Home/Product/fortinet fortiddos
Product

fortinet fortiddos

9 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2026-39815
>= 7.2.1 and < 7.2.3
A improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiDDoS-F 7.2.1
8.8HIGH
CVE-2024-45325
>= 6.1.0 and < 7.0.3
An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] in Fortinet
6.7MEDIUM
CVE-2021-24008
all versions
An exposure of sensitive system information to an unauthorized control sphere vulnerability [CWE-497] in FortiDDoS version 5.4.0,
5.3MEDIUM
CVE-2022-23439
>= 6.1.0 and < 6.3.4
A externally controlled reference to a resource in another sphere vulnerability in Fortinet allows attacker to poison web caches
4.7MEDIUM
CVE-2022-27486
all versions
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiDDoS version 5.5.0 t
6.6MEDIUM
CVE-2023-29177
>= 6.1.0 and <= 6.1.4
Multiple buffer copy without checking size of input ('classic buffer overflow') vulnerabilities [CWE-120] in FortiADC version 7.2.
6.7MEDIUM
CVE-2023-25603
>= 6.3.0 and <= 6.3.4
A permissive cross-domain policy with untrusted domains vulnerability in Fortinet FortiADC 7.1.0 - 7.1.1, FortiDDoS-F 6.3.0 - 6.3.
5.4MEDIUM
CVE-2022-40679
>= 6.1.0 and < 6.1.5
An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in FortiADC 5.x all versions, 6.0 al
7.8HIGH
CVE-2022-29060
all versions
A use of hard-coded cryptographic key vulnerability [CWE-321] in FortiDDoS API 5.5.0 through 5.5.1, 5.4.0 through 5.4.2, 5.3.0 thr
8.1HIGH
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin