A critical security advisory is only useful when you can work out whether your own firewall is affected. Fortinet publishes detailed PSIRT advisories, but checking every FortiOS version, feature, interface, and VDOM by hand can take time and can easily become inconsistent.
PSIRT stands for Product Security Incident Response Team. Fortinet PSIRT advisories describe security weaknesses affecting Fortinet products, the versions involved, the available fixes, and any published workaround.
What the free ConfigSentry check covers
The free System - PSIRT Critical Advisories template checks an authorised FortiGate configuration against 12 critical advisories. It looks at the detected FortiOS version and, where relevant, the configuration that creates or reduces exposure.
- Administrative and FortiCloud SSO authentication bypasses
- SSL-VPN memory-corruption vulnerabilities
- Heap and stack buffer overflows
- Out-of-bounds writes
- FGFM, captive portal, TACACS+, and deep-inspection exposure
The 12 critical PSIRT checks
- Administrative FortiCloud SSO authentication bypass — FG-IR-26-060: view the Fortinet advisory.
- Authentication bypass in administrative interface — FG-IR-22-377: view the Fortinet advisory.
- Authentication bypass in Node.js websocket module and CSF requests — FG-IR-24-535: view the Fortinet advisory.
- Format String Bug in fgfmd — FG-IR-24-029: view the Fortinet advisory.
- FortiCloud SSO login authentication bypass — FG-IR-25-647: view the Fortinet advisory.
- Heap buffer overflow in SSL-VPN pre-authentication — FG-IR-23-097: view the Fortinet advisory.
- Heap buffer underflow in administrative interface — FG-IR-23-001: view the Fortinet advisory.
- Heap-based buffer overflow in sslvpnd — FG-IR-22-398: view the Fortinet advisory.
- Out-of-bounds write in sslvpnd — FG-IR-24-015: view the Fortinet advisory.
- Out-of-bounds write in captive portal — FG-IR-23-328: view the Fortinet advisory.
- Proxy mode with deep inspection stack-based buffer overflow — FG-IR-23-183: view the Fortinet advisory.
- TACACS+ authentication bypass — FG-IR-24-472: view the Fortinet advisory.
Why run the free template?
Instead of manually comparing a configuration with 12 separate advisories, ConfigSentry applies the same checks consistently and returns clear pass, fail, or informational results.
- Save time: check version and configuration exposure together.
- See the evidence: identify the affected setting, interface, VDOM, profile, or service.
- Get a next step: review practical remediation based on the advisory.
- Share the result: use engineer and executive report formats for different audiences.
The audit is configuration-based. It does not exploit the firewall or prove whether a device has already been compromised. It helps identify combinations that should be upgraded, mitigated, or investigated.
Next step: Select the free System - PSIRT Critical Advisories template and run a ConfigSentry audit against an authorised FortiGate configuration.