortiClientEMS console via crafted HTTP or HTTPS requests."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.7,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:C",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-307",
                  "description": "Improper access control",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-01-14T14:10:00.950Z",
            "orgId": "6abe59d8-c742-4dff-8ce8-9b0ca1073da8",
            "shortName": "fortinet"
          },
          "references": [
            {
              "name": "https://fortiguard.fortinet.com/psirt/FG-IR-23-476",
              "url": "https://fortiguard.fortinet.com/psirt/FG-IR-23-476"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "value": "Please upgrade to FortiClientEMS version 7.4.0 or above \nPlease upgrade to FortiClientEMS version 7.2.5 or above \nPlease upgrade to FortiClientEMS version 7.0.11 or above"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "6abe59d8-c742-4dff-8ce8-9b0ca1073da8",
        "assignerShortName": "fortinet",
        "cveId": "CVE-2024-23106",
        "datePublished": "2025-01-14T14:10:00.950Z",
        "dateReserved": "2024-01-11T16:29:07.978Z",
        "dateUpdated": "2025-02-18T21:34:28.472Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-36506 (GCVE-0-2024-36506)

    Vulnerability from cvelistv5 – Published: 2025-01-14 14:09 – Updated: 2025-01-15 14:55
    VLAI
    Summary
    An improper verification of source of a communication channel vulnerability [CWE-940] in FortiClientEMS 7.4.0, 7.2.0 through 7.2.4, 7.0 all versions, 6.4 all versions may allow a remote attacker to bypass the trusted host feature via session connection.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-01-15 14:55 UTC
    CWE
    • CWE-940 - Improper access control
    References
    Impacted products
    Vendor Product Version
    Fortinet FortiClientEMS Affected: 7.4.0
    Affected: 7.2.0 , ≤ 7.2.4 (semver)
    Affected: 7.0.0 , ≤ 7.0.13 (semver)
    Affected: 6.4.7 , ≤ 6.4.9 (semver)
    Affected: 6.4.0 , ≤ 6.4.4 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-36506",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-01-15T14:55:35.373852Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-01-15T14:55:47.884Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "cpes": [],
              "defaultStatus": "unaffected",
              "product": "FortiClientEMS",
              "vendor": "Fortinet",
              "versions": [
                {
                  "status": "affected",
                  "version": "7.4.0"
                },
                {
                  "lessThanOrEqual": "7.2.4",
                  "status": "affected",
                  "version": "7.2.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.0.13",
                  "status": "affected",
                  "version": "7.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.4.9",
                  "status": "affected",
                  "version": "6.4.7",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.4.4",
                  "status": "affected",
                  "version": "6.4.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "An improper verification of source of a communication channel vulnerability [CWE-940] in FortiClientEMS 7.4.0, 7.2.0 through 7.2.4, 7.0 all versions, 6.4 all versions may allow a remote attacker to bypass the trusted host feature via session connection."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 3.5,
                "baseSeverity": "LOW",
                "confidentialityImpact": "NONE",
                "integrityImpact": "LOW",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N/E:P/RL:X/RC:C",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-940",
                  "description": "Improper access control",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-01-14T14:09:52.227Z",
            "orgId": "6abe59d8-c742-4dff-8ce8-9b0ca1073da8",
            "shortName": "fortinet"
          },
          "references": [
            {
              "name": "https://fortiguard.fortinet.com/psirt/FG-IR-24-078",
              "url": "https://fortiguard.fortinet.com/psirt/FG-IR-24-078"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "value": "Please upgrade to FortiClientEMS version 7.4.1 or above \nPlease upgrade to FortiClientEMS version 7.2.5 or above \nPlease upgrade to FortiSASE version 24.2.c or above"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "6abe59d8-c742-4dff-8ce8-9b0ca1073da8",
        "assignerShortName": "fortinet",
        "cveId": "CVE-2024-36506",
        "datePublished": "2025-01-14T14:09:52.227Z",
        "dateReserved": "2024-05-29T08:44:50.759Z",
        "dateUpdated": "2025-01-15T14:55:47.884Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-36510 (GCVE-0-2024-36510)

    Vulnerability from cvelistv5 – Published: 2025-01-14 14:09 – Updated: 2025-01-15 14:51
    VLAI
    Summary
    An observable response discrepancy vulnerability [CWE-204] in FortiClientEMS 7.4.0, 7.2.0 through 7.2.4, 7.0 all versions, and FortiSOAR 7.5.0, 7.4.0 through 7.4.4, 7.3.0 through 7.3.2, 7.2 all versions, 7.0 all versions, 6.4 all versions may allow an unauthenticated attacker to enumerate valid users via observing login request responses.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-01-15 14:50 UTC
    CWE
    References
    Impacted products
    Vendor Product Version
    Fortinet FortiClientEMS Affected: 7.2.0 , ≤ 7.2.4 (semver)
    Affected: 7.0.0 , ≤ 7.0.13 (semver)
    Create a notification for this product.
