PSIRT Advisories

The FortiGuard Labs Product Security Incident Response Team (PSIRT) continually test Fortinet hardware and software products, looking for vulnerabilities and weaknesses. Any such findings are fed back to Fortinet's development teams and serious issues are described along with protective solutions in the advisories below.

Some FortiAP models are vulnerable to the Bleeding Bit Vulnerability (CVE-2018-16986) present in the Texas Instruments WiFi chips.CVE-2018-16986:Texas...

Apr 10, 2019 Risk IR Number: FG-IR-18-356
FortiSwitch is vulnerable to multiple Cross-site Scripting (XSS) attacks present in the jQuery javascript libraryCVE-2015-9251:jQuery...

Apr 10, 2019 Risk IR Number: FG-IR-18-013
An external control of system vulnerability in FortiOS may allow an authenticated, regular user to change the routing settings...

Apr 04, 2019 Risk IR Number: FG-IR-18-230
A reflected Cross-Site-Scripting (XSS) vulnerability in Fortinet FortiSandbox may allow an attacker to execute unauthorized code...

Apr 03, 2019 Risk IR Number: FG-IR-18-024
A heap buffer overflow vulnerability in the FortiOS SSL VPN web portal may cause the SSL VPN web service termination for logged...

Apr 02, 2019 Risk IR Number: FG-IR-18-388
A privilege escalation vulnerability in FortiOS may allow admin users to elevate their profile to super_admin, via restoring modified...

Apr 02, 2019 Risk IR Number: FG-IR-17-053
An improper access control vulnerability in FortiClientMac may allow an attacker to affect the application's performance via modifying...

Apr 02, 2019 Risk IR Number: FG-IR-19-003
Multiple information exposure vulnerabilities in FortiOS may allow an unauthenticated attacker to perform some information gathering...

Mar 29, 2019 Risk IR Number: FG-IR-19-043
An information exposure vulnerability in the admin portal of FortiSIEM may allow an authenticated admin to retrieve the LDAP server...

Mar 29, 2019 Risk IR Number: FG-IR-18-382
The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday...

Feb 07, 2019 Risk IR Number: FG-IR-17-173
There is a format string vulnerability in the SSH username handling when connecting to FortiOS 5.6.0, that may lead to memory...

Jan 11, 2019 Risk IR Number: FG-IR-18-018
There is a Null pointer dereference in the NDIS Miniport drivers in FortiClient on Windows, which may be leveraged by an unprivileged...

Jan 11, 2019 Risk IR Number: FG-IR-18-092
A researcher has disclosed several vulnerabilities against FortiClient for Windows, the combination of these vulnerabilities can...

Dec 22, 2018 Risk IR Number: FG-IR-18-108
An uninitialized memory buffer leak exists in FortiOS web proxy's disclaimer response web pages, potentially causing sensitive...

Nov 22, 2018 Risk IR Number: FG-IR-18-325
New types of side channel attacks impact most processors including Intel, AMD, ARM, etc. These attacks allow malicious userspace...

Nov 22, 2018 Risk IR Number: FG-IR-18-002