A network-reachable heap overflow in FortiOS, FortiSwitchManager and FortiSASE lets unauthenticated attackers send crafted packets to run unauthorised code, and it’s already known to be exploited.
Posts tagged: Fortinet
Improper Authentication of FortiPAM Server
A Chrome extension that mediates FortiPAM privileged access sessions can be tricked into routing a user’s browser traffic through an attacker’s servers just by visiting a malicious site.