1 actively exploited
FortiGate 5.6.12: known CVEs & fixed releases
9 CVEs affect this build · 1 in CISA KEV (actively exploited) · highest CVSS 9.8 · 2 builds behind the latest 5.6.14 · updated 2026-06-26
Patch path: upgrade to 5.6.13 or 6.0.11 or 6.0.15 or 6.0.16 or 6.0.9 or 6.2.12 or 6.2.13 or 6.2.15 or 6.2.2 or 6.2.5 or 6.4.10 or 6.4.11 or 6.4.12 or 6.4.13 or 6.4.2 or 7.0.10 or 7.0.12 or 7.0.8 or 7.0.9 or 7.2.3 or 7.2.4 or 7.2.5 or 7.2.6 to clear the exploited issues below.
- KEV · exploited CRITICALCVE-2022-42475
Fortinet FortiOS Heap-Based Buffer Overflow Vulnerability
Multiple versions of Fortinet FortiOS SSL-VPN contain a heap-based buffer overflow vulnerability which can allow an unauthenticated, remote attacker to execute arbitrary code or commands via specifically crafted requests.
- CVSS
- 9.8
- EPSS
- 99%
- KEV added
- 2022-12-13
- Published
- 2022-12-13
Fixed in6.0.15,6.0.16,6.2.12,6.4.10,6.4.11,7.0.8,7.0.9,7.2.3NVD ↗CISA ↗fortiguard.com ↗ - CRITICALCVE-2023-25610
CVE-2023-25610
A buffer underwrite ('buffer underflow') vulnerability in the administrative interface of Fortinet FortiOS version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.6, version 6.4.0 through 6.4.11 and version 6.2.12 and below, FortiProxy version 7.2.0 through 7.2.2, version 7.0.0 through 7.0.8, version 2.0.12 and below and FortiOS-6K7K version 7.0.5, version 6.4.0 through 6.4.10 and version 6.2.0 through 6.2.10 and below allows a remote unauthenticated attacker to execute arbitrary code or commands via specifically crafted requests.
- CVSS
- 9.8
- Published
- 2025-03-24
Fixed in6.2.13,6.4.12,7.0.10,7.2.4NVD ↗fortiguard.com ↗ - HIGHCVE-2020-12820
CVE-2020-12820
Under non-default configuration, a stack-based buffer overflow in FortiOS version 6.0.10 and below, version 5.6.12 and below may allow a remote attacker authenticated to the SSL VPN to crash the FortiClient NAC daemon (fcnacd) and potentially execute arbitrary code via requesting a large FortiClient file name. We are not aware of proof of concept code successfully achieving the latter.
- CVSS
- 8.8
- Published
- 2024-12-19
Fixed in5.6.13,6.0.11NVD ↗fortiguard.fortinet.com ↗ - HIGHCVE-2023-29181
CVE-2023-29181
A use of externally-controlled format string in Fortinet FortiOS 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through 6.4.12, 6.2.0 through 6.2.14, 6.0.0 through 6.0.16, FortiProxy 7.2.0 through 7.2.4, 7.0.0 through 7.0.10, 2.0.0 through 2.0.12, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6, 1.0.0 through 1.0.7, FortiPAM 1.0.0 through 1.0.3 allows attacker to execute unauthorized code or commands via specially crafted command.
