Resolved issues
The following issues have been fixed in FortiEDR. For inquires about a particular bug, please contact Customer Service & Support.
- Core - Build 6.2.0.1102
- Central Manager - Build 6.2.6.0097 (new features)
- Central Manager - Build 6.2.5.0052 (new features)
- Central Manager - Build 6.2.4.0026
- Central Manager - Build 6.2.3.0036
- Central Manager - Build 6.2.2.0063
Core - Build 6.2.0.1102
|
Bug ID |
Description |
|---|---|
| 1169522 | Unable to deploy on-premise Jumpbox with a valid registration password that includes supported special characters. |
| 1190158, 1070795, 1065649 | Failure in installing Core 6.0.1.0665 (Ubuntu). |
| N/A | Hardening related to system packages of Core. |
Central Manager - Build 6.2.6.0097
|
Bug ID |
Description |
|---|---|
| 1081179, 1168208 | Remote shell command description is misleading. |
| 1131478, 1139171 | Issue with filtering SimulationBlock events in Rest API. |
| 1022052, 1044640 | UI issue in Investigation View. |
| 1137684, 1139174 | No error is shown when the Aggregator IP field is left empty when you request a custom macOS Collector installer. |
| 1090085, 1093959 |
Performance issue when changing between tabs or moving between events. |
| 1096510, 1109687, 1116872, 1117326, 1102300 | Logon errors and White Label Error Pages when accessing the environment. |
| 1016548, 1017832 | Cloning the Threat Hunting profile does not work via REST API. |
| 1132045, 1133075 | Memory issue when handling a huge number of events through the UI. |
| 1139830, 1140795, 1142004, 1141862, 1141316, 1141220 | Issue with processing an event due to an internal length limitation. |
| 1107662, 1109610 | Gibberish values in Communication Control application names. |
| 1131859, 1133653 | Issue with cloning communication control policies via REST API. |
| 1107662, 1090738, 1109213 | REST API call to list all applications for all Collectors and their vulnerabilities times out without returning values. |
| 1148830, 1150189 | Failure to run Inventory report if Communication Control report is stuck. |
| 1149315, 1158932, 1127455, 1172972, 1141221 |
Only security events are received in SIEM. System events and audit trail are not received. |
| 1094467, 1100131 | Workstation with the FortiEDR Collector installed are incorrectly shown under unmanaged devices. |
| 1141888, 1152713 | Wrong calculation of last seen field in Inventory view. |
| 1151399, 1156292 | Remote Shell session counter does not calculate session time correctly. |
| 1134162, 1151250 |
During the provisioning a FortiEDR instance via support portal, the Threat Hunting feature should be disabled when no respond entitlement is present. |
| 1167889, 1169846 | Playbooks are only visible in hoster view and not in organizational view. |
| 1145498 |
When you access the REST API information in the FortiEDR Manager, the example URL reflects the Aggregator's FQDN instead of the Manager's FQDN. |
| 1146024 | FortiClient notification configuration issue. |
|
1096331 |
Event Geo location is incorrect. |
| 1161774 | CPU load is too high. |
| 1147020 | Failure in pooling cloud reputation services list. |
| 1148687 | Failed to retrieve data from the Threat Hunting database. |
| 1144851 | No default classification is selected when handling events. |
| 1139170 | Request Body is not marked as "Required" in swagger but is required by Management. |
| 1150839 | The acquire license API does not work for Collectors in running state. |
| 1152231 | Checkbox is missing in Process Exclusion window in Exclusion Manager. |
|
1156296 |
Creating an exception in the Manager does not take effect on the Collector. |
|
1168763 |
Collectors migration stuck in pending migration. |
|
1166686 |
Failed to transfer the account once the password was changed. |
Refer to Central Manager - Build 6.2.6.0097 for a list of new features and enhancements for this build.
Central Manager - Build 6.2.5.0052
|
Bug ID |
Description |
|---|---|
|
1118639 |
Block usage of old unsupported collectors (before 5.2.5, 5.1.12, 6.0.9). |
|
1121460 |
Missing seconds for threat hunting time range filter. |
|
968588, 1109210 |
Security events are not archived when handled with the "Archive when handled" mark. |
|
1027570, 1049988 |
Unable to delete IP set. |
|
1030972, 1109209 |
Remote URL/IP might be missing in the investigation view when Action Node is Network Access. |
|
1044328, 1126689 |
FortiEDR API times out when creating an organization. |
|
1048022, 1072336, 1051316 |
Executable shows as Signed (invalid) in Investigation View. |
|
1060485, 1071139 |
Collectors uptime in Investigation View might be wrong. |
|
1070454, 1109212 |
When requesting a Collector, the latest version is at the bottom instead of the top of the dropdown list. |
|
1082958, 1109211 |
Misleading popup warning when exporting exceptions. |
|
1088396, 1111097 |
"Add to blocklist" does not work. |
|
1088918, 1110424 |
Error when adding exceptions in Investigation View. |
|
1096392, 1103190 |
Failed to load investigation view for some events |
|
1102334, 1109611 |
Part of the Japanese translation for the "Tools" - "End User Notifications" description is missing. |
|
1107662, 1109213 |
REST management-rest/comm-control/list-products takes too long. |
|
1109749, 1110426 |
Core is disconnected after upgrade. |
|
1111237, 1111316 |
Failed login not exported to Audit report on single account environments. |
|
1111339 |
Events are not shown as expected. |
|
1111573 |
Updating number of shards task causes many registration requests. |
|
1111424, 1115523 |
Moving the Collector is only available in Hoster view. |
|
1123003, 1126709, 1128535 |
Configuration error when an agent group is deleted. |
|
1124038, 1130754, 1125096 |
Central Manager crashes due to a memory issue. |
|
1126848 |
Collector registration fails due to license count error. |
|
1125644 |
Window freezes after pressing on the administration tab. |
|
1113344 |
Deleting a facet on threat hunting doesn't work. |
|
1117172 |
Error in REST API Update Organization function. |
|
1111786 |
Application Control configuration fails to reach the Collector. |
|
1132502 |
Central Manager upgrade fails when on-premise reputation configuration is present. |
|
1132503 |
Failed to retrieve scan test information for IoT devices. |
|
1130738 |
Error in REST API Create Organization function. |
Refer to Central Manager - Build 6.2.5.0052 for a list of new features and enhancements for this build.
Central Manager - Build 6.2.4.0026
|
Bug ID |
Description |
|---|---|
|
1109606 |
The "Change" option for Jumpboxes should be disabled for core versions 6.0.1 or earlier. |
|
1100797 |
Fix SSL communication from the Central Manager to the Internet. |
| 1103485, 1104828 | Pattern matching issue when creating a command line exception. |
| 1017194 | Remote shell commands fail to execute when whitespace exists. |
| 1040689, 1092458 | Issue with importing users with admin role during account move from single-tenant environment. |
|
998858 |
webapp crashed - krys-both-europe-west3-b-0. |
| 1027782 | Set maximum number of rows for export to Excel as 1000000, which is the maximum that Excel supports. |
| 1107296, 1107590 | Forensics page fails to load. |
Refer to Central Manager - Build 6.2.4.0026 for a list of new features and changes for this build.
Central Manager - Build 6.2.3.0036
|
Bug ID |
Description |
|---|---|
| 1066418, 1079834 | When saving a threat hunting query, the "Trigger Playbook Actions" configuration is not saved. |
| 1084495, 1086725 | Error when resetting password via API. |
| 1085365, 1087595 | Event exception deletion is not logged in the audit logs. |
| 1077632, 1081360, 1079828 | Configuration becomes degraded due to a missing backslash at the beginning. |
| 1060494, 1071138 |
Unable to see the whole command line path string in the investigation view. |
| 1076572 | Queries from Threat Hunting page do not return results. |
| 1048022, 1072336, 1051316 | Executable files are shown as "Signed (Invalid)". |
| 1066453, 1073361 | Time zone is different between "Event Viewer" and "Advanced Data". |
| 982597, 995691 | File hash is missing in the Stacks view. |
| 1087430, 1088329 | OS vulnerabilities reported for latest manager release based on Ubuntu. |
| 1094445 | Failure in importing an organization with "evt_aggregations_temp" error. |
| 1093013, 1090062, 1093453 |
Timeout while exporting Aggregator log under certain conditions. |
| 1093002, 1099133 | Exceptions covering queries work slowly on Ubuntu systems. |
| 1085287 | Failure in creating an organization with a FCTEMS serial number. |
| 1067236 | Only SHA1 should be allowed in exclusions for Linux. |
| 1085285 | Cores with a deprecated version should be blocked from registration. |
| 1086245 |
Content version reverts to default after Ubuntu migration. |
| 1069070 | Events from the last hour are not displayed. |
| 1087603 | Failure in creating exceptions with a signer name and executable path. |
Refer to Central Manager - Build 6.2.3.0036 for a list of new features and changes for this build.
Central Manager - Build 6.2.2.0063
|
Bug ID |
Description |
|---|---|
|
1007499, 1007958 |
No support for CEF v0. |
|
1010193, 1011186 |
The Getting Started pop-up is stuck at the right side of the page. |
|
0940899, 981604 |
The script path shown in a Blocked Event is incorrect. |
|
1043710, 1045205 |
Internal performance issues might lead to cores and collectors being shown as disconnected. |
|
1027570, 1049988 |
Failure to delete IP set. |
|
0985081, 1041719 |
Slowness In the UI when handling a large number of IP sets. |
|
1004747, 1005499 |
The version drop-down list for the Update Collector Version is not sorted by revision. |
|
1019580, 1020679 |
Failure to define an exception on the command line using a wildcard. |
|
951958, 978480 |
The option to uninstall the OSX collector via Management has been removed (uninstallation will be done via JAMF). |
|
1010469, 1011188 |
Format issue for messages with line breaks. |
|
1014407, 1041720 |
Enhanced hardening. |
|
1048446, 1049386 |
Parsing issue in FortiSIEM Connector. |
|
1060132, 1060358 |
UI slowness. |
|
1021705, 1048985, 1042304 |
Inappropriate error message appearance. |
|
1043533, 1044050 |
An Isolating and Moving device case was allowed for some Read-Only users in Graph view. |
|
1000196, 1064026, 1071260, 1068122, 1014861 |
Failure to log in using LDAP. |
|
1044328, 1044639 |
Rest API calls to create organizations takes generous amount of time and cause a time-out. |
|
1069674, 1071140 |
Improvement of dashboard UI performance. |
|
1046536, 1055564 |
UI issue with Threat Hunting Time Range Value Changes. |
|
1049792, 1051826 |
REST API issue related to creating a tag for an organization. |
|
1073415, 1074435 |
Move collector to group button is unresponsive with no pop-up windows appearing. |
|
1041344, 1072741 |
Slowness in Threat Hunting query results. |
|
1074761, 1075509 |
Get-audit REST data is corrupted when run by the hosted user. |
|
0964033, 969496 |
The manager sending inaccurate customer serial Numbers during Forti Analyzer log generation. |
|
1061680, 1063403 |
End Users Notifications and WCS settings not saving under Tools. |
|
1021733, 1056612 |
Communication Control applications fail to Export to Excel. |
|
1068904, 1070697 |
A new organization is not showing in FCS & OPS Portal. |
|
1019573, 1068607 |
An error message pops up in the aggregator due to incorrect detection of Gateway account ID. |
|
1023419, 1064123, 1061764 |
An issue with condition handling. |
|
1046232, 1075845, 1073021, 1058030 |
An issue with covering exceptions related to wildcards. |
|
1009758 |
Cannot create exceptions on archived events via the REST API. |
|
1038389 |
Localization issue in the Admin Tools page, where some button labels are in English when the UI is set to Japanese. |
|
1038390 |
Localization issue with the Export button label, which is not in Japanese. |
|
1038392 |
Japanese localization issue in the Investigation view, where the error message is in English when no EDR is connected to Management. |
|
985339 |
An Internal ID field should be configurable through the syslog connector screen. |
|
1069623 |
Error when filtering null or broken events. |
|
1067238 |
Collector fails to get configuration when connected to Aggregator in a separate tenant. |
Common vulnerabilities and exposures
Central Manager - Build 6.2.2.0063 is no longer vulnerable to the following CVE reference:
|
Bug ID |
CVE reference |
|---|---|
|
1072799 |
Central Manager - Build 6.2.1.0111
|
Bug ID |
Description |
|---|---|
|
998216, 999110 |
Missing group assignment for exceptions. |
|
1043710, 1045205 |
Cores and Collectors are shown as disconnected. |
|
1047134, 1040038 |
Central Manager console is slow. |
|
1060698, 1061245, 1055565 |
Failure after upgrade. |
| 1015401, 1016286 |
Optimize "Update Event" query. |
| 891658, 898734, 1001087, 1001509, 871488, 878328, 891628, 898735, 875941, 886735, 991703, 1012791 |
Localization fixes across UI. |
| 989826, 1013342 |
Connectors page flickers. |
| 996383, 999111, 1002993, 1006009, 996383, 996304 |
The management console runs slow. |
| 1008315, 1013846 |
Wrong timezone in Threat Hunting logs export timestamps. |
| 979032, 987942 |
Notification email is still sent to the user after the user has been removed from the user or distribution list. |
| 896347, 1018307 |
False positive events are returned when you filter by URL field in the Threat Hunting page. |
| 1004747, 1005499 |
Versions in the OTI Version dropdown are not sorted by revision. |
| 1002993, 994765 |
Malfunction while saving user preferences. |
| 1003742, 1020687 |
Web application fails to start. |
| 1016569, 1017311 |
The timestamp of runtime generated code is wrong in Graph view. |
| 1020292, 999109, 992151, 995697, 998599 |
The management console freezes. |
| 943931, 993736 |
Unable to delete events due to slowness in management console. |
| 1002993, 1006493 |
Failure to retrieve events through RestAPI after Collector isolation. |
| 1002993, 1016282 |
Improve IOT performance. |
| 816929, 833903 |
Improve Collector expiration logic. |
| 867670, 869516 |
RHEL Collectors display under New OS Family in Inventory. |
| 1009275, 1009755 |
Failure in saving a new password policy. |
| 1000225, 1017310 |
Missing configuration after moving Collectors. |
| 1011708, 1016285 |
Inconsistency in time value of expiration date when updated via the management console and via REST API. |
| 986183, 988881 |
Remote shell failure notice after upgrade. |
| 1026044, 1026437 |
When Japanese is selected, applications cannot be added using Application Control Manager. |
| 1007499, 1007954 |
CEF messages have three extra dashes and do not follow the RFC-3164 standard. |
| 1002993, 1013848 |
Failure in parsing IOT scan. |
| 1008673, 1014862 |
The number of Collectors in Dashboard does not match the number in Inventory. |
| 1005039, 1006008 |
Error parsing Stix2 feed with SHA-1 value. |
| 1008450, 1008577 |
New Collector registration fails in environments with add-ons. |
| 937104, 1007422 |
Improve TCP syslogs. |
| 1027885, 999553 |
Failure in loading Advanced Data details. |
| 940899, 981604 |
The script path shown is incorrect in blocked events. |
