PSIRT Advisories

The FortiGuard Labs Product Security Incident Response Team (PSIRT) continually test Fortinet hardware and software products, looking for vulnerabilities and weaknesses. Any such findings are fed back to Fortinet's development teams and serious issues are described along with protective solutions in the advisories below.

Failure to sanitize input in the SSL VPN web portal may allow an attacker to perform a reflected Cross-site Scripting (XSS) attack...

Aug 21, 2019 Risk IR Number: FG-IR-19-034
A Default Configuration vulnerability in FortiOS may allow an unauthenticated attacker on the same subnet to intercept sensitive...

Jul 26, 2019 Risk IR Number: FG-IR-19-037
FortiClient for Windows could be subject to the following shut down or tampering attempts:a) User Interface or Command Line shut...

Jul 25, 2019 Risk IR Number: FG-IR-19-148
FortiOS Explicit Web Proxy by default allows non-standard HTTP traffic. FortiOS SSL/SSH Inspection Profile by default allows non-standard...

Jul 24, 2019 Risk IR Number: FG-IR-19-111
VM appliance lack of root file system integrity check may allow an attacker with read/write access to the VM image (before it...

Jul 24, 2019 Risk IR Number: FG-IR-19-017
Multiple padding oracle vulnerabilities (Zombie POODLE, GOLDENDOODLE, OpenSSL 0-length) in the CBC padding implementation of FortiOS...

Jul 23, 2019 Risk IR Number: FG-IR-19-145
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") in FortiNAC admin webUI may allow an unauthenticated...

Jul 16, 2019 Risk IR Number: FG-IR-19-140
The URL part of the report message is not encoded in Fortinet FortiWeb which may allow an attacker to execute unauthorized code...

Jun 12, 2019 Risk IR Number: FG-IR-19-070
Server Message Block (SMB) 1.0 - a legacy file and print sharing protocol - has been deprecated by Microsoft due to multiple weaknesses...

Jun 04, 2019 Risk IR Number: FG-IR-17-103
Failure to sanitize the error or message handling parameters in the SSL VPN web portal may allow an attacker to perform a Cross-site...

May 24, 2019 Risk IR Number: FG-IR-18-383
Failure to sanitize the login redir parameter in the SSL-VPN web portal may allow an attacker to perform a Cross-site Scripting...

May 24, 2019 Risk IR Number: FG-IR-17-242
Failure to properly parse message payloads in the SSL VPN portal of FortiOS may allow a non-authenticated attacker to perform...

May 17, 2019 Risk IR Number: FG-IR-18-387
Failure to sanitize input in the customized data pattern webpage of FortiCASB  may allow an authenticated attacker to conduct...

May 15, 2019 Risk IR Number: FG-IR-19-001
Some FortiAP models are vulnerable to the Bleeding Bit Vulnerability (CVE-2018-16986) present in the Texas Instruments WiFi chips.CVE-2018-16986:Texas...

Apr 10, 2019 Risk IR Number: FG-IR-18-356
FortiSwitch is vulnerable to multiple Cross-site Scripting (XSS) attacks present in the jQuery javascript libraryCVE-2015-9251:jQuery...

Apr 10, 2019 Risk IR Number: FG-IR-18-013