PSIRT Advisories
The following is a list of advisories for issues resolved in Fortinet products. The resolution of such issues is coordinated by the Fortinet Product Security Incident Response Team (PSIRT), a dedicated, global team that manages the receipt, investigation, and public reporting of information about security vulnerabilities and issues related to Fortinet products and services.
For details of how to raise a PSIRT Issue with Fortinet, please see our PSIRT Policy here.
FortiGate may fail to record traffic destined to Fortinet owned IP addresses i.e. traffic destined to the following subnets: 173.243.128.0/20,...
A heap-based buffer overflow vulnerability in the processing of Link Control Protocol messages in FortiOS may allow a remote...
Under non-default configuration, a stack-based buffer overflow in FortiGate may allow a remote attacker authenticated to the SSL...
An improper neutralization of input vulnerability in FortiNAC may allow a remote authenticated attacker to perform a stored cross...
An improper neutralization of input vulnerability in FortiAnalyzer and FortiTester may allow a remote authenticated attacker to...
An information exposure vulnerability in FortiWeb CLI may allow an authenticated user to view sensitive information being logged...
An improper neutralization of script-related HTML tags in a web page in FortiManager and FortiAnalyzer may allow an attacker to...
An improper neutralization of input during web page generation in the SSL VPN portal of FortiOS may allow a remote authenticated...
On June 16, 2020, cybersecurity researchers from JSOF published a set of 19 vulnerabilities, dubbed Ripple20 that are impacting...
An improper authentication vulnerability in SSL VPN in FortiOS may result in a user being able to log in successfully without...
Use of a hard-coded cryptographic key to encrypt password data in CLI configuration in FortiOS, FortiManager and FortiAnalyzer...
FortiAnalyzer
6.0, 6.2
FortiManager
6.0, 6.2
FortiOS
6.0, 6.2
Jun 30, 2020
Risk An improper access control vulnerability in the admin SSH console of multiple products may allow an authenticated user to access...
FortiAnalyzer
6.0, 6.2
FortiAP
6.0, 6.2
FortiManager
6.0, 6.2
Jun 26, 2020
Risk An OS command injection vulnerability in FortiManager and FortiAnalyzer may allow a privileged system administrator to run OS...
A cleartext storage in a file or on disk (CWE-313) vulnerability in FortiOS SSL VPN may allow an attacker to retrieve a logged-in...
An insufficient control of network message volume (CWE-406) vulnerability in FortiAnalyzer may allow an unauthenticated remote...