    Fortinet FortiSOAR Affected: 7.5.0
    Affected: 7.4.0 , ≤ 7.4.4 (semver)
    Affected: 7.3.0 , ≤ 7.3.2 (semver)
    Affected: 7.2.0 , ≤ 7.2.2 (semver)
    Affected: 7.0.0 , ≤ 7.0.3 (semver)
    Affected: 6.4.3 , ≤ 6.4.4 (semver)
    Affected: 6.4.0 , ≤ 6.4.1 (semver)
        cpe:2.3:a:fortinet:fortisoar:7.5.0:*:*:*:*:*:*:*
        cpe:2.3:a:fortinet:fortisoar:7.4.4:*:*:*:*:*:*:*
        cpe:2.3:a:fortinet:fortisoar:7.4.3:*:*:*:*:*:*:*
        cpe:2.3:a:fortinet:fortisoar:7.4.2:*:*:*:*:*:*:*
        cpe:2.3:a:fortinet:fortisoar:7.4.1:*:*:*:*:*:*:*
        cpe:2.3:a:fortinet:fortisoar:7.4.0:*:*:*:*:*:*:*
        cpe:2.3:a:fortinet:fortisoar:7.3.2:*:*:*:*:*:*:*
        cpe:2.3:a:fortinet:fortisoar:7.3.1:*:*:*:*:*:*:*
        cpe:2.3:a:fortinet:fortisoar:7.3.0:*:*:*:*:*:*:*
        cpe:2.3:a:fortinet:fortisoar:7.2.2:*:*:*:*:*:*:*
        cpe:2.3:a:fortinet:fortisoar:7.2.1:*:*:*:*:*:*:*
        cpe:2.3:a:fortinet:fortisoar:7.2.0:*:*:*:*:*:*:*
        cpe:2.3:a:fortinet:fortisoar:7.0.3:*:*:*:*:*:*:*
        cpe:2.3:a:fortinet:fortisoar:7.0.2:*:*:*:*:*:*:*
        cpe:2.3:a:fortinet:fortisoar:7.0.1:*:*:*:*:*:*:*
        cpe:2.3:a:fortinet:fortisoar:7.0.0:*:*:*:*:*:*:*
        cpe:2.3:a:fortinet:fortisoar:6.4.4:*:*:*:*:*:*:*
        cpe:2.3:a:fortinet:fortisoar:6.4.3:*:*:*:*:*:*:*
        cpe:2.3:a:fortinet:fortisoar:6.4.1:*:*:*:*:*:*:*
        cpe:2.3:a:fortinet:fortisoar:6.4.0:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-36510",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-01-15T14:50:55.718822Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-01-15T14:51:13.708Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "cpes": [],
              "defaultStatus": "unaffected",
              "product": "FortiClientEMS",
              "vendor": "Fortinet",
              "versions": [
                {
                  "lessThanOrEqual": "7.2.4",
                  "status": "affected",
                  "version": "7.2.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.0.13",
                  "status": "affected",
                  "version": "7.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:fortinet:fortisoar:7.5.0:*:*:*:*:*:*:*",
                "cpe:2.3:a:fortinet:fortisoar:7.4.4:*:*:*:*:*:*:*",
                "cpe:2.3:a:fortinet:fortisoar:7.4.3:*:*:*:*:*:*:*",
                "cpe:2.3:a:fortinet:fortisoar:7.4.2:*:*:*:*:*:*:*",
                "cpe:2.3:a:fortinet:fortisoar:7.4.1:*:*:*:*:*:*:*",
                "cpe:2.3:a:fortinet:fortisoar:7.4.0:*:*:*:*:*:*:*",
                "cpe:2.3:a:fortinet:fortisoar:7.3.2:*:*:*:*:*:*:*",
                "cpe:2.3:a:fortinet:fortisoar:7.3.1:*:*:*:*:*:*:*",
                "cpe:2.3:a:fortinet:fortisoar:7.3.0:*:*:*:*:*:*:*",
                "cpe:2.3:a:fortinet:fortisoar:7.2.2:*:*:*:*:*:*:*",
                "cpe:2.3:a:fortinet:fortisoar:7.2.1:*:*:*:*:*:*:*",
                "cpe:2.3:a:fortinet:fortisoar:7.2.0:*:*:*:*:*:*:*",
                "cpe:2.3:a:fortinet:fortisoar:7.0.3:*:*:*:*:*:*:*",
                "cpe:2.3:a:fortinet:fortisoar:7.0.2:*:*:*:*:*:*:*",
                "cpe:2.3:a:fortinet:fortisoar:7.0.1:*:*:*:*:*:*:*",
                "cpe:2.3:a:fortinet:fortisoar:7.0.0:*:*:*:*:*:*:*",
                "cpe:2.3:a:fortinet:fortisoar:6.4.4:*:*:*:*:*:*:*",
                "cpe:2.3:a:fortinet:fortisoar:6.4.3:*:*:*:*:*:*:*",
                "cpe:2.3:a:fortinet:fortisoar:6.4.1:*:*:*:*:*:*:*",
                "cpe:2.3:a:fortinet:fortisoar:6.4.0:*:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "product": "FortiSOAR",
              "vendor": "Fortinet",
              "versions": [
                {
                  "status": "affected",
                  "version": "7.5.0"
                },
                {
                  "lessThanOrEqual": "7.4.4",
                  "status": "affected",
                  "version": "7.4.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.3.2",
                  "status": "affected",
                  "version": "7.3.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.2.2",
                  "status": "affected",
                  "version": "7.2.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.0.3",
                  "status": "affected",
                  "version": "7.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.4.4",
                  "status": "affected",
                  "version": "6.4.3",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.4.1",
                  "status": "affected",
                  "version": "6.4.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "An observable response discrepancy vulnerability [CWE-204] in FortiClientEMS 7.4.0, 7.2.0 through 7.2.4, 7.0 all versions, and FortiSOAR 7.5.0, 7.4.0 through 7.4.4, 7.3.0 through 7.3.2, 7.2 all versions, 7.0 all versions, 6.4 all versions may allow an unauthenticated attacker to enumerate valid users via observing login request responses."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 4.9,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "LOW",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:X/RC:X",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-204",
                  "description": "Information disclosure",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-01-14T14:09:49.286Z",
            "orgId": "6abe59d8-c742-4dff-8ce8-9b0ca1073da8",
            "shortName": "fortinet"
          },
          "references": [
            {
              "name": "https://fortiguard.fortinet.com/psirt/FG-IR-24-071",
