FAIL › dossier
fortios
PRODUCT· dossier confidence 33%
Fortinet's FortiOS has a concerning history of critical vulnerabilities, including remote code execution and authentication bypasses, requiring immediate attention and remediation to mitigate potential risks. Recent patches address authentication bypasses and command injection flaws, highlighting ongoing security challenges.
PROFILE
CategoryNetwork SecurityWhat they doFortinet provides a broad range of cybersecurity solutions, including firewalls, VPNs, and security management platforms. Their FortiOS operating system powers many of their network security appliances.
Websitehttps://www.fortinet.com/ ↗
SECURITY POSTURE
Fortinet's FortiOS has a history of critical vulnerabilities, including remote code execution and authentication bypasses, indicating a need for improved security practices and rigorous testing.
Notable failures
- Hard-coded credentials in configuration backups (CVE-2019-6693)
- Unauthenticated remote code execution (CVE-2024-21762)
- Heap-based buffer overflow (CVE-2022-42475)
- Path traversal vulnerability allowing file download (CVE-2018-13379)
- Improper authentication allowing unauthorized login (CVE-2020-12812)
- Authentication bypass vulnerability (CVE-2024-55591)
Patterns: Remote code execution vulnerabilities; Authentication bypass vulnerabilities; Path traversal vulnerabilities; Lack of integrity checking in file downloads
FAILURE HISTORY · 16
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2025-06-25 | CVE-2019-6693 | critical | Fortinet FortiOS shipped with hard-coded credentials allowing attackers to decrypt sensitive data from configuration backups. |
| 2024-02-09 | CVE-2024-21762 | critical | Fortinet FortiOS suffered a critical out-of-bounds write vulnerability allowing unauthenticated remote code execution. |
| 2022-12-13 | CVE-2022-42475 | critical | Fortinet FortiOS SSL-VPN suffered a heap-based buffer overflow allowing unauthenticated remote code execution. |
| 2021-12-10 | CVE-2021-44168 | high | Fortinet FortiOS allows arbitrary file downloads via an unpatched vulnerability that was actively exploited in the wild. |
| 2026-07-27 | CVE-2025-68686 | high | A bypass vulnerability in FortiOS allows attackers to access sensitive information after initial compromise, circumventing previous patches and requiring immediate action for DIB organizations using the product. |
| 2023-03-14 | CVE-2022-41328 | high | FortiOS RCE flaw exploited in wild |
| 2021-11-03 | CVE-2020-12812 | critical | Fortinet FortiOS allowed unauthorized logins by manipulating username case, bypassing multi-factor authentication (MFA). |
| 2021-11-03 | CVE-2018-13379 | critical | Fortinet's FortiOS allowed unauthenticated attackers to download system files via a path traversal vulnerability, actively exploited in the wild and linked to ransomware activity. |
| 2021-11-03 | CVE-2019-5591 | high | Fortinet FortiOS default configurations allowed unauthenticated attackers on the same subnet to impersonate an LDAP server and intercept sensitive information. |
| 2025-01-14 | CVE-2024-55591 | critical | An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy version 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12 allows a remote attacker to gain super-admin privileges via crafted requests to |
| 2024-03-12 | CVE-2023-42789 | critical | A out-of-bounds write vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2.0 through 7.2.5, FortiOS 7.0.0 through 7.0.12, FortiOS 6.4.0 through 6.4.14, FortiOS 6.2.0 through 6.2.15, FortiProxy 7.4.0, FortiProxy 7.2.0 through 7.2.6, FortiProxy 7.0.0 through 7.0.12, F |
| 2025-01-14 | CVE-2024-48884 | high | A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiManager 7.6.0 through 7.6.1, FortiManager 7.4.1 through 7.4.3, FortiManager Cloud 7.4.1 through 7.4.3, FortiOS 7.6.0, FortiOS 7.4.0 through 7.4.4, FortiOS 7.2.0 through |
| 2024-02-09 | CVE-2024-21762 | critical | CVE-2024-21762: A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 th |
| 2023-06-13 | CVE-2023-27997 | critical | CVE-2023-27997: A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 an |
| 2022-10-18 | CVE-2022-40684 | critical | CVE-2022-40684: An authentication bypass using an alternate path or channel [CWE-288] in Fortine |
| 2020-07-24 | CVE-2020-12812 | critical | CVE-2020-12812: An improper authentication vulnerability in SSL VPN in FortiOS 6.4.0, 6.2.0 to 6 |
DOSSIER SOURCES
- Fortinet Patches FortiOS Authentication Bypass and FortiSandbox Command ... · cyberpress.org
- Fortinet Patches Seven Vulnerabilities Across FortiOS, FortiProxy ... · vpncentral.com
- How to patch FortiGate (FortiOS) — update to the latest secure version ... · www.isitpatched.com
Open questions: What specific remediation steps are being taken to address the recurring vulnerability patterns? · What is the current status of patching and mitigation for the identified CVEs? · What is the root cause analysis process for these vulnerabilities?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-20 04:45:17.194022+00:00