Latest CVE Feed
-
6.5
MEDIUMCVE-2021-41026
A relative path traversal in FortiWeb versions 6.4.1, 6.4.0, and 6.3.0 through 6.3.15 may allow an authenticated attacker to retrieve arbitrary files from the underlying filesystem via specially crafted web requests.... Read more
Affected Products : fortiweb- Published: Apr. 06, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-41025
Multiple vulnerabilities in the authentication mechanism of confd in FortiWeb versions 6.4.1, 6.4.0, 6.3.0 through 6.3.15, 6.2.0 through 6.2.6, 6.1.0 through 6.1.2, 6.0.0 thorugh 6.0.7, including an instance of concurrent execution using shared resource w... Read more
Affected Products : fortiweb- Published: Dec. 08, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-41024
A relative path traversal [CWE-23] vulnerabiltiy in FortiOS versions 7.0.0 and 7.0.1 and FortiProxy verison 7.0.0 may allow an unauthenticated, unauthorized attacker to inject path traversal character sequences to disclose sensitive information of the ser... Read more
- Published: Dec. 08, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-41023
A unprotected storage of credentials in Fortinet FortiSIEM Windows Agent version 4.1.4 and below allows an authenticated user to disclosure agent password due to plaintext credential storage in log files... Read more
- Published: Nov. 02, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-41022
A improper privilege management in Fortinet FortiSIEM Windows Agent version 4.1.4 and below allows attacker to execute privileged code or commands via powershell scripts... Read more
- Published: Nov. 02, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-41021
A privilege escalation vulnerability in FortiNAC versions 8.8.8 and below and 9.1.2 and below may allow an admin user to escalate the privileges to root via the sudo command.... Read more
Affected Products : fortinac- Published: Dec. 08, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-41020
An improper access control vulnerability [CWE-284] in FortiIsolator versions 2.3.2 and below may allow an authenticated, non privileged attacker to regenerate the CA certificate via the regeneration URL.... Read more
Affected Products : fortiisolator- Published: May. 04, 2022
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-41019
An improper validation of certificate with host mismatch [CWE-297] vulnerability in FortiOS versions 6.4.6 and below may allow the connection to a malicious LDAP server via options in GUI, leading to disclosure of sensitive information, such as AD credent... Read more
Affected Products : fortios- Published: Nov. 02, 2021
- Modified: Nov. 21, 2024
-
9.0
HIGHCVE-2021-41018
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below allows attacker to execute unauthorized code or commands via crafted HTTP requests.... Read more
Affected Products : fortiweb- Published: Feb. 02, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-41017
Multiple heap-based buffer overflow vulnerabilities in some web API controllers of FortiWeb 6.4.1, 6.4.0, and 6.3.0 through 6.3.15 may allow a remote authenticated attacker to execute arbitrary code or commands via specifically crafted HTTP requests.... Read more
Affected Products : fortiweb- Published: Dec. 08, 2021
- Modified: Nov. 21, 2024
-
9.0
HIGHCVE-2021-41016
A improper neutralization of special elements used in a command ('command injection') in Fortinet FortiExtender version 7.0.1 and below, 4.2.3 and below, 4.1.7 and below allows an authenticated attacker to execute privileged shell commands via CLI command... Read more
- Published: Feb. 02, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-41015
A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below allows attacker to execute unauthorized code or commands via crafted HTTP requests to SAML login handler... Read more
Affected Products : fortiweb- Published: Dec. 08, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-41014
