Fortinet FortiMail 7.0.6

CPE Details

Fortinet FortiMail 7.0.6
7.0.6
2025-02-07
01h07 +00:00
2025-02-07
01h07 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:fortinet:fortimail:7.0.6:*:*:*:*:*:*:*

Informations

Vendor

fortinet

Product

fortimail

Version

7.0.6

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2024-56497 2025-01-14 14h09 +00:00 An improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiMail versions 7.2.0 through 7.2.4 and 7.0.0 through 7.0.6 and 6.4.0 through 6.4.7, FortiRecorder versions 7.0.0 and 6.4.0 through 6.4.4 allows attacker to execute unauthorized code or commands via the CLI.
6.7
Medium
CVE-2023-45582 2023-11-14 18h05 +00:00 An improper restriction of excessive authentication attempts vulnerability [CWE-307] in FortiMail webmail version 7.2.0 through 7.2.4, 7.0.0 through 7.0.6 and before 6.4.8 may allow an unauthenticated attacker to  perform a brute force attack on the affected endpoints via repeated login attempts.
7.3
High
CVE-2022-26114 2022-09-06 13h15 +00:00 An improper neutralization of input during web page generation vulnerability [CWE-79] in the Webmail of FortiMail before 7.2.0 may allow an unauthenticated attacker to trigger a cross-site scripting (XSS) attack via sending specially crafted mail messages.
6.1
Medium
CVE-2021-32591 2021-12-08 10h56 +00:00 A missing cryptographic steps vulnerability in the function that encrypts users' LDAP and RADIUS credentials in FortiSandbox before 4.0.1, FortiWeb before 6.3.12, FortiADC before 6.2.1, FortiMail 7.0.1 and earlier may allow an attacker in possession of the password store to compromise the confidentiality of the encrypted secrets.
5.3
Medium