Home/Product/fortinet fortiwlm
Product

fortinet fortiwlm

23 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2023-34990
>= 8.5.0 and < 8.5.5
A relative path traversal in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unau
9.8CRITICAL
CVE-2023-48782
>= 8.6.0 and <= 8.6.5
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 th
8.8HIGH
CVE-2023-42783
>= 8.5.0 and <= 8.5.4
A relative path traversal in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 and 8.4.2 through 8.4.0 and 8.3
7.5HIGH
CVE-2023-34991
>= 8.5.0 and <= 8.5.4
A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiWLM version 8.6.0 through
9.8CRITICAL
CVE-2023-36550
>= 8.5.0 and <= 8.5.4
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 th
9.8CRITICAL
CVE-2023-36549
>= 8.5.0 and <= 8.5.4
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 th
8.8HIGH
CVE-2023-36548
>= 8.5.0 and <= 8.5.4
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 th
9.8CRITICAL
CVE-2023-36547
>= 8.5.0 and <= 8.5.4
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 th
9.8CRITICAL
CVE-2023-34993
>= 8.5.0 and <= 8.5.4
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 th
9.8CRITICAL
CVE-2023-34989
>= 8.5.0 and <= 8.5.4
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 th
8.8HIGH
CVE-2023-34988
>= 8.5.0 and <= 8.5.4
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 th
8.8HIGH
CVE-2023-34987
>= 8.5.0 and <= 8.5.4
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 th
8.8HIGH
CVE-2023-34986
>= 8.5.0 and <= 8.5.4
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 th
8.8HIGH
CVE-2023-34985
>= 8.5.0 and <= 8.5.4
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 th
8.8HIGH
CVE-2021-43070
>= 8.3.0 and <= 8.3.3
Multiple relative path traversal vulnerabilities [CWE-23] in FortiWLM management interface 8.6.2 and below, 8.5.2 and below, 8.4.2
5.4MEDIUM
CVE-2021-43077
<= 8.3.2
A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiWLM version 8.6.2 and belo
8.8HIGH
CVE-2021-43075
<= 8.3.2
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.2 an
8.8HIGH
CVE-2021-42760
<= 8.6.1
A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiWLM version 8.6.1 and belo
8.8HIGH
CVE-2021-42752
<= 8.6.1
A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiWLM version 8.6.1 and belo
5.4MEDIUM
CVE-2021-41029
<= 8.6.1
A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiWLM version 8.6.1 and belo
6.4MEDIUM
CVE-2021-36185
>= 8.2.2 and <= 8.6.1
A improper neutralization of special elements used in an OS command ('OS Command Injection') in Fortinet FortiWLM version 8.6.1 an
8.8HIGH
CVE-2021-36184
>= 8.2.2 and <= 8.6.1
A improper neutralization of Special Elements used in an SQL Command ('SQL Injection') in Fortinet FortiWLM version 8.6.1 and belo
8.8HIGH
CVE-2017-7336
<= 8.3.0
A hard-coded account named 'upgrade' in Fortinet FortiWLM 8.3.0 and lower versions allows a remote attacker to log-in and execute
9.8CRITICAL
threatengine.sh