Home/Product/fortinet fortiwlc
Product

fortinet fortiwlc

14 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2021-32584
>= 8.1.3 and < 8.5.4
An improper access control (CWE-284) vulnerability in FortiWLC version 8.6.0, version 8.5.3 and below, version 8.4.8 and below, ve
5.3MEDIUM
CVE-2021-26087
>= 8.4.0 and <= 8.4.2
An improper neutralization of input during web page generation in FortiWLC version 8.6.0, version 8.5.3 and below, version 8.4.8 a
4.3MEDIUM
CVE-2021-22126
>= 8.4.0 and < 8.5.3
A use of hard-coded password vulnerability in FortiWLC version 8.5.2 and below, version 8.4.8 and below, version 8.3.3 to 8.3.2, v
6.7MEDIUM
CVE-2022-23439
>= 8.6.0 and < 8.6.7
A externally controlled reference to a resource in another sphere vulnerability in Fortinet allows attacker to poison web caches
4.7MEDIUM
CVE-2021-26093
>= 8.0.6 and < 8.6.3
An access of uninitialized pointer (CWE-824) vulnerability in FortiWLC versions 8.6.0, 8.5.3 and earlier may allow a local and au
7.3HIGH
CVE-2021-42758
>= 8.2.4 and <= 8.2.7
An improper access control vulnerability [CWE-284] in FortiWLC 8.6.1 and below may allow an authenticated and remote attacker with
8.8HIGH
CVE-2020-9288
<= 8.5.1
An improper neutralization of input vulnerability in FortiWLC 8.5.1 allows a remote authenticated attacker to perform a stored cro
5.4MEDIUM
CVE-2017-17540
>= 7.0 and <= 7.0.11
The presence of a hardcoded account in Fortinet FortiWLC 8.3.3 allows attackers to gain unauthorized read/write access via a remot
9.8CRITICAL
CVE-2017-17539
>= 7.0 and <= 7.0.11
The presence of a hardcoded account in Fortinet FortiWLC 7.0.11 and earlier allows attackers to gain unauthorized read/write acces
9.8CRITICAL
CVE-2017-7341
>= 6.1-2 and <= 6.1-5
An OS Command Injection vulnerability in Fortinet FortiWLC 6.1-2 through 6.1-5, 7.0-7 through 7.0-10, 8.0 through 8.2, and 8.3.0 t
7.2HIGH
CVE-2017-7335
all versions
A Cross-Site Scripting (XSS) vulnerability in Fortinet FortiWLC 6.1-x (6.1-2, 6.1-4 and 6.1-5); 7.0-x (7.0-7, 7.0-8, 7.0-9, 7.0-10
5.4MEDIUM
CVE-2016-8491
all versions
The presence of a hardcoded account named 'core' in Fortinet FortiWLC allows attackers to gain unauthorized read/write access via
9.1CRITICAL
CVE-2016-7561
<= 6.1-2-29
Fortinet FortiWLC 6.1-2-29 and earlier, 7.0-9-1, 7.0-10-0, 8.0-5-0, 8.1-2-0, and 8.2-4-0 allow administrators to obtain sensitive
7.2HIGH
CVE-2016-7560
<= 6.1-2-29
The rsyncd server in Fortinet FortiWLC 6.1-2-29 and earlier, 7.0-9-1, 7.0-10-0, 8.0-5-0, 8.1-2-0, and 8.2-4-0 has a hardcoded rsyn
9.8CRITICAL
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin