Known vulnerabilities in Fortinet, Inc FortiManager 6.4.11

Vendor: Fortinet, Inc
Website: https://www.fortinet.com/
Total Security Bulletins: 37

Security bulletins (37)

Secuity bulletin Severity Status Published
SB2025120942: Insecure private key storage in Fortinet products Low
Patched
09.12.2025
SB20251014106: Heap-based buffer overflow in Fortinet products Low
Patched
14.10.2025
SB20250812101: Path traversal in FortiManager Low
Patched
12.08.2025
SB2025070869: SQL injection in FortiManager and FortiAnalyzer forward module Low
Patched
08.07.2025
SB2025041041: Buffer underflow in Fortinet products Medium
Patched
10.04.2025
SB2025041039: Missing authentication for critical function in FortiManager High
Patched
10.04.2025
SB2025041038: Multiple vulnerabilities in Fortinet products Low
Patched
10.04.2025
SB2025040977: Privilege escalation via external connector in FortiManager and FortiAnalyzer Low
Patched
09.04.2025
SB2025040976: Arbitrary file deletion via CLI in FortiAnalyzer and FortiManager Low
Patched
09.04.2025
SB2025040975: Use of hard-coded cryptographic key in FortiManager Low
Patched
09.04.2025
SB2025040909: MitM attack in FortiManager High
Patched
09.04.2025
SB20250311116: SQL injection in FortiManager and FortiAnalyzer Low
Patched
11.03.2025
SB20250311115: Privilege escalation in FortiAnalyzer and FortiManager Low
Patched
11.03.2025
SB20250211167: Inclusion of sensitive information into event log in FortiManager Medium
Patched
11.02.2025
SB2025011439: Arbitrary file deletion in FortiManager and FortiAnalyzer Low
Patched
14.01.2025
SB2025011436: Multiple vulnerabilities in FortiManager Medium
Patched
14.01.2025
SB2024121834: OS command injection in FortiManager Low
Patched
18.12.2024
SB2024112169: Privilege escalation in FortiManager Low
Patched
21.11.2024
SB2024112168: Security restrictions bypass in FortiManager Medium
Patched Public exploit
21.11.2024
SB2024111415: Unauthorized file creation in FortiManager Low
Patched
14.11.2024
SB2024111413: Privilege escalation in FortiManager Low
Patched
14.11.2024
SB2024111410: Path traversal in FortiManager Low
Patched
14.11.2024
SB2024111405: Arbitrary file deletion in FortiManager Low
Patched
14.11.2024
SB2024111402: Improper access control in FortiManager Low
Patched
14.11.2024
SB20241112169: Remote code execution in FortiManager httpd High
Patched
12.11.2024
SB20241112152: Improper authentication in FortiManager fgfmd Medium
Patched
12.11.2024
SB2024102360: Remote command execution in Fortinet FortiManager Critical
Patched Exploited
23.10.2024
SB2024101445: FortiManager update for OpenSSH regreSSHion attack High
Patched Public exploit
14.10.2024
SB2024091087: Improper access control in FortiAnalyzer and FortiManager Low
Patched
10.09.2024
SB2024031434: Format string error in Fortinet FortiManager, FortiAnalyzer, FortiAnalyzer-BigData and FortiPortal Low
Patched
14.03.2024
SB2024031433: Improper access control in Fortinet FortiManager High
Patched
14.03.2024
SB2023101257: Multiple vulnerabilities in Fortinet FortiManager and FortiAnalyzer Medium
Patched Public exploit
12.10.2023
SB2023101256: Multiple vulnerabilities in Fortinet FortiAnalyzer and FortiManager Medium
Patched
12.10.2023
SB2023101255: Improper access control in Fortinet FortiManager Medium
Patched
12.10.2023
SB2023101254: OS Command Injection in Fortinet FortiManager, FortiAnalyzer and FortiADC Low
Patched
12.10.2023
SB2023091976: Information disclosure in FortiManager and FortiAnalyzer Low
Patched
19.09.2023
SB2023061325: SSRF in FortiManager and FortiAnalyzer Medium
Patched
13.06.2023