              "url": "https://fortiguard.fortinet.com/psirt/FG-IR-24-071"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "value": "Please upgrade to FortiClientEMS version 7.4.1 or above \nPlease upgrade to FortiClientEMS version 7.2.5 or above \nPlease upgrade to FortiSOAR version 7.6.0 or above \nPlease upgrade to FortiSOAR version 7.5.1 or above \nPlease upgrade to FortiSOAR version 7.4.5 or above \nPlease upgrade to FortiSOAR version 7.3.3 or above"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "6abe59d8-c742-4dff-8ce8-9b0ca1073da8",
        "assignerShortName": "fortinet",
        "cveId": "CVE-2024-36510",
        "datePublished": "2025-01-14T14:09:49.286Z",
        "dateReserved": "2024-05-29T08:44:50.760Z",
        "dateUpdated": "2025-01-15T14:51:13.708Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-21753 (GCVE-0-2024-21753)

    Vulnerability from cvelistv5 – Published: 2024-09-10 14:37 – Updated: 2024-09-10 18:58
    VLAI
    Summary
    A improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiClientEMS versions 7.2.0 through 7.2.4, 7.0.0 through 7.0.13, 6.4.0 through 6.4.9, 6.2.0 through 6.2.9, 6.0.0 through 6.0.8, 1.2.1 through 1.2.5 allows attacker to perform a denial of service, read or write a limited number of files via specially crafted HTTP requests
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-09-10 18:58 UTC
    CWE
    References
    Impacted products
    Vendor Product Version
    Fortinet FortiClientEMS Affected: 7.2.0 , ≤ 7.2.2 (semver)
    Affected: 7.0.0 , ≤ 7.0.13 (semver)
    Affected: 6.4.7 , ≤ 6.4.9 (semver)
    Affected: 6.4.0 , ≤ 6.4.4 (semver)
    Affected: 6.2.6 , ≤ 6.2.9 (semver)
    Affected: 6.2.0 , ≤ 6.2.4 (semver)
    Affected: 6.0.8
    Affected: 6.0.0 , ≤ 6.0.6 (semver)
    Affected: 1.2.2 , ≤ 1.2.5 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-21753",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-09-10T18:58:21.335420Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-09-10T18:58:32.329Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "cpes": [],
              "defaultStatus": "unaffected",
              "product": "FortiClientEMS",
              "vendor": "Fortinet",
              "versions": [
                {
                  "lessThanOrEqual": "7.2.2",
                  "status": "affected",
                  "version": "7.2.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.0.13",
                  "status": "affected",
                  "version": "7.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.4.9",
                  "status": "affected",
                  "version": "6.4.7",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.4.4",
                  "status": "affected",
                  "version": "6.4.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.2.9",
                  "status": "affected",
                  "version": "6.2.6",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.2.4",
                  "status": "affected",
                  "version": "6.2.0",
                  "versionType": "semver"
                },
                {
                  "status": "affected",
                  "version": "6.0.8"
                },
                {
                  "lessThanOrEqual": "6.0.6",
                  "status": "affected",
                  "version": "6.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "1.2.5",
                  "status": "affected",
                  "version": "1.2.2",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A improper limitation of a pathname to a restricted directory (\u0027path traversal\u0027) in Fortinet FortiClientEMS versions 7.2.0 through 7.2.4, 7.0.0 through 7.0.13, 6.4.0 through 6.4.9, 6.2.0 through 6.2.9, 6.0.0 through 6.0.8, 1.2.1 through 1.2.5 allows attacker to perform a denial of service, read or write a limited number of files via specially crafted HTTP requests"
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 5.5,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "LOW",
                "privilegesRequired": "HIGH",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H/E:H/RL:U/RC:C",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-22",
                  "description": "Denial of service",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-09-10T14:37:48.466Z",
            "orgId": "6abe59d8-c742-4dff-8ce8-9b0ca1073da8",
            "shortName": "fortinet"
          },
          "references": [
            {
              "name": "https://fortiguard.fortinet.com/psirt/FG-IR-23-362",
              "url": "https://fortiguard.fortinet.com/psirt/FG-IR-23-362"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "value": "Please upgrade to FortiClientEMS version 7.4.0 or above \nPlease upgrade to FortiClientEMS version 7.2.5 or above"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "6abe59d8-c742-4dff-8ce8-9b0ca1073da8",
        "assignerShortName": "fortinet",
        "cveId": "CVE-2024-21753",
        "datePublished": "2024-09-10T14:37:48.466Z",
        "dateReserved": "2024-01-02T10:15:00.526Z",
        "dateUpdated": "2024-09-10T18:58:32.329Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-31489 (GCVE-0-2024-31489)

    Vulnerability from cvelistv5 – Published: 2024-09-10 14:37 – Updated: 2024-09-10 17:52
    VLAI
    Summary
    AAn improper certificate validation vulnerability [CWE-295] in FortiClientWindows 7.2.0 through 7.2.2, 7.0.0 through 7.0.11, FortiClientLinux 7.2.0, 7.0.0 through 7.0.11 and FortiClientMac 7.0.0 through 7.0.11, 7.2.0 through 7.2.4 may allow a remote and unauthenticated attacker to perform a Man-in-the-Middle attack on the communication channel between the FortiGate and the FortiClient during the ZTNA tunnel creation
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-09-10 17:47 UTC
    CWE
    References
    Impacted products
    Vendor Product Version
    Fortinet FortiClientMac Affected: 7.2.0 , ≤ 7.2.4 (semver)
    Affected: 7.0.0 , ≤ 7.0.11 (semver)
    Create a notification for this product.
    Fortinet FortiClientEMS Affected: 7.0.0 , ≤ 7.0.13 (semver)
    Create a notification for this product.
    Fortinet FortiClientLinux Affected: 7.2.0
    Affected: 7.0.0 , ≤ 7.0.11 (semver)
    Create a notification for this product.
    Fortinet FortiClientWindows Affected: 7.2.0 , ≤ 7.2.2 (semver)
    Affected: 7.0.0 , ≤ 7.0.11 (semver)
    Create a notification for this product.
    fortinet forticlientmac Affected: 7.2.0 , ≤ 7.2.4 (custom)
    Affected: 7.0.0 , ≤ 7.0.11 (custom)
        cpe:2.3:a:fortinet:forticlientmac:*:*:*:*:*:*:*:*
    Create a notification for this product.
    fortinet forticlientlinux Affected: 7.2.0
    Affected: 7.0.0 , ≤ 7.0.11 (custom)
        cpe:2.3:a:fortinet:forticlientlinux:*:*:*:*:*:*:*:*
    Create a notification for this product.
    fortinet forticlientwindows Affected: 7.2.0 , ≤ 7.2.2 (custom)
    Affected: 7.0.0 , ≤ 7.0.11 (custom)
        cpe:2.3:a:fortinet:forticlientwindows:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:fortinet:forticlientmac:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "forticlientmac",
                "vendor": "fortinet",
                "versions": [
                  {
                    "lessThanOrEqual": "7.2.4",
                    "status": "affected",
                    "version": "7.2.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThanOrEqual": "7.0.11",
                    "status": "affected",
                    "version": "7.0.0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:fortinet:forticlientlinux:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "forticlientlinux",
                "vendor": "fortinet",
                "versions": [
                  {
                    "status": "affected",
                    "version": "7.2.0"
                  },
                  {
                    "lessThanOrEqual": "7.0.11",
                    "status": "affected",
                    "version": "7.0.0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:fortinet:forticlientwindows:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "forticlientwindows",
                "vendor": "fortinet",
                "versions": [
                  {
                    "lessThanOrEqual": "7.2.2",
                    "status": "affected",
                    "version": "7.2.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThanOrEqual": "7.0.11",
                    "status": "affected",
                    "version": "7.0.0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-31489",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-09-10T17:47:00.423144Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-09-10T17:52:01.310Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "cpes": [],
              "defaultStatus": "unaffected",
              "product": "FortiClientMac",
              "vendor": "Fortinet",
              "versions": [
                {
                  "lessThanOrEqual": "7.2.4",
                  "status": "affected",
                  "version": "7.2.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.0.11",
                  "status": "affected",
                  "version": "7.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "cpes": [],
              "defaultStatus": "unaffected",
              "product": "FortiClientEMS",
              "vendor": "Fortinet",
              "versions": [
                {
                  "lessThanOrEqual": "7.0.13",
                  "status": "affected",
                  "version": "7.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "cpes": [],
              "defaultStatus": "unaffected",
              "product": "FortiClientLinux",
              "vendor": "Fortinet",
              "versions": [
                {
                  "status": "affected",
                  "version": "7.2.0"
                },
                {
                  "lessThanOrEqual": "7.0.11",
                  "status": "affected",
                  "version": "7.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "cpes": [],
              "defaultStatus": "unaffected",
              "product": "FortiClientWindows",
              "vendor": "Fortinet",
              "versions": [
                {
                  "lessThanOrEqual": "7.2.2",
                  "status": "affected",
                  "version": "7.2.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.0.11",
                  "status": "affected",
                  "version": "7.0.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "AAn improper certificate validation vulnerability [CWE-295] in FortiClientWindows 7.2.0 through 7.2.2, 7.0.0 through 7.0.11,  FortiClientLinux 7.2.0, 7.0.0 through 7.0.11 and FortiClientMac 7.0.0 through 7.0.11, 7.2.0 through 7.2.4 may allow a remote and unauthenticated attacker to perform a Man-in-the-Middle attack on the communication channel between the FortiGate and the FortiClient during the ZTNA tunnel creation"
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "ADJACENT_NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 6.4,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N/E:P/RL:U/RC:C",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-295",
                  "description": "Information disclosure",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-09-10T14:37:48.066Z",
            "orgId": "6abe59d8-c742-4dff-8ce8-9b0ca1073da8",
            "shortName": "fortinet"
          },
          "references": [
            {
              "name": "https://fortiguard.fortinet.com/psirt/FG-IR-22-282",
              "url": "https://fortiguard.fortinet.com/psirt/FG-IR-22-282"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "value": "Please upgrade to FortiClientMac version 7.2.5 or above \nPlease upgrade to FortiClientMac version 7.0.12 or above \nPlease upgrade to FortiClientEMS version 7.2.0 or above \nPlease upgrade to FortiClientLinux version 7.2.1 or above \nPlease upgrade to FortiClientLinux version 7.0.12 or above \nPlease upgrade to FortiClientWindows version 7.2.3 or above \nPlease upgrade to FortiClientWindows version 7.0.12 or above"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "6abe59d8-c742-4dff-8ce8-9b0ca1073da8",
        "assignerShortName": "fortinet",
        "cveId": "CVE-2024-31489",
        "datePublished": "2024-09-10T14:37:48.066Z",
        "dateReserved": "2024-04-04T12:52:41.585Z",
        "dateUpdated": "2024-09-10T17:52:01.310Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-33508 (GCVE-0-2024-33508)

    Vulnerability from cvelistv5 – Published: 2024-09-10 14:37 – Updated: 2024-09-10 17:32
    VLAI
    Summary
    An improper neutralization of special elements used in a command ('Command Injection') vulnerability [CWE-77] in Fortinet FortiClientEMS 7.2.0 through 7.2.4, 7.0.0 through 7.0.12 may allow an unauthenticated attacker to execute limited and temporary operations on the underlying database via crafted requests.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-09-10 17:28 UTC
    CWE
    • CWE-77 - Execute unauthorized code or commands
    References
    Impacted products
    Vendor Product Version
    Fortinet FortiClientEMS Affected: 7.2.0 , ≤ 7.2.4 (semver)
    Affected: 7.0.0 , ≤ 7.0.12 (semver)
    Create a notification for this product.
