PSIRT Advisories

The following is a list of advisories for issues resolved in Fortinet products. The resolution of such issues is coordinated by the Fortinet Product Security Incident Response Team (PSIRT), a dedicated, global team that manages the receipt, investigation, and public reporting of information about security vulnerabilities and issues related to Fortinet products and services.  

For details of how to raise a PSIRT Issue with Fortinet, please see our PSIRT Policy here.

An improper neutralization of input during web page generation in FortiWeb GUI interface may allow an unauthenticated, remote...

Feb 03, 2021 Risk IR Number: FG-IR-20-122
A buffer overflow vulnerability in the SSL VPN portal of FortiProxy may allow an unauthenticated, remote attacker to perform a...

Feb 03, 2021 Risk IR Number: FG-IR-20-232
A heap buffer overflow vulnerability in the FortiProxy SSL VPN web portal may cause the SSL VPN web service termination for logged...

Feb 03, 2021 Risk IR Number: FG-IR-20-229
An insufficient session expiration vulnerability in FortiIsolator may allow an attacker to reuse the unexpired admin user session...

FortiIsolator 2.0
Jan 21, 2021 Risk IR Number: FG-IR-20-011
An exposure of sensitive information to an unauthorized actor vulnerability in FortiGate may allow a remote authenticated attacker...

Jan 04, 2021 Risk IR Number: FG-IR-20-103
A blind SQL injection in the user interface of FortiWeb may allow an unauthenticated, remote attacker to execute arbitrary SQL...

Jan 04, 2021 Risk IR Number: FG-IR-20-124
A stack-based buffer overflow vulnerability in FortiWeb may allow an unauthenticated, remote attacker to overwrite the content...

Jan 04, 2021 Risk IR Number: FG-IR-20-125
A stack-based buffer overflow vulnerability in FortiWeb may allow a remote, unauthenticated attacker to crash the httpd daemon...

Jan 04, 2021 Risk IR Number: FG-IR-20-126
A format string vulnerability in FortiWeb may allow an authenticated, remote attacker to read the content of memory and retrieve...

Jan 04, 2021 Risk IR Number: FG-IR-20-123
An OS command injection vulnerability in FortiDeceptor may allow a remote authenticated attacker to execute arbitrary commands...

Jan 04, 2021 Risk IR Number: FG-IR-20-177
FortiClient and FortiOS AV engines may not immediately detect certain types of malformed or non-standard RAR archives, potentially...

Dec 01, 2020 Risk IR Number: FG-IR-20-037
During the RSA conference of February 26th 2020, researchers Štefan Svorencík and Robert Lipovsky disclosed a vulnerability in...

Dec 01, 2020 Risk IR Number: FG-IR-20-035
An improper neutralization of input vulnerability in the FortiGate may allow a remote attacker to perform a stored cross site...

FortiOS 6.2, 6.4
Dec 01, 2020 Risk IR Number: FG-IR-20-068
A cleartext storage of sensitive information in GUI in FortiADC may allow a remote authenticated attacker to retrieve some sensitive...

Nov 03, 2020 Risk IR Number: FG-IR-20-044
An exposure of sensitive information to an unauthorized actor vulnerability in FortiMail may allow a remote, unauthenticated attacker...

Nov 03, 2020 Risk IR Number: FG-IR-20-105