Monthly PSIRT Advisories
- 2023: Mar , Feb , Jan
- 2022: Dec , Nov , Sep , Aug , Jul , Jun , May , Apr , Mar , Feb
- 2021: Dec , Nov , Oct , Sep , Aug , Jul , Jun , May , Apr , Mar , Feb , Jan
- 2020: Dec
The following is a list of advisories for issues resolved in Fortinet products. The resolution of such issues is coordinated by the Fortinet Product Security Incident Response Team (PSIRT), a dedicated, global team that manages the receipt, investigation, and public reporting of information about security vulnerabilities and issues related to Fortinet products and services.
For details of how to raise a PSIRT Issue with Fortinet, please see our PSIRT Policy here.
FortiAuthenticator - "Mandatory password and OTP" setting not enforcing OTP on unimported remote users
An incorrect implementation of authentication algorithm vulnerability [CWE-303] in FortiAuthenticator may allow an user wh...
FortiAuthenticator 6.4.0Dec 07, 2021 Severity Medium IR Number: FG-IR-21-212 CVE-2021-43068
An authentication bypass by capture-replay vulnerability [CWE-294] in FortiClient EMS may allow an unauthenticated attacke...
FortiClientEMS 7.0.1, 7.0.0, 6.4.4, 6.4.3, 6.4.2, 6.4.1, 6.4.0, 6.2.9, 6.2.8, 6.2.7, 6.2.6, 6.2.4, 6.2.3, 6.2.2, 6.2.1, 6.2.0Dec 07, 2021 Severity Medium IR Number: FG-IR-21-192 CVE-2021-41030
A missing encryption of sensitive data vulnerability [CWE-311] in FortiClientEMS may allow an authenticated attacker to vi...
FortiClientEMS 7.0.1, 7.0.0, 6.4.4, 6.4.3, 6.4.2, 6.4.1, 6.4.0Dec 07, 2021 Severity Medium IR Number: FG-IR-21-140 CVE-2021-36189