📦 Fortipam

by Fortinet

🔍 What is Fortipam?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-23113

CRITICAL CVSS 9.8 Feb 15, 2024

This critical vulnerability allows remote attackers to execute arbitrary code or commands on affected Fortinet devices by sending specially crafted packets that exploit a format string vulnerability. ...

CVE-2025-57740

HIGH CVSS 7.5 Oct 14, 2025

A heap-based buffer overflow vulnerability in Fortinet's FortiOS, FortiPAM, and FortiProxy allows authenticated users to execute arbitrary code via crafted RDP bookmark connection requests. This affec...

CVE-2025-49201

HIGH CVSS 8.1 Oct 14, 2025

A weak authentication vulnerability in Fortinet FortiPAM and FortiSwitchManager allows attackers to execute unauthorized code or commands via specially crafted HTTP requests. This affects multiple ver...

CVE-2024-26009

HIGH CVSS 8.1 Aug 12, 2025

This CVE describes an authentication bypass vulnerability in Fortinet FortiOS, FortiProxy, and FortiPAM products that allows unauthenticated attackers to take control of managed devices. Attackers can...

CVE-2024-45324

HIGH CVSS 7.2 Mar 11, 2025

A format string vulnerability in multiple Fortinet products allows privileged attackers to execute arbitrary code via crafted HTTP/HTTPS requests. This affects FortiOS, FortiProxy, FortiPAM, FortiSRA,...

CVE-2024-47570

MEDIUM CVSS 6.6 Dec 9, 2025

This vulnerability allows read-only administrators to retrieve API tokens of other administrators by examining REST API logs when REST API logging is enabled. This affects Fortinet's FortiOS, FortiPro...

CVE-2025-61713

MEDIUM CVSS 4.2 Nov 18, 2025

This vulnerability allows authenticated administrators with CLI read-write privileges in FortiPAM to obtain other administrators' credentials through diagnose commands. It affects all versions of Fort...

CVE-2024-26008

MEDIUM CVSS 5.3 Oct 14, 2025

This vulnerability allows an unauthenticated attacker to repeatedly reset the fgfm connection via crafted SSL encrypted TCP requests, causing denial of service. Affected systems include FortiOS, Forti...

CVE-2025-25248

MEDIUM CVSS 5.3 Aug 12, 2025

An integer overflow vulnerability in Fortinet SSL-VPN RDP/VNC bookmarks allows authenticated users to craft requests that may crash the SSL-VPN service, causing denial of service. This affects FortiOS...

CVE-2023-45584

MEDIUM CVSS 6.6 Aug 12, 2025

A double free vulnerability in multiple Fortinet products allows privileged attackers to execute arbitrary code or commands via crafted HTTP/HTTPS requests. This affects FortiOS, FortiPAM, and FortiPr...

CVE-2024-26011

MEDIUM CVSS 5.3 Nov 12, 2024

This vulnerability allows unauthenticated attackers to execute arbitrary code or commands on affected Fortinet devices by sending specially crafted packets. It affects multiple Fortinet products inclu...

CVE-2023-45583

MEDIUM CVSS 6.7 May 14, 2024

This CVE describes a format string vulnerability in multiple Fortinet products that allows attackers to execute arbitrary code or commands. The vulnerability affects FortiProxy, FortiPAM, FortiOS, and...

CVE-2025-54821

LOW CVSS 1.9 Nov 18, 2025

This CVE describes an improper privilege management vulnerability in multiple Fortinet products that allows authenticated administrators to bypass trusted host policies via crafted CLI commands. The v...