PSIRT Advisories

Monthly PSIRT Advisories

The following is a list of advisories for issues resolved in Fortinet products. The resolution of such issues is coordinated by the Fortinet Product Security Incident Response Team (PSIRT), a dedicated, global team that manages the receipt, investigation, and public reporting of information about security vulnerabilities and issues related to Fortinet products and services.  

For details of how to raise a PSIRT Issue with Fortinet, please see our PSIRT Policy here.

A cleartext storage of sensitive information vulnerability in FortiOS command line interface may allow an authenticated at...

FortiOS 6.2.4, 6.2.3, 6.2.2, 6.2.1, 6.2.0, 6.0.9, 6.0.8, 6.0.7, 6.0.6, 6.0.5, 6.0.4, 6.0.3, 6.0.2, 6.0.11, 6.0.10, 6.0.1, 6.0.0
Oct 19, 2020 Risk IR Number: FG-IR-20-009 CVE-2020-6648
An execution with unnecessary privileges vulnerability in the VCM engine of FortiClient for Linux may allow local users to...

FortiClientLinux 6.4.0, 6.2.7, 6.2.6, 6.2.4, 6.2.3, 6.2.2, 6.2.1, 6.2.0, 6.0.8, 6.0.6, 6.0.5, 6.0.4, 6.0.3, 6.0.2, 6.0.1, 6.0.0
Oct 19, 2020 Risk IR Number: FG-IR-20-110 CVE-2020-15934
The Apache project released an advisory on August 7th 2020, which describes the following vulnerabilities:1) CVE-2020-9490...

Oct 05, 2020 Risk IR Number: FG-IR-20-128 CVE-2020-9490
A Stack-based Buffer Overflow vulnerability in the HTTPD daemon of FortiOS may allow an authenticated remote attacker to c...

FortiOS 6.2.2, 6.0.9, 6.0.10
Oct 01, 2020 Risk IR Number: FG-IR-19-248 CVE-2019-17656