📦 Fortivoice

by Fortinet

🔍 What is Fortivoice?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-64156

HIGH CVSS 7.2 Dec 9, 2025

This SQL injection vulnerability in Fortinet FortiVoice allows authenticated privileged attackers to execute unauthorized SQL commands via crafted requests. Affected versions include FortiVoice 7.2.0-...

CVE-2025-58692

HIGH CVSS 8.8 Nov 18, 2025

This SQL injection vulnerability in Fortinet FortiVoice allows authenticated attackers to execute arbitrary SQL commands via crafted HTTP/HTTPS requests. Affected systems include FortiVoice versions 7...

CVE-2025-47856

HIGH CVSS 7.2 Oct 14, 2025

Two OS command injection vulnerabilities in Fortinet FortiVoice allow privileged attackers to execute arbitrary commands via crafted HTTP/HTTPS or CLI requests. This affects FortiVoice versions 7.2.0,...

CVE-2023-37931

HIGH CVSS 8.8 Jan 14, 2025

This SQL injection vulnerability in FortiVoice Enterprise allows authenticated attackers to execute arbitrary SQL commands via crafted HTTP/HTTPS requests. Affected systems include FortiVoice Enterpri...

CVE-2023-40720

HIGH CVSS 7.1 May 14, 2024

This vulnerability allows authenticated attackers to bypass authorization controls and access other users' SIP configuration data on FortiVoiceEnterprise systems. Attackers can exploit this by craftin...

CVE-2022-27488

HIGH CVSS 8.3 Dec 13, 2023

This CSRF vulnerability allows remote unauthenticated attackers to trick authenticated administrators into executing malicious CLI commands via crafted GET requests. Affected systems include multiple ...

CVE-2025-58693

MEDIUM CVSS 6.5 Jan 13, 2026

This path traversal vulnerability in Fortinet FortiVoice allows privileged attackers to delete arbitrary files from the underlying filesystem via crafted HTTP/HTTPS requests. Affected systems include ...

CVE-2021-24008

MEDIUM CVSS 5.3 Mar 28, 2025

This vulnerability allows remote unauthenticated attackers to obtain sensitive software version information from multiple Fortinet products by reading a JavaScript file. This affects FortiDDoS, FortiD...

CVE-2022-23439

MEDIUM CVSS 4.7 Jan 22, 2025

This vulnerability allows attackers to poison web caches by sending crafted HTTP requests with malicious Host headers to Fortinet devices. Attackers can redirect users to arbitrary malicious servers, ...

CVE-2024-48885

MEDIUM CVSS 5.3 Jan 16, 2025

This path traversal vulnerability (CWE-22) in multiple Fortinet products allows attackers to escalate privileges by sending specially crafted packets. Affected systems include FortiRecorder, FortiVoic...

CVE-2024-40587

MEDIUM CVSS 6.7 Jan 14, 2025

This CVE describes an OS command injection vulnerability in Fortinet FortiVoice phone systems. Authenticated privileged attackers can execute arbitrary commands on affected devices via crafted CLI req...