CISA Catalog
Data sourced from the official CISA Known Exploited Vulnerabilities Catalog. Federal agencies are required to remediate these vulnerabilities by the due date per BOD 22-01.
KEV Entries
1,660
Ransomware Use
335
Overdue
1,655
Vendors
276
Products
671
29 results · Page 2/2
Fortinet FortiOS Arbitrary File Download
Fortinet · FortiOS
Fortinet FortiOS "execute restore src-vis" downloads code without integrity checking, allowing an attacker to arbitrarily download files.
Required Action
Apply updates per vendor instructions.
Fortinet FortiOS Default Configuration Vulnerability
Fortinet · FortiOS
Fortinet FortiOS contains a default configuration vulnerability that may allow an unauthenticated attacker on the same subnet to intercept sensitive information by impersonating the Lightweight Directory Access Protocol (LDAP) server.
Required Action
Apply updates per vendor instructions.
Fortinet FortiOS SSL VPN Improper Authentication Vulnerability
Fortinet · FortiOS
Fortinet FortiOS SSL VPN contains an improper authentication vulnerability that may allow a user to login successfully without being prompted for the second factor of authentication (FortiToken) if they change the case in their username.
Required Action
Apply updates per vendor instructions.
Fortinet FortiOS SSL VPN Path Traversal Vulnerability
Fortinet · FortiOS
Fortinet FortiOS SSL VPN web portal contains a path traversal vulnerability that may allow an unauthenticated attacker to download FortiOS system files through specially crafted HTTP resource requests.
Required Action
Apply updates per vendor instructions.