- CVSS
- 8.8
- Published
- 2024-02-22
Fixed in6.2.15,6.4.13,7.0.12,7.2.5NVD ↗fortiguard.com ↗ - HIGHCVE-2020-12819
CVE-2020-12819
A heap-based buffer overflow vulnerability in the processing of Link Control Protocol messages in FortiGate versions 5.6.12, 6.0.10, 6.2.4 and 6.4.1 and earlier may allow a remote attacker with valid SSL VPN credentials to crash the SSL VPN daemon by sending a large LCP packet, when tunnel mode is enabled. Arbitrary code execution may be theoretically possible, albeit practically very difficult to achieve in this context
- CVSS
- 7.5
- Published
- 2024-12-19
Fixed in5.6.13,6.0.11,6.2.5,6.4.2NVD ↗fortiguard.com ↗ - HIGHCVE-2023-45583
CVE-2023-45583
A use of externally-controlled format string vulnerability in Fortinet FortiOS 7.4.0, FortiOS 7.2.0 through 7.2.5, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiOS 6.2 all versions, FortiOS 6.0.0 through 6.0.16, FortiPAM 1.1.0, FortiPAM 1.0 all versions, FortiProxy 7.2.0 through 7.2.5, FortiProxy 7.0.0 through 7.0.11, FortiProxy 2.0 all versions, FortiProxy 1.2 all versions, FortiProxy 1.1 all versions, FortiProxy 1.0 all versions, FortiSwitchManager 7.2.0 through 7.2.2, FortiSwitchManager 7.0.0 through 7.0.2 allows attacker to execute unauthorized code or commands via specially crafted cli commands and http requests.
- CVSS
- 7.2
- Published
- 2024-05-14
Fixed in7.2.6NVD ↗fortiguard.com ↗ - MEDIUMCVE-2023-33305
CVE-2023-33305
A loop with unreachable exit condition ('infinite loop') in Fortinet FortiOS version 7.2.0 through 7.2.4, FortiOS version 7.0.0 through 7.0.10, FortiOS 6.4 all versions, FortiOS 6.2 all versions, FortiOS 6.0 all versions, FortiProxy version 7.2.0 through 7.2.3, FortiProxy version 7.0.0 through 7.0.9, FortiProxy 2.0 all versions, FortiProxy 1.2 all versions, FortiProxy 1.1 all versions, FortiProxy 1.0 all versions, FortiWeb version 7.2.0 through 7.2.1, FortiWeb version 7.0.0 through 7.0.6, FortiWeb 6.4 all versions, FortiWeb 6.3 all versions allows attacker to perform a denial of service via specially crafted HTTP requests.
- CVSS
- 6.5
- Published
- 2023-06-13
- MEDIUMCVE-2019-15706
CVE-2019-15706
An improper neutralization of input during web page generation in the SSL VPN portal of FortiProxy version 2.0.0, version 1.2.9 and below and FortiOS version 6.2.1 and below, version 6.0.8 and below, version 5.6.12 may allow a remote authenticated attacker to perform a stored cross site scripting attack (XSS).
- CVSS
- 5.4
- Published
- 2025-03-17
Fixed in5.6.13,6.0.9,6.2.2NVD ↗fortiguard.fortinet.com ↗ - MEDIUMCVE-2022-22305
CVE-2022-22305
An improper certificate validation vulnerability [CWE-295] in FortiManager 7.0.1 and below, 6.4.6 and below; FortiAnalyzer 7.0.2 and below, 6.4.7 and below; FortiOS 6.2.x and 6.0.x; FortiSandbox 4.0.x, 3.2.x and 3.1.x may allow a network adjacent and unauthenticated attacker to man-in-the-middle the communication between the listed products and some external peers.
- CVSS
- 4.2
- Published
- 2023-09-01
Stop checking versions by hand
Is your whole fleet exposed, not just this FortiGate?
VulnMonitor reconciles every advisory against your real inventory and ranks what matters by actual exploitation (CISA KEV, EPSS), not raw CVSS. New CVE hits your gear, it is on your queue with the fix attached.
Free to start · no credit card
Other FortiGate versions
- 7.2.0 132 CVEs · 7 KEV
- 7.0.3 130 CVEs · 10 KEV
- 7.0.2 130 CVEs · 10 KEV
- 7.0.1 129 CVEs · 10 KEV
- 7.2.2 128 CVEs · 7 KEV
- 7.2.1 128 CVEs · 7 KEV
- 7.0.5 128 CVEs · 9 KEV
- 7.0.4 128 CVEs · 9 KEV
- 7.0.0 126 CVEs · 10 KEV
- 7.0.10 111 CVEs · 7 KEV
- 6.4.8 104 CVEs · 4 KEV
- 6.4.6 102 CVEs · 4 KEV
- 6.4.10 101 CVEs · 3 KEV
- 6.4.1 101 CVEs · 4 KEV