Fortinet FortiDeceptor 3.1

CPE Details

Fortinet FortiDeceptor 3.1
3.1
2020-06-25
15h09 +00:00
2020-06-25
15h09 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:fortinet:fortideceptor:3.1:*:*:*:*:*:*:*

Informations

Vendor

fortinet

Product

fortideceptor

Version

3.1

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2024-35280 2025-01-15 10h07 +00:00 A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiDeceptor 3.x all versions, 4.x all versions, 5.0 all versions, 5.1 all versions, version 5.2.0, and version 5.3.0 may allow an attacker to perform a reflected cross-site scripting attack in the recovery endpoints
6.1
Medium
CVE-2022-27487 2023-04-11 16h06 +00:00 A improper privilege management in Fortinet FortiSandbox version 4.2.0 through 4.2.2, 4.0.0 through 4.0.2 and before 3.2.3 and FortiDeceptor version 4.1.0, 4.0.0 through 4.0.2 and before 3.3.3 allows a remote authenticated attacker to perform unauthorized API calls via crafted HTTP or HTTPS requests.
8.8
High
CVE-2023-26209 2023-03-09 14h55 +00:00 A improper restriction of excessive authentication attempts vulnerability [CWE-307] in Fortinet FortiDeceptor 3.1.x and before allows a remote unauthenticated attacker to partially exhaust CPU and memory via sending numerous HTTP requests to the login form.
5.3
Medium
CVE-2022-30302 2022-07-18 14h40 +00:00 Multiple relative path traversal vulnerabilities [CWE-23] in FortiDeceptor management interface 1.0.0 through 3.2.x, 3.3.0 through 3.3.2, 4.0.0 through 4.0.1 may allow a remote and authenticated attacker to retrieve and delete arbitrary files from the underlying filesystem via specially crafted web requests.
8.1
High