PSIRT Advisories

Monthly PSIRT Advisories

The following is a list of advisories for issues resolved in Fortinet products. The resolution of such issues is coordinated by the Fortinet Product Security Incident Response Team (PSIRT), a dedicated, global team that manages the receipt, investigation, and public reporting of information about security vulnerabilities and issues related to Fortinet products and services.  

For details of how to raise a PSIRT Issue with Fortinet, please see our PSIRT Policy here.

Use of a hard-coded cryptographic key to encrypt password data in CLI configuration in FortiOS, FortiManager and FortiAnal...

FortiAnalyzer 6.0, 6.2 FortiManager 6.0, 6.2 FortiOS 6.0, 6.2
Jun 30, 2020 Risk IR Number: FG-IR-19-007
An improper access control vulnerability in the admin SSH console of multiple products may allow an authenticated user to ...

FortiAnalyzer 6.0, 6.2 FortiAP 6.0, 6.2 FortiManager 6.0, 6.2
Jun 26, 2020 Risk IR Number: FG-IR-19-292
An OS command injection vulnerability in FortiManager and FortiAnalyzer may allow a privileged system administrator to run...

FortiAnalyzer 6.0, 6.2 FortiManager 6.0, 6.2
Jun 26, 2020 Risk IR Number: FG-IR-19-294
An improper neutralization of input vulnerability in the Admin Profile of FortiAnalyzer may allow a remote authenticated a...

FortiAnalyzer 6.2
Jun 03, 2020 Risk IR Number: FG-IR-20-003
TCP stacks that lack RFC 5961 3.2 & 4.2 support (or have it disabled at application level) may allow remote attackers to g...

FortiAnalyzer 6.2, 6.0 FortiManager 6.2, 6.0
May 20, 2020 Risk IR Number: FG-IR-16-039
An Uncontrolled Resource Consumption vulnerability in multiple products may allow an attacker to cause web service portal ...

FortiAnalyzer 5.6, 6.0, 6.2 FortiAP 6.0, 6.2 FortiManager 5.6, 6.0, 6.2 FortiOS 6.0, 6.2 FortiSwitch 6.0, 6.2
Feb 03, 2020 Risk IR Number: FG-IR-19-013
A collection of AMD vulnerabilities known as "Ryzenfall, Fallout, Chimera, Masterkey" has been released. Attackers in poss...

FortiAnalyzer FortiAP 5.2, 5.6 FortiOS 5.2, 4.2 FortiSwitch
Apr 13, 2018 Risk IR Number: FG-IR-18-046