    fortinet forticlient_endpoint_management_server Affected: 7.2.0 , ≤ 7.2.4 (custom)
    Affected: 7.0.0 , ≤ 7.0.12 (custom)
        cpe:2.3:a:fortinet:forticlient_endpoint_management_server:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:fortinet:forticlient_endpoint_management_server:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "forticlient_endpoint_management_server",
                "vendor": "fortinet",
                "versions": [
                  {
                    "lessThanOrEqual": "7.2.4",
                    "status": "affected",
                    "version": "7.2.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThanOrEqual": "7.0.12",
                    "status": "affected",
                    "version": "7.0.0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-33508",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-09-10T17:28:56.999080Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-09-10T17:32:21.879Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "cpes": [],
              "defaultStatus": "unaffected",
              "product": "FortiClientEMS",
              "vendor": "Fortinet",
              "versions": [
                {
                  "lessThanOrEqual": "7.2.4",
                  "status": "affected",
                  "version": "7.2.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.0.12",
                  "status": "affected",
                  "version": "7.0.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "An improper neutralization of special elements used in a command\u00a0(\u0027Command Injection\u0027) vulnerability [CWE-77] in Fortinet FortiClientEMS 7.2.0 through 7.2.4, 7.0.0 through 7.0.12 may allow an unauthenticated attacker to execute limited and temporary operations on the underlying database via crafted requests."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "LOW",
                "baseScore": 6.9,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "LOW",
                "integrityImpact": "LOW",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-77",
                  "description": "Execute unauthorized code or commands",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-09-10T14:37:45.323Z",
            "orgId": "6abe59d8-c742-4dff-8ce8-9b0ca1073da8",
            "shortName": "fortinet"
          },
          "references": [
            {
              "name": "https://fortiguard.fortinet.com/psirt/FG-IR-24-123",
              "url": "https://fortiguard.fortinet.com/psirt/FG-IR-24-123"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "value": "Please upgrade to FortiSASE version 24.2.c or above \nPlease upgrade to FortiClientEMS version 7.4.0 or above \nPlease upgrade to FortiClientEMS version 7.2.5 or above \nPlease upgrade to FortiClientEMS version 7.0.13 or above"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "6abe59d8-c742-4dff-8ce8-9b0ca1073da8",
        "assignerShortName": "fortinet",
        "cveId": "CVE-2024-33508",
        "datePublished": "2024-09-10T14:37:45.323Z",
        "dateReserved": "2024-04-23T14:18:29.830Z",
        "dateUpdated": "2024-09-10T17:32:21.879Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-47534 (GCVE-0-2023-47534)

    Vulnerability from cvelistv5 – Published: 2024-03-12 15:09 – Updated: 2024-08-12 18:01
    VLAI
    Summary
    A improper neutralization of formula elements in a csv file in Fortinet FortiClientEMS version 7.2.0 through 7.2.2, 7.0.0 through 7.0.10, 6.4.0 through 6.4.9, 6.2.0 through 6.2.9, 6.0.0 through 6.0.8 allows attacker to execute unauthorized code or commands via specially crafted packets.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-03-21 04:00 UTC
    CWE
    • CWE-1236 - Execute unauthorized code or commands
    References
    Impacted products
    Vendor Product Version
    Fortinet FortiClientEMS Affected: 7.2.0 , ≤ 7.2.2 (semver)
    Affected: 7.0.0 , ≤ 7.0.10 (semver)
    Affected: 6.4.7 , ≤ 6.4.9 (semver)
    Affected: 6.4.0 , ≤ 6.4.4 (semver)
    Affected: 6.2.6 , ≤ 6.2.9 (semver)
    Affected: 6.2.0 , ≤ 6.2.4 (semver)
    Affected: 6.0.8
    Affected: 6.0.0 , ≤ 6.0.6 (semver)
    Create a notification for this product.
    fortinet forticlient_endpoint_management_server Affected: 6.0.8
        cpe:2.3:a:fortinet:forticlient_endpoint_management_server:6.0.8:*:*:*:*:*:*:*
    Create a notification for this product.
