Skip to content
COOEY

FAIL › dossier

fortios

PRODUCT

· dossier confidence 33%

Fortinet's FortiOS has a concerning history of critical vulnerabilities, including remote code execution and authentication bypasses, requiring immediate attention and remediation to mitigate potential risks. Recent patches address authentication bypasses and command injection flaws, highlighting ongoing security challenges.

PROFILE
CategoryNetwork SecurityWhat they doFortinet provides a broad range of cybersecurity solutions, including firewalls, VPNs, and security management platforms. Their FortiOS operating system powers many of their network security appliances. Websitehttps://www.fortinet.com/ ↗
SECURITY POSTURE

Fortinet's FortiOS has a history of critical vulnerabilities, including remote code execution and authentication bypasses, indicating a need for improved security practices and rigorous testing.

Notable failures
  • Hard-coded credentials in configuration backups (CVE-2019-6693)
  • Unauthenticated remote code execution (CVE-2024-21762)
  • Heap-based buffer overflow (CVE-2022-42475)
  • Path traversal vulnerability allowing file download (CVE-2018-13379)
  • Improper authentication allowing unauthorized login (CVE-2020-12812)
  • Authentication bypass vulnerability (CVE-2024-55591)
Patterns: Remote code execution vulnerabilities; Authentication bypass vulnerabilities; Path traversal vulnerabilities; Lack of integrity checking in file downloads
FAILURE HISTORY · 16
DATEEVENTSEVSUMMARY
2025-06-25 CVE-2019-6693 critical Fortinet FortiOS shipped with hard-coded credentials allowing attackers to decrypt sensitive data from configuration backups.
2024-02-09 CVE-2024-21762 critical Fortinet FortiOS suffered a critical out-of-bounds write vulnerability allowing unauthenticated remote code execution.
2022-12-13 CVE-2022-42475 critical Fortinet FortiOS SSL-VPN suffered a heap-based buffer overflow allowing unauthenticated remote code execution.
2021-12-10 CVE-2021-44168 high Fortinet FortiOS allows arbitrary file downloads via an unpatched vulnerability that was actively exploited in the wild.
2026-07-27 CVE-2025-68686 high A bypass vulnerability in FortiOS allows attackers to access sensitive information after initial compromise, circumventing previous patches and requiring immediate action for DIB organizations using the product.
2023-03-14 CVE-2022-41328 high FortiOS RCE flaw exploited in wild
2021-11-03 CVE-2020-12812 critical Fortinet FortiOS allowed unauthorized logins by manipulating username case, bypassing multi-factor authentication (MFA).
2021-11-03 CVE-2018-13379 critical Fortinet's FortiOS allowed unauthenticated attackers to download system files via a path traversal vulnerability, actively exploited in the wild and linked to ransomware activity.
2021-11-03 CVE-2019-5591 high Fortinet FortiOS default configurations allowed unauthenticated attackers on the same subnet to impersonate an LDAP server and intercept sensitive information.
2025-01-14 CVE-2024-55591 critical An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy version 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12 allows a remote attacker to gain super-admin privileges via crafted requests to 
2024-03-12 CVE-2023-42789 critical A out-of-bounds write vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2.0 through 7.2.5, FortiOS 7.0.0 through 7.0.12, FortiOS 6.4.0 through 6.4.14, FortiOS 6.2.0 through 6.2.15, FortiProxy 7.4.0, FortiProxy 7.2.0 through 7.2.6, FortiProxy 7.0.0 through 7.0.12, F
2025-01-14 CVE-2024-48884 high A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiManager 7.6.0 through 7.6.1, FortiManager 7.4.1 through 7.4.3, FortiManager Cloud 7.4.1 through 7.4.3, FortiOS 7.6.0, FortiOS 7.4.0 through 7.4.4, FortiOS 7.2.0 through
2024-02-09 CVE-2024-21762 critical CVE-2024-21762: A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 th
2023-06-13 CVE-2023-27997 critical CVE-2023-27997: A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 an
2022-10-18 CVE-2022-40684 critical CVE-2022-40684: An authentication bypass using an alternate path or channel [CWE-288] in Fortine
2020-07-24 CVE-2020-12812 critical CVE-2020-12812: An improper authentication vulnerability in SSL VPN in FortiOS 6.4.0, 6.2.0 to 6
Open questions: What specific remediation steps are being taken to address the recurring vulnerability patterns? · What is the current status of patching and mitigation for the identified CVEs? · What is the root cause analysis process for these vulnerabilities?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-20 04:45:17.194022+00:00