PSIRT Advisories

The FortiGuard Labs Product Security Incident Response Team (PSIRT) continually test Fortinet hardware and software products, looking for vulnerabilities and weaknesses. Any such findings are fed back to Fortinet's development teams and serious issues are described along with protective solutions in the advisories below.

An improper neutralization of input vulnerability in the FortiGateCloud login page may allow a remote unauthenticated attacker...

FortiCloud 4.4
May 25, 2020 Risk IR Number: FG-IR-19-306
An Insecure Temporary File (CWE-377) vulnerability in FortiClient for Windows may allow a local user to gain elevated privileges...

FortiClient 6.2, 6.0
May 25, 2020 Risk IR Number: FG-IR-20-040
An improper input validation (CWE-20) vulnerability in FortiAP CLI admin console may allow unauthorized administrators to overwrite...

FortiAP 5.6, 6.0, 6.2
May 25, 2020 Risk IR Number: FG-IR-19-298
TCP stacks that lack RFC 5961 3.2 & 4.2 support (or have it disabled at application level) may allow remote attackers to guess...

FortiAnalyzer 6.2, 6.0 FortiManager 6.2, 6.0
May 20, 2020 Risk IR Number: FG-IR-16-039
The Bluetooth BR/EDR specification up to and including version 5.1 permits sufficiently low encryption key length and does not...

FortiSwitch 6.0, 6.2
Apr 23, 2020 Risk IR Number: FG-IR-19-224
An improper neutralization of input vulnerability in the dashboard of FortiADC may allow an authenticated attacker to perform...

Apr 06, 2020 Risk IR Number: FG-IR-20-012
A Cross-Site Request Forgery (CSRF) vulnerability in the user interface of FortiSIEM could allow a remote, unauthenticated attacker...

Mar 12, 2020 Risk IR Number: FG-IR-19-240
An information exposure vulnerability in FortiWeb CLI may allow an authenticated user to view sensitive information being logged...

Mar 11, 2020 Risk IR Number: FG-IR-19-269
Multiple unsafe search path vulnerabilities in FortiClient online installers may allow an attacker with control over the directory...

Mar 09, 2020 Risk IR Number: FG-IR-19-060
An improper neutralization of input vulnerability in FortiWeb may allow a remote authenticated attacker to perform a stored cross...

FortiWeb 6.2, 6.3
Mar 09, 2020 Risk IR Number: FG-IR-20-001
An unquoted service path vulnerability in the FortiClient FortiTray component may allow an attacker to gain elevated privileges...

FortiClient 6.2
Mar 09, 2020 Risk IR Number: FG-IR-19-281
Two authorization bypass through user-controlled key vulnerabilities in the FortiPresence administration interface may allow an...

Mar 09, 2020 Risk IR Number: FG-IR-19-258
An improper neutralization of input vulnerability in the URL Description of FortiIsolator may allow a remote authenticated attacker...

FortiIsolator 1.2
Mar 09, 2020 Risk IR Number: FG-IR-19-270
An improper neutralization of input vulnerability in the Anomaly Detection interface of FortiWeb may allow a remote unauthenticated...

FortiWeb
Mar 09, 2020 Risk IR Number: FG-IR-19-265
Multiple padding Oracle vulnerabilities (Zombie POODLE, GOLDENDOODLE, OpenSSL 0-length) in the CBC padding implementation of FortiOS...

Feb 25, 2020 Risk IR Number: FG-IR-19-145