    fortinet forticlient_endpoint_management_server Affected: 7.2.0 , ≤ 7.2.2 (semver)
    Affected: 7.0.0 , ≤ 7.0.10 (semver)
    Affected: 6.4.7 , ≤ 6.4.9 (semver)
    Affected: 6.4.0 , ≤ 6.4.4 (semver)
    Affected: 6.2.6 , ≤ 6.2.9 (semver)
    Affected: 6.2.0 , ≤ 6.2.4 (semver)
    Affected: 6.0.0 , ≤ 6.0.6 (semver)
        cpe:2.3:a:fortinet:forticlient_endpoint_management_server:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T21:09:37.346Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "name": "https://fortiguard.com/psirt/FG-IR-23-390",
                "tags": [
                  "x_transferred"
                ],
                "url": "https://fortiguard.com/psirt/FG-IR-23-390"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:fortinet:forticlient_endpoint_management_server:6.0.8:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "forticlient_endpoint_management_server",
                "vendor": "fortinet",
                "versions": [
                  {
                    "status": "affected",
                    "version": "6.0.8"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:fortinet:forticlient_endpoint_management_server:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "forticlient_endpoint_management_server",
                "vendor": "fortinet",
                "versions": [
                  {
                    "lessThanOrEqual": "7.2.2",
                    "status": "affected",
                    "version": "7.2.0",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "7.0.10",
                    "status": "affected",
                    "version": "7.0.0",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "6.4.9",
                    "status": "affected",
                    "version": "6.4.7",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "6.4.4",
                    "status": "affected",
                    "version": "6.4.0",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "6.2.9",
                    "status": "affected",
                    "version": "6.2.6",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "6.2.4",
                    "status": "affected",
                    "version": "6.2.0",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "6.0.6",
                    "status": "affected",
                    "version": "6.0.0",
                    "versionType": "semver"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-47534",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-03-21T04:00:36.803943Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-08-12T18:01:16.372Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "FortiClientEMS",
              "vendor": "Fortinet",
              "versions": [
                {
                  "lessThanOrEqual": "7.2.2",
                  "status": "affected",
                  "version": "7.2.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.0.10",
                  "status": "affected",
                  "version": "7.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.4.9",
                  "status": "affected",
                  "version": "6.4.7",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.4.4",
                  "status": "affected",
                  "version": "6.4.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.2.9",
                  "status": "affected",
                  "version": "6.2.6",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.2.4",
                  "status": "affected",
                  "version": "6.2.0",
                  "versionType": "semver"
                },
                {
                  "status": "affected",
                  "version": "6.0.8"
                },
                {
                  "lessThanOrEqual": "6.0.6",
                  "status": "affected",
                  "version": "6.0.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A improper neutralization of formula elements in a csv file in Fortinet FortiClientEMS version 7.2.0 through 7.2.2, 7.0.0 through 7.0.10, 6.4.0 through 6.4.9, 6.2.0 through 6.2.9, 6.0.0 through 6.0.8 allows attacker to execute unauthorized code or commands via specially crafted packets."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 8.7,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "CHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H/E:P/RL:U/RC:R",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-1236",
                  "description": "Execute unauthorized code or commands",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-03-12T15:09:19.802Z",
            "orgId": "6abe59d8-c742-4dff-8ce8-9b0ca1073da8",
            "shortName": "fortinet"
          },
          "references": [
            {
              "name": "https://fortiguard.com/psirt/FG-IR-23-390",
              "url": "https://fortiguard.com/psirt/FG-IR-23-390"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "value": "Please upgrade to FortiClientEMS version 7.2.3 or above \nPlease upgrade to FortiClientEMS version 7.0.11 or above \n"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "6abe59d8-c742-4dff-8ce8-9b0ca1073da8",
        "assignerShortName": "fortinet",
        "cveId": "CVE-2023-47534",
        "datePublished": "2024-03-12T15:09:19.802Z",
        "dateReserved": "2023-11-06T10:35:25.827Z",
        "dateUpdated": "2024-08-12T18:01:16.372Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-48788 (GCVE-0-2023-48788)

    Vulnerability from cvelistv5 – Published: 2024-03-12 15:09 – Updated: 2025-10-21 23:05
    VLAI
    Summary
    A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiClientEMS version 7.2.0 through 7.2.2, FortiClientEMS 7.0.1 through 7.0.10 allows attacker to execute unauthorized code or commands via specially crafted packets.
    SSVC
    Exploitation: active Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-08-16 04:01 UTC
    CWE
    • CWE-89 - Execute unauthorized code or commands
    Impacted products
    Vendor Product Version
    Fortinet FortiClientEMS Affected: 7.2.0 , ≤ 7.2.2 (semver)
    Affected: 7.0.1 , ≤ 7.0.10 (semver)
    Create a notification for this product.
