Fortiproxy

Vendor:

First CVE: May 29, 2019 · Active for 7 years

125
Total CVEs
More Total CVEs than 99% of tracked products
15.6
Avg CVEs / Year
Higher CVE frequency than 98% of tracked products
6.8
Avg CVSS
Higher Avg CVSS than 36% of tracked products
9.6%
KEV Rate
Higher KEV Rate than 97% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Fortiproxy over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 29, 2019
7 years ago
Most Recent CVE
Jul 14, 2026
11 days ago

CVE Severity & Scoring

Fortiproxy125 CVEs
All CVEs352,427 CVEs
LowMediumHighCritical
Attack Vector
Local20 (16.0%)
Network101 (80.8%)
Unknown0 (0.0%)
Physical1 (0.8%)
Adjacent Network3 (2.4%)
Attack Complexity
Low113 (90.4%)
High12 (9.6%)
Unknown0 (0.0%)
User Interaction
None102 (81.6%)
Unknown0 (0.0%)
Required23 (18.4%)
Privileges Required
Low40 (32.0%)
High29 (23.2%)
None56 (44.8%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (125 CVEs).

125 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6, FortiProxy version 7.2.0 and version
Oct 18, 20229.899YESYES
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.3 to 5.6.7 and 5.4.6 to 5.4.12 and FortiProxy 2.0.0, 1.2.0
Jun 4, 20199.899YESYES
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy version 7.0.0 through 7.0.19 and 7
Jan 14, 20259.898YESYES
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0 through 6.4.10, 6.2.0 through 6.2.11, 6.0.15 and earlier an
Jan 2, 20239.898YESYES
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.5, FortiAnalyzer 7.4.0 through 7.4.9,
Jan 27, 20269.896YESNO
A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, 6.0.0 through 6.0.17,
Feb 9, 20249.895YESNO
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, version 6.4.12 and below, version 6.0.16 and below and FortiProxy
Jun 13, 20239.895YESNO
An Improper Authorization vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.8 and 5.4.1 to 5.4.10 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 to 1.1.6, 1.0.0 to 1.0.7
Jun 4, 20197.595YESYES
A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 t
Dec 9, 20259.894YESNO
A use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, FortiProxy versions 7.4.0 through 7.4.2, 7
Feb 15, 20249.892YESNO

Exploit Exposure

Signals from CVEs in this product scope (125 CVEs).

CISA KEV
12 CVEs
9.6% of CVEs· 97th percentile
Metasploit
2 CVEs
1.6% of CVEs· 96th percentile
Nuclei
5 CVEs
4.0% of CVEs· 97th percentile
ExploitDB
3 CVEs
2.4% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (125 CVEs).

Media Mentions

Signals from CVEs in this product scope (125 CVEs).

Top CNAs Publishing CVEs For Fortiproxy

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
7.6.037.20.7%00
7.4.126.90.6%00
7.4.057.71.2%00
7.2.314.30.9%00
7.2.246.81.1%00
7.2.1136.20.6%00
7.2.0156.57.3%11
7.0.127.30.3%00
7.0.046.60.7%00
2.0.127.00.7%00
2.0.0116.925.8%33
1.2.018.80.9%00
1.1.616.50.8%00
1.1.516.50.8%00
1.1.018.80.9%00
1.0.018.80.9%00