PSIRT Advisories

Monthly PSIRT Advisories

The following is a list of advisories for issues resolved in Fortinet products. The resolution of such issues is coordinated by the Fortinet Product Security Incident Response Team (PSIRT), a dedicated, global team that manages the receipt, investigation, and public reporting of information about security vulnerabilities and issues related to Fortinet products and services.  

For details of how to raise a PSIRT Issue with Fortinet, please see our PSIRT Policy here.

FortiGate may fail to record traffic destined to Fortinet owned IP addresses i.e. traffic destined to the following subnet...

Sep 24, 2020 Risk IR Number: FG-IR-20-033 CVE-2020-12818 (disputed)
A heap-based buffer overflow vulnerability in the processing of Link Control Protocol messages in FortiOS may allow a rem...

FortiOS 6.4.1, 6.4.0, 6.2.4, 6.2.3, 6.2.2, 6.2.1, 6.2.0, 6.0.9, 6.0.8, 6.0.7, 6.0.6, 6.0.5, 6.0.4, 6.0.3, 6.0.2, 6.0.10, 6.0.1, 6.0.0, 5.6.9, 5.6.8, 5.6.7, 5.6.6, 5.6.5, 5.6.4, 5.6.3, 5.6.2, 5.6.12, 5.6.11, 5.6.10, 5.6.1, 5.6.0
Sep 24, 2020 Risk IR Number: FG-IR-20-082 CVE-2020-12819
Under non-default configuration, a stack-based buffer overflow in FortiGate may allow a remote attacker authenticated to t...

FortiOS 6.0.9, 6.0.8, 6.0.7, 6.0.6, 6.0.5, 6.0.4, 6.0.3, 6.0.2, 6.0.10, 6.0.1, 6.0.0, 5.6.9, 5.6.8, 5.6.7, 5.6.6, 5.6.5, 5.6.4, 5.6.3, 5.6.2, 5.6.12, 5.6.11, 5.6.10, 5.6.1, 5.6.0
Sep 24, 2020 Risk IR Number: FG-IR-20-083 CVE-2020-12820
An improper neutralization of input vulnerability in FortiNAC may allow a remote authenticated attacker to perform a store...

FortiNAC 8.6.2
Sep 23, 2020 Risk IR Number: FG-IR-20-002 CVE-2020-12816
An improper neutralization of input vulnerability in FortiAnalyzer and FortiTester may allow a remote authenticated attack...

Sep 21, 2020 Risk IR Number: FG-IR-20-054 CVE-2020-12815
An information exposure vulnerability in FortiWeb CLI may allow an authenticated user to view sensitive information being ...

Sep 18, 2020 Risk IR Number: FG-IR-19-269 CVE-2019-16157
An improper neutralization of script-related HTML tags in a web page in FortiManager and FortiAnalyzer may allow an attack...

FortiManager 6.2.5, 6.2.3, 6.2.2, 6.2.1, 6.2.0 FortiAnalyzer 6.2.8, 6.2.7
Sep 18, 2020 Risk IR Number: FG-IR-20-005 CVE-2020-12811
An improper neutralization of input during web page generation in the SSL VPN portal of FortiOS may allow a remote authen...

Sep 16, 2020 Risk IR Number: FG-IR-19-223 CVE-2019-15706