A critical security advisory is only useful when you can work out whether your own firewall is affected. Fortinet publishes detailed PSIRT advisories, but checking every FortiOS version, feature, interface, and VDOM by hand can take time and can easily become inconsistent.

PSIRT stands for Product Security Incident Response Team. Fortinet PSIRT advisories describe security weaknesses affecting Fortinet products, the versions involved, the available fixes, and any published workaround.

What the free ConfigSentry check covers

The free System - PSIRT Critical Advisories template checks an authorised FortiGate configuration against 12 critical advisories. It looks at the detected FortiOS version and, where relevant, the configuration that creates or reduces exposure.

  • Administrative and FortiCloud SSO authentication bypasses
  • SSL-VPN memory-corruption vulnerabilities
  • Heap and stack buffer overflows
  • Out-of-bounds writes
  • FGFM, captive portal, TACACS+, and deep-inspection exposure

The 12 critical PSIRT checks

Why run the free template?

Instead of manually comparing a configuration with 12 separate advisories, ConfigSentry applies the same checks consistently and returns clear pass, fail, or informational results.

  • Save time: check version and configuration exposure together.
  • See the evidence: identify the affected setting, interface, VDOM, profile, or service.
  • Get a next step: review practical remediation based on the advisory.
  • Share the result: use engineer and executive report formats for different audiences.

The audit is configuration-based. It does not exploit the firewall or prove whether a device has already been compromised. It helps identify combinations that should be upgraded, mitigated, or investigated.

Next step: Select the free System - PSIRT Critical Advisories template and run a ConfigSentry audit against an authorised FortiGate configuration.