Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT
← Search results
CVE-LINKED INVENTORY124 SECURITY RECORDS

Fortinet, Inc.

FortiOS

Affected and fixed version statements observed in the public BlackTree CVE catalogue. These statements describe vulnerability scope, not publisher support entitlement.

Lifecycle evidence status

This CVE identity is linked to the Lifecycle record FortiOS. Use that record for publisher support phases and retirement dates.

A missing support date does not mean the product is supported. CVE publication dates and affected-version ranges must not be interpreted as EOL dates.

CVE-observed version history

CVEPublishedAffected versionsFixed version informationPublisher evidence
CVE-2022-41328 7 Mar 2023 FortiOS: 7.2.0 ≤ 7.2.3, 7.0.0 ≤ 7.0.9, 6.4.0 ≤ 6.4.11, 6.2.0 ≤ 6.2.13, 6.0.0 ≤ 6.0.16 Please upgrade to FortiOS version 7.2.4 or above; Please upgrade to FortiOS version 7.0.10 or above; Please upgrade to FortiOS version 6.4.12 or above Update reference ↗
CVE-2022-29054 16 Feb 2023 7.2.0; 7.0.0 ≤ 7.0.7; 6.4.0 ≤ 6.4.9; 6.2.0 ≤ 6.2.12; 6.0.0 ≤ 6.0.16; 7.2.0 ≤ 7.2.1; 2.0.0 ≤ 2.0.11; 1.2.0 ≤ 1.2.13 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2022-38378 16 Feb 2023 7.2.0; 7.0.0 ≤ 7.0.7; 6.4.0 ≤ 6.4.11; 6.2.0 ≤ 6.2.12; 6.0.0 ≤ 6.0.16; 7.2.0 ≤ 7.2.1; 2.0.0 ≤ 2.0.11; 1.2.0 ≤ 1.2.13 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2022-41334 16 Feb 2023 7.2.0 ≤ 7.2.3; 7.0.0 ≤ 7.0.7 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2022-42475 2 Jan 2023 FortiProxy: 7.2.0 ≤ 7.2.1, 7.0.0 ≤ 7.0.7, 2.0.0 ≤ 2.0.11, 1.2.0 ≤ 1.2.13, 1.1.0 ≤ 1.1.6, 1.0.0 ≤ 1.0.7; FortiOS: 7.2.0 ≤ 7.2.2, 7.0.0 ≤ 7.0.8, 6.4.0 ≤ 6.4.10, 6.2.0 ≤ 6.2.11, 6.0.0 ≤ 6.0.15, 5.6.0 ≤ 5.6.14, 5.4.0 ≤ 5.4.13, 5.2.0 ≤ 5.2.15, 5.0.0 ≤ 5.0.14 Please upgrade to FortiOS version 7.2.3 or above; Please upgrade to FortiOS version 7.0.9 or above; Please upgrade to FortiOS version 6.4.11 or above; Please upgrade to FortiOS version 6.2.12 or above; Please upgrade to FortiOS version 6.0.16 or above; Please upgrade to upcoming FortiOS-6K7K version 7.0.8 or above; Please upgrade to FortiOS-6K7K version 6.4.10 or above; Please upgrade to FortiOS-6K7K version 6.2.12 or above; Please upgrade to FortiOS-6K7K version 6.0.15 or above; Please upgrade to FortiProxy version 7.2.2 or above; Please upgrade to FortiProxy version 7.0.8 or above; Please upgrade to upcoming FortiProxy version 2.0.12 or above Update reference ↗
CVE-2022-35843 6 Dec 2022 7.2.0; 7.0.0 ≤ 7.0.6; 6.4.0 ≤ 6.4.9; 6.2.0 ≤ 6.2.12; 6.0.0 ≤ 6.0.15; 6.2.0 < 6.2.*; 6.0.0 < 6.0.*; 7.0.0 ≤ 7.0.5 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2021-44168 4 Jan 2022 Fortinet FortiOS: FortiOS before 7.0.3 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2021-42757 8 Dec 2021 7.0.0 ≤ 7.0.2; 6.4.0 ≤ 6.4.7; 6.2.0 ≤ 6.2.9; 6.0.0 ≤ 6.0.13; 5.6.0 ≤ 5.6.14; 5.4.0 ≤ 5.4.13; 5.2.0 ≤ 5.2.15; 5.0.0 ≤ 5.0.14 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2019-5591 14 Aug 2020 Fortinet FortiOS: FortiOS 6.2.0 and below. No fixed version is explicitly recorded in the structured CVE data. Update reference ↗
CVE-2020-12812 24 Jul 2020 Fortinet FortiOS: FortiOS 6.4.0, 6.2.0 to 6.2.3, 6.0.9 and below No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2019-6693 21 Nov 2019 FortiGate: 5.6.9 and below, 6.0.5 and below, 6.2.0 No fixed version is explicitly recorded in the structured CVE data. Update reference ↗
CVE-2018-13367 23 Aug 2019 6.2.3; 6.2.0 and below No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2018-13379 4 Jun 2019 Fortinet FortiOS, FortiProxy: FortiOS 6.0.0 to 6.0.4, 5.6.3 to 5.6.7 and 5.4.6 to 5.4.12, FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 to 1.1.6, 1.0.0 to 1.0.7 No fixed version is explicitly recorded in the structured CVE data. Update reference ↗
CVE-2017-17544 9 Apr 2019 < 6.2.0 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2018-9194 5 Sep 2018 6.0.1, 6.0.0; 5.4.9, 5.4.8, 5.4.7, 5.4.6 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2018-9192 5 Sep 2018 6.0.1, 6.0.0; 5.4.9, 5.4.8, 5.4.7, 5.4.6 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2017-14185 25 May 2018 5.6.0 to 5.6.2; 5.4.0 to 5.4.8; 5.2 all versions No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2017-14187 24 May 2018 5.6.0 to 5.6.2; 5.4.0 to 5.4.8; 5.2 and below versions No fixed version is explicitly recorded in the structured CVE data. Update reference ↗
CVE-2017-14190 29 Jan 2018 5.6.0 to 5.6.2; 5.4.0 to 5.4.7; 5.2 and all earlier versions. No fixed version is explicitly recorded in the structured CVE data. Update reference ↗
CVE-2017-7738 13 Dec 2017 5.6.0 to 5.6.2; 5.4.0 to 5.4.5; 5.2 and below No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2017-14186 29 Nov 2017 5.6.0 to 5.6.2; 5.4.0 to 5.4.6; 5.2.0 to 5.2.12; 5.0 and below No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2017-7739 13 Nov 2017 5.6.0; 5.4.5, 5.4.4, 5.4.3, 5.4.2, 5.4.1, 5.4.0; 5.2.11, 5.2.10, 5.2.9, 5.2.8, 5.2.7, 5.2.6, 5.2.5, 5.2.4, 5.2.3, 5.2.2, 5.2.1, 5.2.0 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2016-7542 30 Mar 2017 5.2.0 - 5.2.9, 5.4.1 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2016-7541 30 Mar 2017 5.0.x, 5.2.x No fixed version is explicitly recorded in the structured CVE data. Use CVE record

How this record is maintained

The CVE inventory is reconciled automatically from cve.blacktree.nl. Exact identity matches link to existing Lifecycle product or package histories. Unmatched products stay in a prioritised publisher-source research queue, and Lifecycle marks the date gap instead of inferring a support boundary from vulnerability data.