• Filter by Date
  • Filter by Risk
  • Filter by Affected Product

PSIRT Advisories

The following is a list of advisories for issues resolved in Fortinet products. The resolution of such issues is coordinated by the Fortinet Product Security Incident Response Team (PSIRT), a dedicated, global team that manages the receipt, investigation, and public reporting of information about security vulnerabilities and issues related to Fortinet products and services.  

For details of how to raise a PSIRT Issue with Fortinet, please see our PSIRT Policy here.

Multiple padding Oracle vulnerabilities (Zombie POODLE, GOLDENDOODLE, OpenSSL 0-length) in the CBC padding implementation of FortiOS...

Feb 25, 2020 Risk IR Number: FG-IR-19-145
An improper input validation vulnerability in FortiOS admin webUI may allow an attacker to perform an URL redirect attack via...

FortiOS 5.4, 5.6, 6.0, 6.2
Feb 18, 2020 Risk IR Number: FG-IR-19-179
An Insufficient Verification of Data Authenticity vulnerability in FortiManager may allow an unauthenticated attacker to perform...

FortiManager 5.6, 6.0, 6.2
Feb 13, 2020 Risk IR Number: FG-IR-19-191
FortiGate models which do not contain and embedded TRNG may suffer from insufficient entropy ("seed") in the CTR DRBG random data...

Feb 13, 2020 Risk IR Number: FG-IR-19-186
A system command injection vulnerability in the FortiAP CLI admin console may allow unauthorized administrators to run arbitrary...

FortiAP 5.6, 6.0, 6.2
Feb 10, 2020 Risk IR Number: FG-IR-19-209
An Uncontrolled Resource Consumption vulnerability in multiple products may allow an attacker to cause web service portal denial...

FortiAnalyzer 5.6, 6.0, 6.2 FortiAP 6.0, 6.2 FortiManager 5.6, 6.0, 6.2 FortiOS 6.0, 6.2 FortiSwitch 6.0, 6.2
Feb 03, 2020 Risk IR Number: FG-IR-19-013