PSIRT Advisories
The following is a list of advisories for issues resolved in Fortinet products. The resolution of such issues is coordinated by the Fortinet Product Security Incident Response Team (PSIRT), a dedicated, global team that manages the receipt, investigation, and public reporting of information about security vulnerabilities and issues related to Fortinet products and services.
For details of how to raise a PSIRT Issue with Fortinet, please see our PSIRT Policy here.
A Cross-Site Request Forgery (CSRF) vulnerability in the user interface of FortiSIEM could allow a remote, unauthenticated attacker...
An improper neutralization of input vulnerability in FortiManager GUI may allow an authenticated attacker to perform an XSS (Cross...
An information exposure vulnerability in FortiWeb CLI may allow an authenticated user to view sensitive information being logged...
Multiple unsafe search path vulnerabilities in FortiClient online installers may allow an attacker with control over the directory...
An improper neutralization of input vulnerability in the FortiADC may allow an attacker to execute a stored Cross Site Scripting...
An improper neutralization of input vulnerability in FortiWeb may allow a remote authenticated attacker to perform a stored cross...
An unquoted service path vulnerability in the FortiClient FortiTray component may allow an attacker to gain elevated privileges...
Two authorization bypass through user-controlled key vulnerabilities in the FortiPresence administration interface may allow an...
An improper neutralization of input vulnerability in the URL Description of FortiIsolator may allow a remote authenticated attacker...
An improper neutralization of input vulnerability in the Anomaly Detection interface of FortiWeb may allow a remote unauthenticated...
Multiple padding Oracle vulnerabilities (Zombie POODLE, GOLDENDOODLE, OpenSSL 0-length) in the CBC padding implementation of FortiOS...
An improper input validation vulnerability in FortiOS admin webUI may allow an attacker to perform an URL redirect attack via...
An Insufficient Verification of Data Authenticity vulnerability in FortiManager may allow an unauthenticated attacker to perform...
FortiGate models which do not contain and embedded TRNG may suffer from insufficient entropy ("seed") in the CTR DRBG random data...
A system command injection vulnerability in the FortiAP CLI admin console may allow unauthorized administrators to run arbitrary...