Home/Product/fortinet fortiisolator
Product

fortinet fortiisolator

10 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2024-33507
>= 2.3.0 and < 2.4.5
An insufficient session expiration vulnerability [CWE-613] and an incorrect authorization vulnerability [CWE-863] in FortiIsolator
7.4HIGH
CVE-2024-32124
>= 2.3.0 and <= 2.3.4
An improper access control vulnerability [CWE-284] in FortiIsolator version 2.4.4, version 2.4.3, 2.3 all versions logging compone
4.3MEDIUM
CVE-2024-27779
>= 1.2.0 and < 2.4.5
An insufficient session expiration vulnerability [CWE-613] in FortiSandbox version 4.4.4 and below, version 4.2.6 and
6.7MEDIUM
CVE-2024-54025
>= 2.4.3 and < 2.4.7
An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet F
6.7MEDIUM
CVE-2024-54024
>= 2.4.3 and < 2.4.7
An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet F
7.2HIGH
CVE-2024-55590
>= 2.4.0 and < 2.4.6
Multiple improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] in Fo
8.8HIGH
CVE-2022-22298
>= 2.3.0 and <= 2.3.4
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiIsolator version 1.0
6.7MEDIUM
CVE-2021-41020
>= 2.3.0 and < 2.3.3
An improper access control vulnerability [CWE-284] in FortiIsolator versions 2.3.2 and below may allow an authenticated, non privi
8.8HIGH
CVE-2020-6649
<= 2.0.1
An insufficient session expiration vulnerability in FortiNet's FortiIsolator version 2.0.1 and below may allow an attacker to reus
9.8CRITICAL
CVE-2020-6643
<= 1.2.2
An improper neutralization of input vulnerability in the URL Description in Fortinet FortiIsolator version 1.2.2 allows a remote a
5.4MEDIUM
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin