PSIRT Advisories

The following is a list of advisories for issues resolved in Fortinet products. The resolution of such issues is coordinated by the Fortinet Product Security Incident Response Team (PSIRT), a dedicated, global team that manages the receipt, investigation, and public reporting of information about security vulnerabilities and issues related to Fortinet products and services.  

For details of how to raise a PSIRT Issue with Fortinet, please see our PSIRT Policy here.

An execution with unnecessary privileges vulnerability in the VCM engine of FortiClient for Linux may allow local users to elevate...

Oct 19, 2020 Risk IR Number: FG-IR-20-110
The Apache project released an advisory on August 7th 2020, which describes the following vulnerabilities:1) CVE-2020-9490 Apache...

Oct 05, 2020 Risk IR Number: FG-IR-20-128
Makers of popular WiFi hacking tool hashcat have discovered a way to improve password brute-forcing of the WPA/WPA2 wifi network...

Jan 27, 2020 Risk IR Number: FG-IR-18-199
Two improper access control vulnerabilities in FortiMail admin webUI may allow administrators to perform privileged functions...

Jan 03, 2020 Risk IR Number: FG-IR-19-237
CVE-2019-11477:The Linux kernel is vulnerable to an integer overflow in the 16 bit width of  TCP_SKB_CB(skb)->tcp_gso_segs.  A...

Nov 29, 2019 Risk IR Number: FG-IR-19-180
A heap buffer overflow vulnerability in the FortiOS SSL VPN web portal may cause the SSL VPN web service termination for logged...

Nov 26, 2019 Risk IR Number: FG-IR-18-388
A path traversal vulnerability in the FortiOS SSL VPN web portal may allow an unauthenticated attacker to download FortiOS system...

Nov 26, 2019 Risk IR Number: FG-IR-18-384
Some models of FortiAnalyzer and FortiManager have a default setting of "Failover", for remote IPMI access; this means that if...

Sep 17, 2019 Risk IR Number: FG-IR-17-195
An Improper Authorization vulnerability in the SSL VPN web portal may allow an unauthenticated attacker to change the password...

Aug 30, 2019 Risk IR Number: FG-IR-18-389
11 zero day vulnerabilities (aka. URGENT/11) were disclosed in VxWorks® TCP/IP stack (IPnet):CVE-2019-12255 - TCP Urgent Pointer...

Aug 26, 2019 Risk IR Number: FG-IR-19-222
An Use of Hard-coded Credentials vulnerability in FortiRecorder may allow an unauthenticated attacker with knowledge of the aforementioned...

Aug 12, 2019 Risk IR Number: FG-IR-19-185
Multiple Fortinet products may be affected by the following Linux Kernel vulnerability:CVE-2016-10229 Linux Kernel ipv4/udp.c...

Jul 24, 2019 Risk IR Number: FG-IR-17-118
An external control of system vulnerability in FortiOS may allow an authenticated, regular user to change the routing settings...

Apr 04, 2019 Risk IR Number: FG-IR-18-230
There is a format string vulnerability in the SSH username handling when connecting to FortiOS 5.6.0, that may lead to memory...

Jan 11, 2019 Risk IR Number: FG-IR-18-018
libssh versions 0.6 and above have an authentication bypass vulnerability inthe server code. By presenting the server an SSH2_MSG_USERAUTH_SUCCESS...

Nov 21, 2018 Risk IR Number: FG-IR-18-336