A uncontrolled resource consumption in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below allows an unauthenticated attacker to make the httpsd daemon unresponsive via huge HTTP packets... Read more
Affected Products : fortiweb- Published: Dec. 08, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-41013
An improper access control vulnerability [CWE-284] in FortiWeb versions 6.4.1 and below and 6.3.15 and below in the Report Browse section of Log & Report may allow an unauthorized and unauthenticated user to access the Log reports via their URLs.... Read more
Affected Products : fortiweb- Published: Dec. 08, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-41011
LINE client for iOS before 11.15.0 might expose authentication information for a certain service to external entities under certain conditions. This is usually impossible, but in combination with a server-side bug, attackers could get this information.... Read more
Affected Products : line- Published: Sep. 22, 2021
- Modified: Nov. 21, 2024
-
6.8
MEDIUMCVE-2021-41005
A remote vulnerability was discovered in Aruba Instant On 1930 Switch Series version(s): Firmware below v1.0.7.0.... Read more
Affected Products : aruba_instant_on_1930_8g_2sfp_firmware aruba_instant_on_1930_8g_class4_poe_2sfp_124w_firmware aruba_instant_on_1930_48g_class4_poe_4sfp\/sfp\+_370w_firmware aruba_instant_on_1930_48g_4sfp\/sfp\+_firmware aruba_instant_on_1930_24g_class4_poe_4sfp\/sfp\+_370w_firmware aruba_instant_on_1930_24g_class4_poe_4sfp\/sfp\+_195w_firmware aruba_instant_on_1930_24g_4sfp\/sfp\+_firmware aruba_instant_on_1930_8g_2sfp aruba_instant_on_1930_8g_class4_poe_2sfp_124w aruba_instant_on_1930_48g_class4_poe_4sfp\/sfp\+_370w +4 more products- Published: Apr. 12, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-41004
A remote vulnerability was discovered in Aruba Instant On 1930 Switch Series version(s): Firmware below v1.0.7.0.... Read more
Affected Products : aruba_instant_on_1930_8g_2sfp_firmware aruba_instant_on_1930_8g_class4_poe_2sfp_124w_firmware aruba_instant_on_1930_48g_class4_poe_4sfp\/sfp\+_370w_firmware aruba_instant_on_1930_48g_4sfp\/sfp\+_firmware aruba_instant_on_1930_24g_class4_poe_4sfp\/sfp\+_370w_firmware aruba_instant_on_1930_24g_class4_poe_4sfp\/sfp\+_195w_firmware aruba_instant_on_1930_24g_4sfp\/sfp\+_firmware aruba_instant_on_1930_8g_2sfp aruba_instant_on_1930_8g_class4_poe_2sfp_124w aruba_instant_on_1930_48g_class4_poe_4sfp\/sfp\+_370w +4 more products- Published: Apr. 12, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-41003
Multiple unauthenticated command injection vulnerabilities were discovered in the AOS-CX API interface in Aruba CX 6200F Switch Series, Aruba 6300 Switch Series, Aruba 6400 Switch Series, Aruba 8320 Switch Series, Aruba 8325 Switch Series, Aruba 8400 Swit... Read more
Affected Products : arubaos-cx aruba_cx_6200f aruba_cx_6300f aruba_cx_6300m aruba_cx_6405 aruba_cx_6410 aruba_8320 aruba_8325-32-c aruba_8325-48y8c aruba_8360-12c +5 more products- Published: Mar. 02, 2022
- Modified: Nov. 21, 2024
-
8.5
HIGHCVE-2021-41002
Multiple authenticated remote path traversal vulnerabilities were discovered in the AOS-CX command line interface in Aruba CX 6200F Switch Series, Aruba 6300 Switch Series, Aruba 6400 Switch Series, Aruba 8320 Switch Series, Aruba 8325 Switch Series, Arub... Read more
Affected Products : arubaos-cx aruba_cx_6200f aruba_cx_6300f aruba_cx_6300m aruba_cx_6405 aruba_cx_6410 aruba_8320 aruba_8325-32-c aruba_8325-48y8c aruba_8360-12c +5 more products- Published: Mar. 02, 2022
- Modified: Nov. 21, 2024
-
9.0
HIGHCVE-2021-41001
An authenticated remote code execution vulnerability was discovered in the AOS-CX Network Analytics Engine (NAE) in Aruba CX 6200F Switch Series, Aruba 6300 Switch Series, Aruba 6400 Switch Series, Aruba 8320 Switch Series, Aruba 8325 Switch Series, Aruba... Read more
Affected Products : arubaos-cx aruba_cx_6200f aruba_cx_6300f aruba_cx_6300m aruba_cx_6405 aruba_cx_6410 aruba_8320 aruba_8325-32-c aruba_8325-48y8c aruba_8360-12c +5 more products- Published: Mar. 02, 2022
- Modified: Nov. 21, 2024