PSIRT Advisories

Monthly PSIRT Advisories

The following is a list of advisories for issues resolved in Fortinet products. The resolution of such issues is coordinated by the Fortinet Product Security Incident Response Team (PSIRT), a dedicated, global team that manages the receipt, investigation, and public reporting of information about security vulnerabilities and issues related to Fortinet products and services.  

For details of how to raise a PSIRT Issue with Fortinet, please see our PSIRT Policy here.

The Bluetooth BR/EDR specification up to and including version 5.1 permits sufficiently low encryption key length and does...

FortiSwitch 6.0, 6.2
Apr 23, 2020 Risk IR Number: FG-IR-19-224
An improper neutralization of input vulnerability in the dashboard of FortiADC may allow an authenticated attacker to perf...

Apr 06, 2020 Risk IR Number: FG-IR-20-012
An improper authorization vulnerability in FortiADC may allow a remote authenticated user with low privileges to perform c...

Apr 06, 2020 Risk IR Number: FG-IR-20-013
A Cross-Site Request Forgery (CSRF) vulnerability in the user interface of FortiSIEM could allow a remote, unauthenticated...

Mar 12, 2020 Risk IR Number: FG-IR-19-240
An improper neutralization of input vulnerability in FortiManager GUI may allow an authenticated attacker to perform an XS...

Mar 11, 2020 Risk IR Number: FG-IR-19-271
An information exposure vulnerability in FortiWeb CLI may allow an authenticated user to view sensitive information being ...

Mar 11, 2020 Risk IR Number: FG-IR-19-269
Multiple unsafe search path vulnerabilities in FortiClient online installers may allow an attacker with control over the d...

Mar 09, 2020 Risk IR Number: FG-IR-19-060
An improper neutralization of input vulnerability in the FortiADC may allow an attacker to execute a stored Cross Site Scr...

FortiADC 5.3
Mar 09, 2020 Risk IR Number: FG-IR-19-220
An improper neutralization of input vulnerability in FortiWeb may allow a remote authenticated attacker to perform a store...

FortiWeb 6.2, 6.3
Mar 09, 2020 Risk IR Number: FG-IR-20-001
An unquoted service path vulnerability in the FortiClient FortiTray component may allow an attacker to gain elevated privi...

FortiClient 6.2
Mar 09, 2020 Risk IR Number: FG-IR-19-281
Two authorization bypass through user-controlled key vulnerabilities in the FortiPresence administration interface may all...

Mar 09, 2020 Risk IR Number: FG-IR-19-258
An improper neutralization of input vulnerability in the URL Description of FortiIsolator may allow a remote authenticated...

FortiIsolator 1.2
Mar 09, 2020 Risk IR Number: FG-IR-19-270
An improper neutralization of input vulnerability in the Anomaly Detection interface of FortiWeb may allow a remote unauth...

FortiWeb
Mar 09, 2020 Risk IR Number: FG-IR-19-265
Multiple padding Oracle vulnerabilities (Zombie POODLE, GOLDENDOODLE, OpenSSL 0-length) in the CBC padding implementation ...

Feb 25, 2020 Risk IR Number: FG-IR-19-145
An improper input validation vulnerability in FortiOS admin webUI may allow an attacker to perform an URL redirect attack ...

FortiOS 5.4, 5.6, 6.0, 6.2
Feb 18, 2020 Risk IR Number: FG-IR-19-179