PSIRT Advisories

The following is a list of advisories for issues resolved in Fortinet products. The resolution of such issues is coordinated by the Fortinet Product Security Incident Response Team (PSIRT), a dedicated, global team that manages the receipt, investigation, and public reporting of information about security vulnerabilities and issues related to Fortinet products and services.  

For details of how to raise a PSIRT Issue with Fortinet, please see our PSIRT Policy here.

The Apache project released an advisory on August 7th 2020, which describes the following vulnerabilities:1) CVE-2020-9490 Apache...

Oct 05, 2020 Risk IR Number: FG-IR-20-128
Makers of popular WiFi hacking tool hashcat have discovered a way to improve password brute-forcing of the WPA/WPA2 wifi network...

Jan 27, 2020 Risk IR Number: FG-IR-18-199
Two improper access control vulnerabilities in FortiMail admin webUI may allow administrators to perform privileged functions...

Jan 03, 2020 Risk IR Number: FG-IR-19-237
CVE-2019-11477:The Linux kernel is vulnerable to an integer overflow in the 16 bit width of  TCP_SKB_CB(skb)->tcp_gso_segs.  A...

Nov 29, 2019 Risk IR Number: FG-IR-19-180
A heap buffer overflow vulnerability in the FortiOS SSL VPN web portal may cause the SSL VPN web service termination for logged...

Nov 26, 2019 Risk IR Number: FG-IR-18-388
A path traversal vulnerability in the FortiOS SSL VPN web portal may allow an unauthenticated attacker to download FortiOS system...

Nov 26, 2019 Risk IR Number: FG-IR-18-384
Some models of FortiAnalyzer and FortiManager have a default setting of "Failover", for remote IPMI access; this means that if...

Sep 17, 2019 Risk IR Number: FG-IR-17-195
An Improper Authorization vulnerability in the SSL VPN web portal may allow an unauthenticated attacker to change the password...

Aug 30, 2019 Risk IR Number: FG-IR-18-389
11 zero day vulnerabilities (aka. URGENT/11) were disclosed in VxWorks® TCP/IP stack (IPnet):CVE-2019-12255 - TCP Urgent Pointer...

Aug 26, 2019 Risk IR Number: FG-IR-19-222
An Use of Hard-coded Credentials vulnerability in FortiRecorder may allow an unauthenticated attacker with knowledge of the aforementioned...

Aug 12, 2019 Risk IR Number: FG-IR-19-185
Multiple Fortinet products may be affected by the following Linux Kernel vulnerability:CVE-2016-10229 Linux Kernel ipv4/udp.c...

Jul 24, 2019 Risk IR Number: FG-IR-17-118
An external control of system vulnerability in FortiOS may allow an authenticated, regular user to change the routing settings...

Apr 04, 2019 Risk IR Number: FG-IR-18-230
There is a format string vulnerability in the SSH username handling when connecting to FortiOS 5.6.0, that may lead to memory...

Jan 11, 2019 Risk IR Number: FG-IR-18-018
libssh versions 0.6 and above have an authentication bypass vulnerability inthe server code. By presenting the server an SSH2_MSG_USERAUTH_SUCCESS...

Nov 21, 2018 Risk IR Number: FG-IR-18-336
In certain conditions, FortiClient users' VPN credentials are stored in improperly secured locations and unsafely encrypted.[CVE-2017-14184]When...

Apr 20, 2018 Risk IR Number: FG-IR-17-214