PSIRT Advisories

The FortiGuard Labs Product Security Incident Response Team (PSIRT) continually test Fortinet hardware and software products, looking for vulnerabilities and weaknesses. Any such findings are fed back to Fortinet's development teams and serious issues are described along with protective solutions in the advisories below.

An improper authentication vulnerability in SSL VPN in FortiOS may result in a user being able to log in successfully without...

FortiOS 6.0, 6.2, 6.4
Jul 13, 2020 Risk IR Number: FG-IR-19-283
An improper access control vulnerability in the admin SSH console of multiple products may allow an authenticated user to access...

FortiAnalyzer 6.0, 6.2 FortiAP 6.0, 6.2 FortiManager 6.0, 6.2
Jun 26, 2020 Risk IR Number: FG-IR-19-292
An OS command injection vulnerability in FortiManager and FortiAnalyzer may allow a privileged system administrator to run OS...

FortiAnalyzer 6.0, 6.2 FortiManager 6.0, 6.2
Jun 26, 2020 Risk IR Number: FG-IR-19-294
A cleartext storage in a file or on disk (CWE-313) vulnerability in FortiOS SSL VPN may allow an attacker to retrieve a logged-in...

FortiGate 5.4, 5.6, 6.0, 6.2
Jun 26, 2020 Risk IR Number: FG-IR-19-217
An insufficient control of network message volume (CWE-406) vulnerability in FortiAnalyzer may allow an unauthenticated remote...

Jun 22, 2020 Risk IR Number: FG-IR-20-036
An insufficient session expiration vulnerability in FortiDeceptor may allow an attacker to reuse the unexpired admin user session...

FortiDeceptor 3.0
Jun 21, 2020 Risk IR Number: FG-IR-20-006
An expression language injection vulnerability in FortiSIEM may allow a remote attacker to inject arbitrary javascript code in...

FortiSIEM 5.2
Jun 21, 2020 Risk IR Number: FG-IR-20-041
An improper neutralization of input vulnerability in FortiWLC may allow a remote authenticated attacker to perform a stored cross...

Jun 21, 2020 Risk IR Number: FG-IR-20-016
An improper neutralization of input vulnerability in the Admin Profile of FortiAnalyzer may allow a remote authenticated attacker...

FortiAnalyzer 6.2
Jun 03, 2020 Risk IR Number: FG-IR-20-003
An unquoted service path vulnerability in the FortiSIEM Windows Agent component may allow an attacker to gain elevated privileges...

Jun 03, 2020 Risk IR Number: FG-IR-20-021
An improper neutralization of input vulnerability in the FortiGateCloud login page may allow a remote unauthenticated attacker...

FortiCloud 4.4
May 25, 2020 Risk IR Number: FG-IR-19-306
An Insecure Temporary File (CWE-377) vulnerability in FortiClient for Windows may allow a local user to gain elevated privileges...

FortiClient 6.2, 6.0
May 25, 2020 Risk IR Number: FG-IR-20-040
An improper input validation (CWE-20) vulnerability in FortiAP CLI admin console may allow unauthorized administrators to overwrite...

FortiAP 5.6, 6.0, 6.2
May 25, 2020 Risk IR Number: FG-IR-19-298
TCP stacks that lack RFC 5961 3.2 & 4.2 support (or have it disabled at application level) may allow remote attackers to guess...

FortiAnalyzer 6.2, 6.0 FortiManager 6.2, 6.0
May 20, 2020 Risk IR Number: FG-IR-16-039
The Bluetooth BR/EDR specification up to and including version 5.1 permits sufficiently low encryption key length and does not...

FortiSwitch 6.0, 6.2
Apr 23, 2020 Risk IR Number: FG-IR-19-224