PSIRT Advisories

The FortiGuard Labs Product Security Incident Response Team (PSIRT) continually test Fortinet hardware and software products, looking for vulnerabilities and weaknesses. Any such findings are fed back to Fortinet's development teams and serious issues are described along with protective solutions in the advisories below.

It is possible to inject malicious script through the DHCP HOSTNAME option. The malicious script code is injected into the device's...

Mar 15, 2016 Risk IR Number: FG-IR-16-003
Researchers discovered that certain next generation firewalls are designed to permit full TCP handshake with any destination,...

Dec 14, 2015 Risk IR Number: FG-IR-15-024
OpenSSL released an update in December 2015 to address a small number of vulnerability issues.

Dec 09, 2015 Risk IR Number: FG-IR-15-023
FortiClient drivers expose IOCTL that may allow an unprivileged user to get system-level privileges.

Aug 31, 2015 Risk IR Number: FG-IR-15-025
When connecting to a FortiGuard server via TLS, FortiOS 5.2.3/5.0.11 and below is supporting multiple weak ciphers including anonymous,...

Jul 23, 2015 Risk IR Number: FG-IR-15-021
OpenSSL released a security advisory in June 2015 to announce multiple security vulnerabilities.

Jun 11, 2015 Risk IR Number: FG-IR-15-014
Researchers (from the same group of people who discovered the FREAK Vulnerability in SSL/TLS) have published a paper demonstrating...

May 19, 2015 Risk IR Number: FG-IR-15-013
Certain versions of FortiManager are subject to the following vulnerabilities: 1. Escalation of Privileges: under certain circumstances,...

Apr 15, 2015 Risk IR Number: FG-IR-15-011
Older versions of FortiWeb are subject to three vulnerabilities: 1. OS command injection: A WebUI administrator user may run...

Apr 15, 2015 Risk IR Number: FG-IR-15-010
FortiMail's "diag debug application httpd" set of commands can be used to capture the credentials entered in the admin WebGui...

Apr 09, 2015 Risk IR Number: FG-IR-15-009
OpenSSL released a security advisory in March 2015 to announce multiple security vulnerabilities.

Mar 23, 2015 Risk IR Number: FG-IR-15-008
FREAK is an attack on SSL/TLS, which allows "Man in the Middle" attackers to decipher and alter HTTPS connections between a server...

Mar 03, 2015 Risk IR Number: FG-IR-15-007
FortiClient Android and iOS are affected by two vulnerabilities: Android and iOS FortiClient do not check the validity of server...

Feb 24, 2015 Risk IR Number: FG-IR-15-004
The Web User Interface of FortiGate, FortiManager, FortiAnalyzer, FortiMail and FortiADC D models are vulnerable to reflected...

Feb 24, 2015 Risk IR Number: FG-IR-15-005

Feb 04, 2015 Risk IR Number: FG-IR-15-002