PSIRT Advisories

The FortiGuard Labs Product Security Incident Response Team (PSIRT) continually test Fortinet hardware and software products, looking for vulnerabilities and weaknesses. Any such findings are fed back to Fortinet's development teams and serious issues are described along with protective solutions in the advisories below.

A cross-site-scripting vulnerablity in FortiAnalyzer/FortiManager in advanced settings page could allow an administrator to inject...

Oct 05, 2016 Risk IR Number: FG-IR-16-051
One of the processes in FortiClient stores VPN credentials unencrypted in memory. A malicious attacker who compromised the workstation...

Sep 12, 2016 Risk IR Number: FG-IR-16-021
OpenSSL released an update in January 2016 to address one high and one low severity vulnerabilities.

Jul 12, 2016 Risk IR Number: FG-IR-16-012
A path traversal vulnerability allows an administrator account with read and write privileges to read arbitrary files using the...

May 26, 2016 Risk IR Number: FG-IR-16-009
FortiOS now includes for all SSL libraries a countermeasure against Lenstra's fault attack on RSA-CRT optimization when a RSA...

May 16, 2016 Risk IR Number: FG-IR-16-008
The FortiOS webui accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect....

Mar 16, 2016 Risk IR Number: FG-IR-16-004
It is possible to inject malicious script through the DHCP HOSTNAME option. The malicious script code is injected into the device's...

Mar 16, 2016 Risk IR Number: FG-IR-16-003
Researchers discovered that certain next generation firewalls are designed to permit full TCP handshake with any destination,...

Dec 15, 2015 Risk IR Number: FG-IR-15-024
OpenSSL released an update in December 2015 to address a small number of vulnerability issues.

Dec 10, 2015 Risk IR Number: FG-IR-15-023
FortiClient drivers expose IOCTL that may allow an unprivileged user to get system-level privileges.

Sep 01, 2015 Risk IR Number: FG-IR-15-025
When connecting to a FortiGuard server via TLS, FortiOS 5.2.3/5.0.11 and below is supporting multiple weak ciphers including anonymous,...

Jul 24, 2015 Risk IR Number: FG-IR-15-021
OpenSSL released a security advisory in June 2015 to announce multiple security vulnerabilities.

Jun 11, 2015 Risk IR Number: FG-IR-15-014
Researchers (from the same group of people who discovered the FREAK Vulnerability in SSL/TLS) have published a paper demonstrating...

May 20, 2015 Risk IR Number: FG-IR-15-013
Older versions of FortiWeb are subject to three vulnerabilities: 1. OS command injection: A WebUI administrator user may run...

Apr 16, 2015 Risk IR Number: FG-IR-15-010
Certain versions of FortiManager are subject to the following vulnerabilities: 1. Escalation of Privileges: under certain circumstances,...

Apr 16, 2015 Risk IR Number: FG-IR-15-011