PSIRT Advisories

The FortiGuard Labs Product Security Incident Response Team (PSIRT) continually test Fortinet hardware and software products, looking for vulnerabilities and weaknesses. Any such findings are fed back to Fortinet's development teams and serious issues are described along with protective solutions in the advisories below.

OpenSSL released an update in December 2015 to address a small number of vulnerability issues.

Dec 10, 2015 Risk IR Number: FG-IR-15-023
The Graphical User Interface (GUI) of FortiManager v5.2.2 is vulnerable to two reflected Cross-Site Scripting (XSS) vulnerabilities. 2...

Sep 24, 2015 Risk IR Number: FG-IR-15-022
FortiClient drivers expose IOCTL that may allow an unprivileged user to get system-level privileges.

Sep 01, 2015 Risk IR Number: FG-IR-15-025
The Web User Interface of FortiSandbox version 2.0.4 and below is vulnerable to multiple reflected Cross-Site Scripting vulnerabilities. 5...

Jul 24, 2015 Risk IR Number: FG-IR-15-019
Installing Forticlient SSLVPN Linux client build 2312 and lower in a home directory that is world readable-executable yields a...

Jul 24, 2015 Risk IR Number: FG-IR-15-017
A remote attacker may access the internal ZebOS shell of FortiOS 5.2.3 without authentication on the HA ("High Availability")...

Jul 24, 2015 Risk IR Number: FG-IR-15-020
When connecting to a FortiGuard server via TLS, FortiOS 5.2.3/5.0.11 and below is supporting multiple weak ciphers including anonymous,...

Jul 24, 2015 Risk IR Number: FG-IR-15-021
The SSL-VPN feature of FortiOS 4.3.12 and lower only checks the first byte of the TLS MAC in the finished message. An attacker...

Jul 15, 2015 Risk IR Number: FG-IR-15-016
OpenSSL released a security advisory in July 2015 to announce a high severity vulnerability affecting any application that verifies...

Jul 09, 2015 Risk IR Number: FG-IR-15-015
OpenSSL released a security advisory in June 2015 to announce multiple security vulnerabilities.

Jun 11, 2015 Risk IR Number: FG-IR-15-014
Researchers (from the same group of people who discovered the FREAK Vulnerability in SSL/TLS) have published a paper demonstrating...

May 20, 2015 Risk IR Number: FG-IR-15-013
The VENOM (Virtualized Environment Neglected Operations Manipulation) vulnerability impacts popular virtualization platforms,...

May 19, 2015 Risk IR Number: FG-IR-15-012
Certain versions of FortiManager are subject to the following vulnerabilities: 1. Escalation of Privileges: under certain circumstances,...

Apr 16, 2015 Risk IR Number: FG-IR-15-011
Older versions of FortiWeb are subject to three vulnerabilities: 1. OS command injection: A WebUI administrator user may run...

Apr 16, 2015 Risk IR Number: FG-IR-15-010
FortiMail's "diag debug application httpd" set of commands can be used to capture the credentials entered in the admin WebGui...

Apr 10, 2015 Risk IR Number: FG-IR-15-009