PSIRT Advisories

Monthly PSIRT Advisories

The following is a list of advisories for issues resolved in Fortinet products. The resolution of such issues is coordinated by the Fortinet Product Security Incident Response Team (PSIRT), a dedicated, global team that manages the receipt, investigation, and public reporting of information about security vulnerabilities and issues related to Fortinet products and services.  

For details of how to raise a PSIRT Issue with Fortinet, please see our PSIRT Policy here.

Use of a hard-coded cryptographic key to encrypt security sensitive data in configuration in FortiClient for Windows may a...

FortiClientWindows 6.2.9, 6.2.8, 6.2.7, 6.2.6
Jun 01, 2020 Severity black-background-circle-icon black-background-circle-icon lightgray-background-circle-icon lightgray-background-circle-icon lightgray-background-circle-icon Low IR Number: FG-IR-19-194 CVE-2019-16150
An improper authorization vulnerability in FortiADC may allow a remote authenticated user with low privileges to perform c...

FortiADC 5.3.4
Apr 06, 2020 Severity black-background-circle-icon black-background-circle-icon lightgray-background-circle-icon lightgray-background-circle-icon lightgray-background-circle-icon Low IR Number: FG-IR-20-013 CVE-2020-9286
An improper neutralization of input vulnerability in the FortiADC may allow an attacker to execute a stored Cross Site Scr...

FortiADC 5.3.3, 5.3.2, 5.3.1
Mar 09, 2020 Severity black-background-circle-icon black-background-circle-icon lightgray-background-circle-icon lightgray-background-circle-icon lightgray-background-circle-icon Low IR Number: FG-IR-19-220 CVE-2019-6699
A privilege escalation vulnerability in FortiOS may allow admin users to elevate their profile to super_admin, via restori...

FortiOS 6.2.0, 6.0.7, 6.0.6, 6.0.5, 6.0.4, 6.0.3, 6.0.2, 6.0.1, 6.0.0, 5.6.9, 5.6.8, 5.6.7, 5.6.6, 5.6.5, 5.6.4, 5.6.3, 5.6.2, 5.6.10, 5.6.1, 5.6.0, 5.4.9, 5.4.8, 5.4.7, 5.4.6, 5.4.5, 5.4.4, 5.4.3, 5.4.2, 5.4.13, 5.4.12, 5.4.11, 5.4.10, 5.4.1, 5.4.0 FortiADC 5.2.2, 5.1.4
Nov 14, 2019 Severity black-background-circle-icon black-background-circle-icon lightgray-background-circle-icon lightgray-background-circle-icon lightgray-background-circle-icon Low IR Number: FG-IR-17-053 CVE-2017-17544
New types of side channel attacks impact most processors including Intel, AMD, ARM, etc. These attacks allow malicious use...

FortiSandbox 3.1.2, 3.1.1, 3.1.0 FortiClientWindows 5.6.4, 5.4.4 FortiSIEM 4.10.0
Aug 26, 2019 Severity black-background-circle-icon black-background-circle-icon lightgray-background-circle-icon lightgray-background-circle-icon lightgray-background-circle-icon Low IR Number: FG-IR-18-002 CVE-2017-5753