FortiOS vulnerability matching
Denetta FortiOS Vulnerability Matching is the module that compares a FortiGate’s FortiOS version with Fortinet’s records on CVE.org, the CISA KEV catalogue (actively exploited vulnerabilities) and FIRST EPSS (exploit probability); it classifies vulnerabilities by real-world risk rather than CVSS score and suggests the fixed version on the same branch. Detection is version comparison only; no exploit is ever attempted against the device.
Which sources are used?
The vulnerability list comes from records on CVE.org written by Fortinet as a CVE Numbering Authority (CNA); exploitation status from the CISA Known Exploited Vulnerabilities catalogue; exploit probability from FIRST EPSS scores. Data is refreshed daily.
If the feed is older than 72 hours, or the device version could not be read, the result is “unknown”, never “no vulnerabilities”. No vulnerability is ever marked “resolved” on stale data.
How are vulnerabilities prioritised?
Each vulnerability falls into exactly one class, so penalties are never counted twice:
- Critical — listed in CISA KEV (actively exploited).
- Critical — belongs to the SSL VPN component and SSL VPN is enabled on the device (assumed enabled if the state could not be read).
- High — high EPSS exploit probability.
- Medium — other matching vulnerabilities.
Which version should I upgrade to?
Denetta calculates the fixed version on the device’s own branch. If the branch has no fix, it says so and recommends a branch upgrade; it never invents a version. A CVE record that cannot be interpreted is not treated as “not affected”; it is listed separately.
What is in scope?
Matching covers FortiOS only; hardware and other Fortinet products are out of scope. The module is an add-on to Firewall Audit, and the FortiGate version comes from the configuration it reads.