PSIRT Advisories

The following is a list of advisories for issues resolved in Fortinet products. The resolution of such issues is coordinated by the Fortinet Product Security Incident Response Team (PSIRT), a dedicated, global team that manages the receipt, investigation, and public reporting of information about security vulnerabilities and issues related to Fortinet products and services.  

For details of how to raise a PSIRT Issue with Fortinet, please see our PSIRT Policy here.

An insufficient session expiration vulnerability in FortiDeceptor may allow an attacker to reuse the unexpired admin user session...

FortiDeceptor 3.0
Jun 21, 2020 Risk IR Number: FG-IR-20-006
An expression language injection vulnerability in FortiSIEM JBoss RichFaces library may allow a remote attacker to inject expression...

FortiSIEM 5.2
Jun 21, 2020 Risk IR Number: FG-IR-20-041
An improper neutralization of input vulnerability in FortiWLC may allow a remote authenticated attacker to perform a stored cross...

Jun 21, 2020 Risk IR Number: FG-IR-20-016
An improper neutralization of input vulnerability in the Admin Profile of FortiAnalyzer may allow a remote authenticated attacker...

FortiAnalyzer 6.2
Jun 03, 2020 Risk IR Number: FG-IR-20-003
An unquoted service path vulnerability in the FortiSIEM Windows Agent component may allow an attacker to gain elevated privileges...

Jun 03, 2020 Risk IR Number: FG-IR-20-021
Use of a hard-coded cryptographic key to encrypt security sensitive data in configuration in FortiClient for Windows may allow...

FortiClient 6.0, 6.2
Jun 01, 2020 Risk IR Number: FG-IR-19-194
An information exposure vulnerability in FortiOS WEB UI may allow an unauthenticated attacker to gain platform information such...

Jun 01, 2020 Risk IR Number: FG-IR-18-173
An improper neutralization of input vulnerability in the FortiGateCloud login page may allow a remote unauthenticated attacker...

FortiCloud 4.4
May 25, 2020 Risk IR Number: FG-IR-19-306
An Insecure Temporary File (CWE-377) vulnerability in FortiClient for Windows may allow a local user to gain elevated privileges...

FortiClient 6.2, 6.0
May 25, 2020 Risk IR Number: FG-IR-20-040
An improper input validation (CWE-20) vulnerability in FortiAP CLI admin console may allow unauthorized administrators to overwrite...

FortiAP 5.6, 6.0, 6.2
May 25, 2020 Risk IR Number: FG-IR-19-298
TCP stacks that lack RFC 5961 3.2 & 4.2 support (or have it disabled at application level) may allow remote attackers to guess...

FortiAnalyzer 6.2, 6.0 FortiManager 6.2, 6.0
May 20, 2020 Risk IR Number: FG-IR-16-039
An improper authentication vulnerability in FortiMail and FortiVoiceEnterprise may allow a remote unauthenticated attacker to...

Apr 27, 2020 Risk IR Number: FG-IR-20-045
The Bluetooth BR/EDR specification up to and including version 5.1 permits sufficiently low encryption key length and does not...

FortiSwitch 6.0, 6.2
Apr 23, 2020 Risk IR Number: FG-IR-19-224
An improper neutralization of input vulnerability in the dashboard of FortiADC may allow an authenticated attacker to perform...

Apr 06, 2020 Risk IR Number: FG-IR-20-012
An improper authorization vulnerability in FortiADC may allow a remote authenticated user with low privileges to perform certain...

Apr 06, 2020 Risk IR Number: FG-IR-20-013