PSIRT Advisories

The FortiGuard Labs Product Security Incident Response Team (PSIRT) continually test Fortinet hardware and software products, looking for vulnerabilities and weaknesses. Any such findings are fed back to Fortinet's development teams and serious issues are described along with protective solutions in the advisories below.

FortiOS 4.3 used to implement the ANSI X9.31 RNG to decrypt TLS/IPSec traffic.It is now superseded by the CTR_DRBG implementation...

Nov 22, 2016 Risk IR Number: FG-IR-16-067
BlackNurse is a Denial of Service attack consisting in flooding the target with ICMP Type 3 Code 3 packets. The latter type of...

Nov 15, 2016 Risk IR Number: FG-IR-16-091
The following products are confirmed to be not affected:FortiGate FortiAnalyzerFortiSwitchFortiAP For questions about other Fortinet...

Nov 09, 2016 Risk IR Number: FG-IR-16-063
FortiWLC comes with a hardcoded account named 'core' which is used by Meru Access Points to send core dumps to the FortiWLC and...

Nov 09, 2016 Risk IR Number: FG-IR-16-065
A cross-site-scripting vulnerablity in FortiAnalyzer/FortiManager in advanced settings page could allow an administrator to inject...

Oct 05, 2016 Risk IR Number: FG-IR-16-051
The pam.log file generated by FortiWLC contains authenticated users credentials (local admin and users authenticated against external...

Sep 30, 2016 Risk IR Number: FG-IR-16-030
FortiWLC runs a rsyncd server, historically used for High-Availability purpose. This server comes with a hardcoded account, which...

Sep 30, 2016 Risk IR Number: FG-IR-16-029
A vulnerability in FortiDDoS allows escalation of privilege via remote OS injection through crafted URLs sent to the GUI. The...

Sep 28, 2016 Risk IR Number: FG-IR-16-037
OpenSSL released an update in May 2016 to address two high and four low severity vulnerabilities.CVE-2016-2108; CVE-2016-2107;...

Sep 22, 2016 Risk IR Number: FG-IR-16-026
When executed, the FortiClient installer (FortiClientOnlineInstaller.exe), if downloaded before August 11th, 2016 (build 0842),...

Sep 12, 2016 Risk IR Number: FG-IR-16-046
One of the processes in FortiClient stores VPN credentials unencrypted in memory. A malicious attacker who compromised the workstation...

Sep 12, 2016 Risk IR Number: FG-IR-16-021
FortWan 4.2.4 and below is exposed to cross site scripting, information leak and escalation of privilege vulnerabilities.CVE-2016-4965:...

Sep 07, 2016 Risk IR Number: FG-IR-16-045
FortiGate firmware (FortiOS) released before Aug 2012 has a cookie parser buffer overflow vulnerability. This vulnerability, when...

Aug 17, 2016 Risk IR Number: FG-IR-16-023
Forticloud online service before May 3, 2016 was exposed to cross site scripting web vulnerabilities, which could allow malicious...

Aug 09, 2016 Risk IR Number: FG-IR-16-022
A vulnerablity in FortiVoice 5.0 web-application could allow malicious script being injected in the affected module; this potentially...

Aug 09, 2016 Risk IR Number: FG-IR-16-020