PSIRT Advisories

The FortiGuard Labs Product Security Incident Response Team (PSIRT) continually test Fortinet hardware and software products, looking for vulnerabilities and weaknesses. Any such findings are fed back to Fortinet's development teams and serious issues are described along with protective solutions in the advisories below.

The FortiOS web proxy disclaimer page is potentially vulnerable to an XSS attack, via maliciously crafted "Host" headers in user...

Jan 22, 2018 Risk IR Number: FG-IR-17-262
A new type of side channel attacks impact most processors including Intel, AMD and ARM. The attack allows malicious userspace...

Jan 04, 2018 Risk IR Number: FG-IR-18-002
Intel recently released a security update (Intel-SA-00086), regarding Intel ME 11.x, SPS 4.0, and TXE 3.0 intel products.The following...

Jan 04, 2018 Risk IR Number: FG-IR-17-271
A plaintext recovery of encrypted messages or a Man-in-the-middle (MiTM) attack on RSA PKCS #1 v1.5 encryption is possible without...

Dec 22, 2017 Risk IR Number: FG-IR-17-302
When the "VPN before logon" feature of FortiClient Windows is enabled (disabled by default), and when the server certificate is...

Dec 12, 2017 Risk IR Number: FG-IR-17-070
An admin user with super_admin privileges (i.e. with a super_admin profile) may view the current sslvpn web portal session info,...

Dec 08, 2017 Risk IR Number: FG-IR-17-172
Before Dec 5th, 2017, a Cross-Site-Scripting (XSS) vulnerability in forticloud.com on-demand sandbox GUI may have allowed an authenticated...

Dec 08, 2017 Risk IR Number: FG-IR-17-259
When the FortiClient "Save Password" feature is enabled (disabled by default), and when users make use of it, FortiClient for...

Dec 07, 2017 Risk IR Number: FG-IR-17-214
Some models of FortiAnalyzer and FortiManager have a default setting of "Failover", for remote IPMI access; this means that if...

Nov 29, 2017 Risk IR Number: FG-IR-17-195
A Cross-site Scripting (XSS) vulnerability in FortiOS SSL-VPN web portalmay allow an authenticated user to inject arbitrary web...

Nov 23, 2017 Risk IR Number: FG-IR-17-242
FortiWebManager 5.8.0 fails to check the admin password, granting access regardless the provided string.

Nov 22, 2017 Risk IR Number: FG-IR-17-248
There exists a persistent Cross-site Scripting (XSS) vulnerability on FortiWeb's webUI Certificate View page, which can be triggered...

Nov 17, 2017 Risk IR Number: FG-IR-17-131
An old Infineon RSA library does not properly generate RSA key pairs, therefore enabling an attacker to potentially infer a private...

Nov 03, 2017 Risk IR Number: FG-IR-17-249
A collection of Bluetooth implementation vulnerabilities known as "BlueBorne" has been released. These vulnerabilities collectively...

Nov 03, 2017 Risk IR Number: FG-IR-17-212
A reflected XSS vulnerability exists in FortiOS web proxy disclaimer response web pages, potentially exploitable by an unauthenticated...

Nov 03, 2017 Risk IR Number: FG-IR-17-168