    fortinet forticlient_enterprise_management_server Affected: 7.2.0 , ≤ 7.2.2 (semver)
    Affected: 7.0.1 , ≤ 7.0.10 (semver)
        cpe:2.3:a:fortinet:forticlient_enterprise_management_server:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:fortinet:forticlient_enterprise_management_server:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "forticlient_enterprise_management_server",
                "vendor": "fortinet",
                "versions": [
                  {
                    "lessThanOrEqual": "7.2.2",
                    "status": "affected",
                    "version": "7.2.0",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "7.0.10",
                    "status": "affected",
                    "version": "7.0.1",
                    "versionType": "semver"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:fortinet:forticlient_enterprise_management_server:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "forticlient_enterprise_management_server",
                "vendor": "fortinet",
                "versions": [
                  {
                    "lessThanOrEqual": "7.2.2",
                    "status": "affected",
                    "version": "7.2.0",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "7.0.10",
                    "status": "affected",
                    "version": "7.0.1",
                    "versionType": "semver"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-48788",
                    "options": [
                      {
                        "Exploitation": "active"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-08-16T04:01:14.476146Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              },
              {
                "other": {
                  "content": {
                    "dateAdded": "2024-03-25",
                    "reference": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-48788"
                  },
                  "type": "kev"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-10-21T23:05:23.092Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "government-resource"
                ],
                "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-48788"
              }
            ],
            "timeline": [
              {
                "lang": "en",
                "time": "2024-03-25T00:00:00.000Z",
                "value": "CVE-2023-48788 added to CISA KEV"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T21:37:55.011Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "name": "https://fortiguard.com/psirt/FG-IR-24-007",
                "tags": [
                  "x_transferred"
                ],
                "url": "https://fortiguard.com/psirt/FG-IR-24-007"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "FortiClientEMS",
              "vendor": "Fortinet",
              "versions": [
                {
                  "lessThanOrEqual": "7.2.2",
                  "status": "affected",
                  "version": "7.2.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.0.10",
                  "status": "affected",
                  "version": "7.0.1",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A improper neutralization of special elements used in an sql command (\u0027sql injection\u0027) in Fortinet FortiClientEMS version 7.2.0 through 7.2.2, FortiClientEMS 7.0.1 through 7.0.10 allows attacker to execute unauthorized code or commands via specially crafted packets."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 9.3,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:U/RC:C",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-89",
                  "description": "Execute unauthorized code or commands",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-03-19T08:04:03.038Z",
            "orgId": "6abe59d8-c742-4dff-8ce8-9b0ca1073da8",
            "shortName": "fortinet"
          },
          "references": [
            {
              "name": "https://fortiguard.com/psirt/FG-IR-24-007",
              "url": "https://fortiguard.com/psirt/FG-IR-24-007"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "value": "Please upgrade to FortiClientEMS version 7.2.3 or above \nPlease upgrade to FortiClientEMS version 7.0.11 or above"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "6abe59d8-c742-4dff-8ce8-9b0ca1073da8",
        "assignerShortName": "fortinet",
        "cveId": "CVE-2023-48788",
        "datePublished": "2024-03-12T15:09:18.527Z",
        "dateReserved": "2023-11-19T19:58:38.554Z",
        "dateUpdated": "2025-10-21T23:05:23.092Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-45581 (GCVE-0-2023-45581)

    Vulnerability from cvelistv5 – Published: 2024-02-15 13:59 – Updated: 2024-08-02 20:21
    VLAI
    Summary
    An improper privilege management vulnerability [CWE-269] in Fortinet FortiClientEMS version 7.2.0 through 7.2.2 and before 7.0.10 allows an Site administrator with Super Admin privileges to perform global administrative operations affecting other sites via crafted HTTP or HTTPS requests.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-07-09 17:06 UTC
    CWE
    • CWE-269 - Execute unauthorized code or commands
    References
    Impacted products
    Vendor Product Version
    Fortinet FortiClientEMS Affected: 7.2.0 , ≤ 7.2.2 (semver)
    Affected: 7.0.6 , ≤ 7.0.10 (semver)
    Affected: 7.0.0 , ≤ 7.0.4 (semver)
    Affected: 6.4.7 , ≤ 6.4.9 (semver)
    Affected: 6.4.0 , ≤ 6.4.4 (semver)
    Affected: 6.2.6 , ≤ 6.2.9 (semver)
    Affected: 6.2.0 , ≤ 6.2.4 (semver)
    Create a notification for this product.
    fortinet forticlient_enterprise_management_server Affected: 6.2.0 , < 6.3 (custom)
    Affected: 6.4.0 , < 6.5 (custom)
    Affected: 7.0.0 , ≤ 7.0.4 (custom)
    Affected: 7.0.6 , ≤ 7.0.10 (custom)
    Affected: 7.2.0 , ≤ 7.2.2 (custom)
        cpe:2.3:a:fortinet:forticlient_enterprise_management_server:6.2.0:*:*:*:*:*:*:*
        cpe:2.3:a:fortinet:forticlient_enterprise_management_server:6.4.0:*:*:*:*:*:*:*
        cpe:2.3:a:fortinet:forticlient_enterprise_management_server:7.0.0:*:*:*:*:*:*:*
        cpe:2.3:a:fortinet:forticlient_enterprise_management_server:7.0.6:*:*:*:*:*:*:*
        cpe:2.3:a:fortinet:forticlient_enterprise_management_server:7.2.0:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:fortinet:forticlient_enterprise_management_server:6.2.0:*:*:*:*:*:*:*",
                  "cpe:2.3:a:fortinet:forticlient_enterprise_management_server:6.4.0:*:*:*:*:*:*:*",
                  "cpe:2.3:a:fortinet:forticlient_enterprise_management_server:7.0.0:*:*:*:*:*:*:*",
                  "cpe:2.3:a:fortinet:forticlient_enterprise_management_server:7.0.6:*:*:*:*:*:*:*",
                  "cpe:2.3:a:fortinet:forticlient_enterprise_management_server:7.2.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "forticlient_enterprise_management_server",
                "vendor": "fortinet",
                "versions": [
                  {
                    "lessThan": "6.3",
                    "status": "affected",
                    "version": "6.2.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "6.5",
                    "status": "affected",
                    "version": "6.4.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThanOrEqual": "7.0.4",
                    "status": "affected",
                    "version": "7.0.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThanOrEqual": "7.0.10",
                    "status": "affected",
                    "version": "7.0.6",
                    "versionType": "custom"
                  },
                  {
                    "lessThanOrEqual": "7.2.2",
                    "status": "affected",
                    "version": "7.2.0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-45581",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-07-09T17:06:14.506422Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-07-09T17:08:17.614Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T20:21:16.534Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "name": "https://fortiguard.com/psirt/FG-IR-23-357",
                "tags": [
                  "x_transferred"
                ],
                "url": "https://fortiguard.com/psirt/FG-IR-23-357"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "FortiClientEMS",
              "vendor": "Fortinet",
              "versions": [
                {
                  "lessThanOrEqual": "7.2.2",
                  "status": "affected",
                  "version": "7.2.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.0.10",
                  "status": "affected",
                  "version": "7.0.6",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.0.4",
                  "status": "affected",
                  "version": "7.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.4.9",
                  "status": "affected",
                  "version": "6.4.7",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.4.4",
                  "status": "affected",
                  "version": "6.4.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.2.9",
                  "status": "affected",
                  "version": "6.2.6",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.2.4",
                  "status": "affected",
                  "version": "6.2.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "An improper privilege management vulnerability [CWE-269] in Fortinet FortiClientEMS version 7.2.0 through 7.2.2 and before 7.0.10 allows an\u00a0Site administrator with Super Admin privileges to perform global administrative operations affecting other sites via crafted HTTP or HTTPS requests."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.9,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:X/RC:U",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-269",
                  "description": "Execute unauthorized code or commands",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-02-15T13:59:23.728Z",
            "orgId": "6abe59d8-c742-4dff-8ce8-9b0ca1073da8",
            "shortName": "fortinet"
          },
          "references": [
            {
              "name": "https://fortiguard.com/psirt/FG-IR-23-357",
              "url": "https://fortiguard.com/psirt/FG-IR-23-357"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "value": "Please upgrade to FortiClientEMS version 7.2.3 or above \nPlease upgrade to FortiClientEMS version 7.0.11 or above \n"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "6abe59d8-c742-4dff-8ce8-9b0ca1073da8",
        "assignerShortName": "fortinet",
        "cveId": "CVE-2023-45581",
        "datePublished": "2024-02-15T13:59:23.728Z",
        "dateReserved": "2023-10-09T08:01:29.296Z",
        "dateUpdated": "2024-08-02T20:21:16.534Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2021-44172 (GCVE-0-2021-44172)

    Vulnerability from cvelistv5 – Published: 2023-09-13 12:30 – Updated: 2024-09-24 19:55
    VLAI
    Summary
    An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiClientEMS versions 7.0.0 through 7.0.4, 7.0.6 through 7.0.7, in all 6.4 and 6.2 version management interface may allow an unauthenticated attacker to gain information on environment variables such as the EMS installation path.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-09-24 19:39 UTC
    CWE
    References
    Impacted products
    Vendor Product Version
    Fortinet FortiClientEMS Affected: 7.0.6 , ≤ 7.0.7 (semver)
    Affected: 7.0.0 , ≤ 7.0.4 (semver)
    Affected: 6.4.7 , ≤ 6.4.9 (semver)
    Affected: 6.4.0 , ≤ 6.4.4 (semver)
    Affected: 6.2.6 , ≤ 6.2.9 (semver)
    Affected: 6.2.0 , ≤ 6.2.4 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-04T04:17:24.531Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "name": "https://fortiguard.com/psirt/FG-IR-21-244",
                "tags": [
                  "x_transferred"
                ],
                "url": "https://fortiguard.com/psirt/FG-IR-21-244"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2021-44172",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-09-24T19:39:59.818505Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-09-24T19:55:20.426Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "FortiClientEMS",
              "vendor": "Fortinet",
              "versions": [
                {
                  "lessThanOrEqual": "7.0.7",
                  "status": "affected",
                  "version": "7.0.6",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.0.4",
                  "status": "affected",
                  "version": "7.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.4.9",
                  "status": "affected",
                  "version": "6.4.7",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.4.4",
                  "status": "affected",
                  "version": "6.4.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.2.9",
                  "status": "affected",
                  "version": "6.2.6",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.2.4",
                  "status": "affected",
                  "version": "6.2.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiClientEMS versions 7.0.0 through 7.0.4, 7.0.6 through 7.0.7, in all 6.4 and 6.2 version management interface may allow an unauthenticated attacker to gain information on environment variables such as the EMS installation path."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "ADJACENT_NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 3.6,
                "baseSeverity": "LOW",
                "confidentialityImpact": "LOW",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:O/RC:U",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-200",
                  "description": "Information disclosure",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2023-09-13T12:30:09.839Z",
            "orgId": "6abe59d8-c742-4dff-8ce8-9b0ca1073da8",
            "shortName": "fortinet"
          },
          "references": [
            {
              "name": "https://fortiguard.com/psirt/FG-IR-21-244",
              "url": "https://fortiguard.com/psirt/FG-IR-21-244"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "value": "Please upgrade to FortiClientEMS version 7.2.0 or above Please upgrade to FortiClientEMS version 7.0.8 or above "
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "6abe59d8-c742-4dff-8ce8-9b0ca1073da8",
        "assignerShortName": "fortinet",
        "cveId": "CVE-2021-44172",
        "datePublished": "2023-09-13T12:30:09.839Z",
        "dateReserved": "2021-11-23T15:35:55.087Z",
        "dateUpdated": "2024-09-24T19:55:20.426Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }