PSIRT Advisories

The FortiGuard Labs Product Security Incident Response Team (PSIRT) continually test Fortinet hardware and software products, looking for vulnerabilities and weaknesses. Any such findings are fed back to Fortinet's development teams and serious issues are described along with protective solutions in the advisories below.

An XSS vulnerablity in FortiManager/FortiAnalyzer could allow privileged guest user accounts and restricted user accounts to inject...

Aug 09, 2016 Risk IR Number: FG-IR-16-016
A vulnerablity in FortiManager/FortiAnalyzer address added page could allow malicious script being injected in the input field;...

Aug 09, 2016 Risk IR Number: FG-IR-16-017
A client side XSS vulnerablity in FortiManager/FortiAnalyzer could allow malicious script being injected in the Web-UI; this potentially...

Aug 09, 2016 Risk IR Number: FG-IR-16-015
When a low privileged user uploads images in the report section, the filenames are notproperly sanitized; this potentially enables...

Jul 14, 2016 Risk IR Number: FG-IR-16-014
OpenSSL released an update in January 2016 to address one high and one low severity vulnerabilities.

Jul 12, 2016 Risk IR Number: FG-IR-16-012
During an upgrade to version 3.4.1, a FortiSwitch device may let an attacker log in the rest_admin account without a password,...

Jul 11, 2016 Risk IR Number: FG-IR-16-011
There is a CSRF vulnerability with FortiWEB console on dashboard. Attackers may submit local forms to change admin password illegally....

Jun 23, 2016 Risk IR Number: FG-IR-16-010
A path traversal vulnerability allows an administrator account with read and write privileges to read arbitrary files using the...

May 26, 2016 Risk IR Number: FG-IR-16-009
FortiOS now includes for all SSL libraries a countermeasure against Lenstra's fault attack on RSA-CRT optimization when a RSA...

May 16, 2016 Risk IR Number: FG-IR-16-008
The Security Account Manager Remote Protocol [MS-SAMR] and theLocal Security Authority (Domain Policy) Remote Protocol [MS-LSAD]are...

Apr 14, 2016 Risk IR Number: FG-IR-16-007
The FortiOS webui accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect....

Mar 16, 2016 Risk IR Number: FG-IR-16-004
It is possible to inject malicious script through the DHCP HOSTNAME option. The malicious script code is injected into the device's...

Mar 16, 2016 Risk IR Number: FG-IR-16-003
Since glibc 2.9, the glibc DNS client side resolver is vulnerable to a stack-based buffer overflow when the getaddrinfo() library...

Feb 25, 2016 Risk IR Number: FG-IR-16-002
An undocumented account used for communication with authorized FortiManager devices exists on some versions of FortiOS, FortiAnalyzer,...

Jan 12, 2016 Risk IR Number: FG-IR-16-001
Researchers discovered that certain next generation firewalls are designed to permit full TCP handshake with any destination,...

Dec 15, 2015 Risk IR Number: FG-IR-15-024