Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
douji
New Contributor

CVE's and Fortinet FortiOS

I met an experienced network engineer/executive recently in the financial sector and he said he would never use Fortinet firewalls due to the amount of CVE's. As a long time Fortinet customer, I'd love to hear your thoughts.

 
1 REPLY 1
RicardoPearce
New Contributor

I’ve heard that many times before, but it’s not the whole story.
Fortinet ends up with a lot of CVEs because the platform does so much.
It includes NGFW, VPN, SD-WAN, proxy features, IPS, ZTNA, wireless and more. The more features a vendor ships, the larger the attack surface becomes, and naturally the higher the CVE count . That doesn’t automatically mean the product is insecure.

What really matters is how fast a vendor responds and Fortinet is usually quick with patches and clear PSIRT advisories. Every major firewall vendor has had serious vulnerabilities at one point or another, whether it’s Palo Alto, Cisco, Check Point or Juniper. None of them are immune.

In practice, FortiGate tends to be as secure and stable as the way it’s deployed. Staying on a supported firmware branch, patching regularly, enabling only what you actually use and following proper design and segmentation principles make a much bigger difference than the raw number of CVEs.

If Fortinet has served you well so far, I wouldn’t let the CVE count alone sway you.

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors