FortiGate-3000
Chassis
· FortiGate Series
Is the FortiGate-3000 still supported?
No. Fortinet ended support for the FortiGate-3000 on 2012-09-13. No further security fixes will be issued. See Fortinet's lifecycle bulletin.
When does the FortiGate-3000 reach end of support?
Fortinet support for the FortiGate-3000 ends on 2012-09-13.
What replaces the FortiGate-3000?
Fortinet has not published a successor model for the FortiGate-3000.
What known-exploited CVEs apply to the FortiGate-3000 past end of support?
19 CVEs in CISA's Known Exploited Vulnerabilities catalog apply to the platform the FortiGate-3000 runs. These will not be patched on this device because it is past the Fortinet security-support date. See the Known Exploited Vulnerabilities table below for the full list.
Known Exploited Vulnerabilities
This device is past Fortinet's security-support date. 19 CVEs in CISA's Known Exploited Vulnerabilities catalog apply to the platform it runs. Fortinet is not issuing patches for this model. Isolate, compensate, or refresh.
| CVE | KEV added | Vulnerability | Flags |
|---|---|---|---|
CVE-2025-68686
|
Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability | ||
CVE-2026-24858
|
Fortinet Multiple Products Authentication Bypass Using an Alternate Path or Channel Vulnerability | ||
CVE-2025-59718
|
Fortinet Multiple Products Improper Verification of Cryptographic Signature Vulnerability | ||
CVE-2019-6693
|
Fortinet FortiOS Use of Hard-Coded Credentials Vulnerability | Ransomware | |
CVE-2025-24472
|
Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability | Ransomware | |
CVE-2024-55591
|
Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability | Ransomware | |
CVE-2024-23113
|
Fortinet Multiple Products Format String Vulnerability | ||
CVE-2024-21762
|
Fortinet FortiOS Out-of-Bound Write Vulnerability | Ransomware | |
CVE-2023-27997
|
Fortinet FortiOS and FortiProxy SSL-VPN Heap-Based Buffer Overflow Vulnerability | Ransomware | |
CVE-2022-41328
|
Fortinet FortiOS Path Traversal Vulnerability | ||
CVE-2022-42475
|
Fortinet FortiOS Heap-Based Buffer Overflow Vulnerability | Ransomware | |
CVE-2022-40684
|
Fortinet Multiple Products Authentication Bypass Vulnerability | Ransomware | |
CVE-2018-13374
|
Fortinet FortiOS and FortiADC Improper Access Control Vulnerability | Ransomware | |
CVE-2018-13382
|
Fortinet FortiOS and FortiProxy Improper Authorization | Ransomware | |
CVE-2018-13383
|
Fortinet FortiOS and FortiProxy Out-of-bounds Write | Ransomware | |
CVE-2021-44168
|
Fortinet FortiOS Arbitrary File Download | ||
CVE-2019-5591
|
Fortinet FortiOS Default Configuration Vulnerability | ||
CVE-2020-12812
|
Fortinet FortiOS SSL VPN Improper Authentication Vulnerability | Ransomware | |
CVE-2018-13379
|
Fortinet FortiOS SSL VPN Path Traversal Vulnerability | Ransomware |
Source: CISA Known Exploited Vulnerabilities catalog. The Ransomware flag reflects CISA's own knownRansomwareCampaignUse field, set when the CVE has been observed in ransomware campaigns per their threat intel. It's not a property of the vulnerability description itself.
Correlation is at the platform level, not per-OS-version. Not exhaustive: KEV only lists actively-exploited CVEs and many relevant unexploited vulnerabilities are not here. Verify against vendor security advisories (PSIRT, JSA, PAN-SA) and NVD before acting. See compensating controls if refresh isn't immediate.
FortiGate-3000 Lifecycle Overview
The Fortinet FortiGate-3000 is a chassis product in the Fortinet FortiGate series. This product has reached end of life as of , meaning Fortinet no longer provides technical support, software updates, or hardware replacement for this product. It was last available for purchase on . Organizations still running the FortiGate-3000 should plan a migration .
Lifecycle Milestones
| End of sale | 18y 11mo ago | |
|---|---|---|
| End of software maintenance | 16y 11mo ago | |
| Last date of support | 13y 11mo ago |