PSIRT Advisories

Monthly PSIRT Advisories

The following is a list of advisories for issues resolved in Fortinet products. The resolution of such issues is coordinated by the Fortinet Product Security Incident Response Team (PSIRT), a dedicated, global team that manages the receipt, investigation, and public reporting of information about security vulnerabilities and issues related to Fortinet products and services.  

For details of how to raise a PSIRT Issue with Fortinet, please see our PSIRT Policy here.

A missing release of memory after effective lifetime vulnerability in FortiSwitch may allow an attacker on an adjacent net...

FortiSwitch 6.4.6, 6.4.5, 6.4.4, 6.4.3, 6.4.2, 6.4.1, 6.4.0, 6.2.6, 6.2.5, 6.2.4, 6.2.3, 6.2.2, 6.2.1, 6.2.0, 6.0.7, 6.0.6, 6.0.5, 6.0.4, 6.0.3, 6.0.2, 6.0.1, 6.0.0
Jun 01, 2021 Risk light-circle-logo light-circle-logo light-circle-logo light-circle-logo light-circle-logo IR Number: FG-IR-21-026 CVE-2021-26111
The Bluetooth BR/EDR specification up to and including version 5.1 permits sufficiently low encryption key length and does...

FortiSwitch 6.2.7, 6.2.6, 6.2.5, 6.2.4, 6.2.3, 6.2.2, 6.0.7, 6.0.6, 6.0.5
Apr 23, 2020 Risk light-circle-logo light-circle-logo light-circle-logo light-circle-logo light-circle-logo IR Number: FG-IR-19-224 CVE-2019-9506
An Uncontrolled Resource Consumption vulnerability in multiple products may allow an attacker to cause web service portal ...

FortiAnalyzer 5.6, 6.0, 6.2 FortiAP 6.0, 6.2 FortiManager 5.6, 6.0, 6.2 FortiOS 6.0, 6.2 FortiSwitch 6.0, 6.2
Feb 03, 2020 Risk light-circle-logo light-circle-logo light-circle-logo light-circle-logo light-circle-logo IR Number: FG-IR-19-013 CVE-2019-17657
The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birt...

FortiCache 4.2.8, 4.1.1, 4.0.4, 4.0.3, 4.0.2, 4.0.1, 4.0.0, 3.1.1, 3.1.0, 3.0.8, 3.0.7, 3.0.6, 3.0.5, 3.0.4, 3.0.3, 3.0.2, 3.0.1, 3.0.0, 2.3.7, 2.3.6, 2.3.5, 2.3.4, 2.3.3, 2.3.2, 2.3.1, 2.3.0, 2.2.4, 2.2.3, 2.2.2, 2.2.1, 2.2.0, 2.1.3, 2.1.2, 2.1.1, 2.1.0, 2.0.1, 2.0.0, 1.0.0, 0.4.10 FortiClientEMS 1.2.1, 1.0.2, 1.0.1, 1.0.0 FortiManager 6.0.2, 5.6.5 FortiAnalyzer 6.0.2, 5.6.5 FortiOS 5.4.1, 5.4.0, 5.2.9, 5.0.14 FortiSwitch 6.0.1, 3.6.7 FortiPortal 5.0.0
Feb 07, 2019 Risk light-circle-logo light-circle-logo light-circle-logo light-circle-logo light-circle-logo IR Number: FG-IR-17-173 CVE-2016-2183
A collection of AMD vulnerabilities known as "Ryzenfall, Fallout, Chimera, Masterkey" has been released. Attackers in poss...

FortiAnalyzer FortiAP 5.2, 5.6 FortiOS 5.2, 4.2 FortiSwitch
Apr 13, 2018 Risk light-circle-logo light-circle-logo light-circle-logo light-circle-logo light-circle-logo IR Number: FG-IR-18-046 CVE-2018-8930