Known Vulnerabilities for Fortiportal by Fortinet
Listed below are 10 of the newest known vulnerabilities associated with "Fortiportal" by "Fortinet".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2021-36172 | An improper restriction of XML external entity reference vulnerability in the parser of XML responses of FortiPortal before 6... | 8.1 - HIGH | 2021-11-02 | 2021-11-04 |
| CVE-2021-36171 | The use of a cryptographically weak pseudo-random number generator in the password reset feature of FortiPortal before 6.0.6 ... | 8.1 - HIGH | 2022-03-01 | 2022-03-09 |
| CVE-2021-36168 | A Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Fortinet FortiPortal 6.x before 6.0.5, Fo... | 6.5 - MEDIUM | 2021-08-04 | 2021-08-10 |
| CVE-2021-32602 | An improper neutralization of input during web page generation vulnerability (CWE-79) in FortiPortal GUI 6.0.4 and below, 5.3... | 6.1 - MEDIUM | 2021-08-19 | 2021-08-25 |
| CVE-2021-32596 | A use of one-way hash with a predictable salt vulnerability in the password storing mechanism of FortiPortal 6.0.0 through 6.... | 7.5 - HIGH | 2021-08-04 | 2021-08-10 |
| CVE-2021-32595 | Multiple uncontrolled resource consumption vulnerabilities in the web interface of FortiPortal before 6.0.6 may allow a singl... | 6.5 - MEDIUM | 2021-11-02 | 2021-11-03 |
| CVE-2021-32594 | An unrestricted file upload vulnerability in the web interface of FortiPortal 6.0.0 through 6.0.4, 5.3.0 through 5.3.5, 5.2.0... | 8.1 - HIGH | 2021-08-04 | 2021-08-11 |
| CVE-2021-32590 | Multiple improper neutralization of special elements used in an SQL command vulnerabilities in FortiPortal 6.0.0 through 6.0.... | 8.8 - HIGH | 2021-08-04 | 2021-08-11 |
| CVE-2021-32588 | A use of hard-coded credentials (CWE-798) vulnerability in FortiPortal versions 5.2.5 and below, 5.3.5 and below, 6.0.4 and b... | 9.8 - CRITICAL | 2021-08-18 | 2021-08-26 |
| CVE-2021-26104 | Multiple OS command injection (CWE-78) vulnerabilities in the command line interface of FortiManager 6.2.7 and below, 6.4.5 a... | 7.8 - HIGH | 2022-04-06 | 2022-07-28 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Fortinet | Fortiportal | 4.0.0 | All | All | All |