| 1019247, 1020682 |
Exclude noisy organizations from sending events in case of a flood of events. |
| 928566, 1021657 |
When exporting to Excel in Japanese environment, the order of column is sorted differently from the English environment. |
| 1018853, 1029861 |
Updating organization from the UI resets number of shards to 1. |
| 1026062, 1023904 |
"Loading data failed" error after right-clicking a node and selecting View activity events in Investigation View. |
| 1010193, 1011186 |
Getting Started popup windows gets stuck at the right side of the page. |
| 1006077, 1022775 |
Empty Taxii2/Taxii1 feed conversion should return "empty feed" error. |
| 1033544, 1029339 |
Unable to update number of licenses for organizations with unsupported characters after upgrading to 6.2. |
| 987058 |
Exporting event raw JSON is slow and causes slowness in the management console. |
| 1037376, 1041159 |
Error when logging out an Analyst user. |
| 1030490, 1032990 |
Failure in saving file scan configuration with a Collector group. |
| 1030678, 1016497 |
Error during the execution of REST API request. |
| 1044790, 1041155 |
Failure in saving an integration with an action. |
| 1015068, 1036804 |
Failure in executing some procedures using Rest API. |
| 1041471, 1007961 |
Failure when importing organizations. |
| 1027850, 1029342 |
Security events are not sent to the management console. |
| 1026575, 1041158 |
Error when saving threat hunting query via REST API. |
| 1028502, 1036803, 982543 |
Moving collector via REST API fails due to missing account name. |
| 989461, 1005495 |
Collector upgrade fails. |
| 982341, 985548 |
Failure in testing the firewall connector. |
| 998216, 999110 |
Group assignment of an exception is missing after the exception is edited. |
| 1048422 |
Unable to sccess system events. |
|
1025494 |
Clear Erased task failure on delete audit records. |
| 965878, 1036470 |
Issue related to the use of wildcard in alert key path in exceptions. |
| 998398, 990232 |
Parsing issue related to Taxii. |
| 1002993, 1000040 |
User preferences might cause system slowness. |
|
Performance degradation. |
|
| 1045803, 1012229 |
Failure in creating exceptions due to system overload. |
Refer to Central Manager - Build 6.2.1.0111 for a list of new features and changes for this build.
Central Manager - Build 6.2.0.0451
|
Bug ID |
Description |
|---|---|
| 1026062, 1031933 |
The Details pane does not show for some nodes or edges in the investigation view. |
|
1031422 |
Missing information in stacks view. |
|
1027529, 1029378, 1033544, 1029339 |
Error of invalid characters in organization name when trying to extend license for an organization after the upgrade to 6.2. |
Refer to Central Manager - Build 6.2.0.0451 for a list of new features and changes for this build.
Central Manager - Build 6.2.0.0440
|
Bug ID |
Description |
|---|---|
| 1011247, 1007511 | Issue with Graph view. |
| 1014463 | Loading error when configuring client certificate for syslog. |
Central Manager - GA Build 6.2.0.0436
|
Bug ID |
Description |
|---|---|
| N/A | No validation for organization registration passwords. |
|
915698 |
Wrong message when you click "Block address on Firewall" in the Investigation View. |
|
915266 |
Viewer users can save a rule under Communication Control. |
|
911996 |
Cannot add an application to two policies in Application Control. |
|
889939 |
Investigation View graph presentation error when zooming to fit. |
|
889942 |
Cannot see the buttons at the bottom when adding process exclusions in Investigation View. |
|
889945 |
Collector version is not displayed under "Update Collector Version". |
|
964773 |
Incorrect event association for devices with the same name. |
|
N/A |
Rest API option should be disabled during LDAP and SAML user configuration. |
Refer to GA build (Central Manager - 6.2.0.0436, Core - Build 6.0.1.0578, Threat Hunting Repository - Build 6.2.0.0427) for a list of new features and changes for this build.