PSIRT Advisories
Monthly PSIRT Advisories
- 2023: May , Apr , Mar , Feb , Jan
- 2022: Dec , Nov , Sep , Aug , Jul , Jun , May , Apr , Mar , Feb
- 2021: Dec , Nov , Oct , Sep , Aug , Jul , Jun , May , Apr , Mar , Feb , Jan
- 2020: Dec
The following is a list of advisories for issues resolved in Fortinet products. The resolution of such issues is coordinated by the Fortinet Product Security Incident Response Team (PSIRT), a dedicated, global team that manages the receipt, investigation, and public reporting of information about security vulnerabilities and issues related to Fortinet products and services.
For details of how to raise a PSIRT Issue with Fortinet, please see our PSIRT Policy here.
An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in the command line interpret...
FortiAuthenticator
6.3.0, 6.2.2, 6.2.1, 6.2.0, 6.1.3, 6.1.2, 6.1.1, 6.1.0, 6.0.8, 6.0.7, 6.0.6, 6.0.5, 6.0.4, 6.0.3, 6.0.2, 6.0.1, 6.0.0, 5.5.0, 5.4.1, 5.4.0, 5.3.1, 5.3.0, 5.2.2, 5.2.1, 5.2.0, 5.1.2, 5.1.1, 5.1.0, 5.0.0
Sep 07, 2021
Severity
An OS command injection (CWE-78)Â vulnerability in FortiClient for Linux may allow an unauthenticated, network-adjacent at...
An improper authentication vulnerability [CWE-287] in FortiManager may allow a standard user to assign or un-assign a glob...
An improper neutralization of formula elements vulnerability (CWE 1236) in FortiManager may allow a local authenticated pr...
Sep 07, 2021
Severity
Low
IR Number: FG-IR-20-190
CVE-2021-24016
An exposure of sensitive information to an unauthorized actor vulnerability in FortiOS CLI may allow a local and authenti...
Sep 07, 2021
Severity
Medium
IR Number: FG-IR-20-243
CVE-2021-32600
An improper neutralization of input during web page generation vulnerability [CWE-79]Â in FortiOSÂ may allow a remote unau...
FortiOS
6.4.1, 6.4.0, 6.2.9, 6.2.8, 6.2.7, 6.2.6, 6.2.5, 6.2.4, 6.2.3, 6.2.2, 6.2.1, 6.2.0
Sep 07, 2021
Severity
A debug functionality in FortiGate may allow a privileged user to execute unauthorized code or commands via specific
chai...
Sep 07, 2021
Severity
Medium
IR Number: FG-IR-21-091
CVE-2021-36169
A cleartext storage in a file or on disk (CWE-313) vulnerability in FortiOS SSL VPN may allow an attacker to retrieve a lo...
FortiOS
6.2.2, 6.2.1, 6.2.0, 6.0.9, 6.0.8, 6.0.7, 6.0.6, 6.0.5, 6.0.4, 6.0.3, 6.0.2, 6.0.1, 6.0.0, 5.6.9, 5.6.8, 5.6.7, 5.6.6, 5.6.5, 5.6.4, 5.6.3, 5.6.2, 5.6.13, 5.6.12, 5.6.11, 5.6.10, 5.6.1, 5.6.0, 5.4.9, 5.4.8, 5.4.7, 5.4.6, 5.4.5, 5.4.4, 5.4.3, 5.4.2, 5.4.13, 5.4.12, 5.4.11, 5.4.10, 5.4.1, 5.4.0, 5.2.9, 5.2.8, 5.2.7, 5.2.6, 5.2.5, 5.2.4, 5.2.3, 5.2.2, 5.2.15, 5.2.14, 5.2.13, 5.2.12, 5.2.11, 5.2.10, 5.2.1, 5.2.0
Sep 07, 2021
Severity
An insufficient session expiration vulnerability [CWE-613] in FortiSandbox may allow an attacker to reuse the unexpired ad...
Multiple stack-based buffer overflow vulnerabilities in FortiWeb CLI interface may allow an authenticated attacker to exec...
FortiWeb
6.3.9, 6.3.8, 6.3.7, 6.3.6, 6.3.5, 6.3.4, 6.3.3, 6.3.2, 6.3.14, 6.3.13, 6.3.12, 6.3.11, 6.3.10, 6.3.1, 6.3.0, 6.2.4, 6.2.3, 6.2.2, 6.2.1, 6.2.0
Sep 07, 2021
Severity
Multiple improper neutralization of special elements vulnerabilities [CWE-89] used in a command in FortiWeb may allow an a...
FortiWeb
6.3.9, 6.3.8, 6.3.7, 6.3.6, 6.3.5, 6.3.4, 6.3.3, 6.3.2, 6.3.13, 6.3.12, 6.3.11, 6.3.10, 6.3.1, 6.3.0, 6.2.4
Sep 07, 2021
Severity
An improper input validation vulnerability in the sniffer interface of FortiSandbox may allow an authenticated attacker to...