PSIRT Advisories

The following is a list of advisories for issues resolved in Fortinet products. The resolution of such issues is coordinated by the Fortinet Product Security Incident Response Team (PSIRT), a dedicated, global team that manages the receipt, investigation, and public reporting of information about security vulnerabilities and issues related to Fortinet products and services.  

For details of how to raise a PSIRT Issue with Fortinet, please see our PSIRT Policy here.

An improper neutralization of input vulnerability in the FortiGate may allow a remote attacker to perform a stored cross site...

FortiOS 6.2, 6.4
Dec 01, 2020 Risk IR Number: FG-IR-20-068
Use of a hard-coded cryptographic key to encrypt password data in CLI configuration in FortiOS, FortiManager and FortiAnalyzer...

FortiAnalyzer 6.0, 6.2 FortiManager 6.0, 6.2 FortiOS 6.0, 6.2
Jun 30, 2020 Risk IR Number: FG-IR-19-007
An Uncontrolled Resource Consumption vulnerability in multiple products may allow an attacker to cause web service portal denial...

FortiAnalyzer 5.6, 6.0, 6.2 FortiAP 6.0, 6.2 FortiManager 5.6, 6.0, 6.2 FortiOS 6.0, 6.2 FortiSwitch 6.0, 6.2
Feb 03, 2020 Risk IR Number: FG-IR-19-013
A collection of AMD vulnerabilities known as "Ryzenfall, Fallout, Chimera, Masterkey" has been released. Attackers in possession...

FortiAnalyzer FortiAP 5.2, 5.6 FortiOS 5.2, 4.2 FortiSwitch
Apr 13, 2018 Risk IR Number: FG-IR-18-046
An improper authentication vulnerability in SSL VPN in FortiOS may result in a user being able to log in successfully without...

FortiOS 6.0, 6.2, 6.4
Jul 13, 2020 Risk IR Number: FG-IR-19-283
An improper input validation vulnerability in FortiOS admin webUI may allow an attacker to perform an URL redirect attack via...

FortiOS 5.4, 5.6, 6.0, 6.2
Feb 18, 2020 Risk IR Number: FG-IR-19-179