CVE-2015-3611: Fortinet FortiManager

High severity, CVSS 8.8. EPSS: 5.6% chance of exploitation in the next 30 days.

A Command Injection vulnerability exists in FortiManager 5.2.1 and earlier and FortiManager 5.0.10 and earlier via unspecified vectors, which could let a malicious user run systems commands when executing a report.

Affected products

  • Fortinet FortiManager: from 5.0.0, up to and including 5.0.10; from 5.2.0, up to and including 5.2.1

Published 2020-02-04. Last modified 2026-06-17.