Vulnérabilités
Vulnérabilités affectant les pare-feu et équipements de sécurité, avec les correctifs des éditeurs, le statut CISA KEV et l’EPSS.
259 vulnérabilités
PAN-OS: Privilege Escalation (PE) Vulnerability in the Web Management Interface
Élevée7,2CVSS 3.1, Élevée95 %PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)
Critique9,8CVSS 3.1, Critique100 %- CVE-2024-255014 nov. 2024
PAN-OS: Firewall Denial of Service (DoS) in GlobalProtect Gateway Using a Specially Crafted Packet
Élevée7,5CVSS 3.1, Élevée0,51 % - CVE-2024-255114 nov. 2024
PAN-OS: Firewall Denial of Service (DoS) Using a Specially Crafted Packet
Élevée7,5CVSS 3.1, Élevée0,48 % - CVE-2024-3350512 nov. 2024
A heap-based buffer overflow in Fortinet FortiAnalyzer version 7.4.0 through 7.4.2, 7.2.0 through 7.2.5, 7.0.…
Élevée7,3CVSS 3.1, Élevée0,48 % - CVE-2024-2601112 nov. 2024
A missing authentication for critical function in Fortinet FortiManager version 7.4.0 through 7.4.2, 7.2.0 th…
Critique9,8CVSS 3.1, Critique0,60 % - CVE-2023-5017612 nov. 2024
A session fixation vulnerability in Fortinet FortiOS 7.4.0 through 7.4.3, FortiOS 7.2.0 through 7.2.7, FortiO…
Élevée8,8CVSS 3.1, Élevée0,40 % - CVE-2024-2366612 nov. 2024
A client-side enforcement of server-side security in Fortinet FortiAnalyzer-BigData at least version 7.4.0 an…
Élevée8,8CVSS 3.1, Élevée3 % Cisco ASA and FTD Denial-of-Service Vulnerability
Moyenne5,8CVSS 3.1, Moyenne16 %Fortinet FortiManager Missing Authentication Vulnerability
Critique9,8CVSS 3.1, Critique95 %- CVE-2024-94689 oct. 2024
PAN-OS: Firewall Denial of Service (DoS) via a Maliciously Crafted Packet
Élevée7,5CVSS 3.1, Élevée0,41 % Expedition: SQL Injection Leads to Firewall Admin Credential Disclosure
Critique9,1CVSS 3.1, Critique100 %Expedition: Unauthenticated OS Command Injection Vulnerability Leads to Firewall Credential Disclosure
Élevée7,5CVSS 3.1, Élevée99 %- CVE-2024-869111 sept. 2024
PAN-OS: User Impersonation in GlobalProtect Portal
Élevée7,1CVSS 3.1, Élevée0,32 % - CVE-2024-868711 sept. 2024
PAN-OS: Cleartext Exposure of GlobalProtect Portal Passcodes
Élevée7,1CVSS 3.1, Élevée0,41 % - CVE-2024-868611 sept. 2024
PAN-OS: Command Injection Vulnerability
Élevée7,2CVSS 3.1, Élevée1 % Cisco Smart Licensing Utility Static Credential Vulnerability
Critique9,8CVSS 3.1, Critique97 %- CVE-2024-2175713 août 2024
A unverified password change in Fortinet FortiManager versions 7.0.0 through 7.0.10, versions 7.2.0 through 7…
Élevée7,8CVSS 3.1, Élevée0,19 % - CVE-2022-4586213 août 2024
An insufficient session expiration vulnerability [CWE-613] vulnerability in FortiOS 7.2.5 and below, 7.0 all …
Élevée8,8CVSS 3.1, Élevée0,44 % Expedition: Missing Authentication Leads to Admin Account Takeover
Critique9,8CVSS 3.1, Critique92 %Cisco NX-OS Software CLI Command Injection Vulnerability
Moyenne6,7CVSS 3.1, Moyenne4 %- CVE-2024-2601011 juin 2024
A stack-based buffer overflow in Fortinet FortiPAM version 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, F…
Élevée7,5CVSS 3.1, Élevée0,79 % - CVE-2023-4672011 juin 2024
A stack-based buffer overflow in Fortinet FortiOS version 7.4.0 through 7.4.1 and 7.2.0 through 7.2.7 and 7.0…
Élevée7,8CVSS 3.1, Élevée0,28 % - CVE-2024-2311011 juin 2024
A stack-based buffer overflow in Fortinet FortiOS version 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 thr…
Élevée7,8CVSS 3.1, Élevée0,28 % Information disclosure
Élevée8,6CVSS 3.1, Élevée100 %- CVE-2023-4558314 mai 2024
A use of externally-controlled format string vulnerability in Fortinet FortiOS 7.4.0, FortiOS 7.2.0 through 7…
Élevée7,2CVSS 3.1, Élevée0,66 % - CVE-2023-4671414 mai 2024
A stack-based buffer overflow [CWE-121] vulnerability in Fortinet FortiOS version 7.2.1 through 7.2.6 and ver…
Élevée7,2CVSS 3.1, Élevée1 % - CVE-2023-4424714 mai 2024
A double free vulnerability [CWE-415] vulnerability in Fortinet FortiOS 6.4 all versions may allow a privileg…
Élevée7,2CVSS 3.1, Élevée1 % - CVE-2024-2600714 mai 2024
An improper check or handling of exceptional conditions vulnerability [CWE-703] in Fortinet FortiOS version 7…
Élevée7,5CVSS 3.1, Élevée1 % Cisco ASA and FTD Privilege Escalation Vulnerability
Moyenne6CVSS 3.1, Moyenne19 %