PSIRT Advisories

The FortiGuard Labs Product Security Incident Response Team (PSIRT) continually test Fortinet hardware and software products, looking for vulnerabilities and weaknesses. Any such findings are fed back to Fortinet's development teams and serious issues are described along with protective solutions in the advisories below.

OpenSSL released an update in May 2016 to address two high and four low severity vulnerabilities.CVE-2016-2108; CVE-2016-2107;...

Sep 22, 2016 Risk IR Number: FG-IR-16-026
When executed, the FortiClient installer (FortiClientOnlineInstaller.exe), if downloaded before August 11th, 2016 (build 0842),...

Sep 12, 2016 Risk IR Number: FG-IR-16-046
FortWan 4.2.4 and below is exposed to cross site scripting, information leak and escalation of privilege vulnerabilities.CVE-2016-4965:...

Sep 07, 2016 Risk IR Number: FG-IR-16-045
Forticloud online service before May 3, 2016 was exposed to cross site scripting web vulnerabilities, which could allow malicious...

Aug 09, 2016 Risk IR Number: FG-IR-16-022
A vulnerablity in FortiVoice 5.0 web-application could allow malicious script being injected in the affected module; this potentially...

Aug 09, 2016 Risk IR Number: FG-IR-16-020
An XSS vulnerablity in FortiManager/FortiAnalyzer could allow privileged guest user accounts and restricted user accounts to inject...

Aug 09, 2016 Risk IR Number: FG-IR-16-016
A vulnerablity in FortiManager/FortiAnalyzer address added page could allow malicious script being injected in the input field;...

Aug 09, 2016 Risk IR Number: FG-IR-16-017
A client side XSS vulnerablity in FortiManager/FortiAnalyzer could allow malicious script being injected in the Web-UI; this potentially...

Aug 09, 2016 Risk IR Number: FG-IR-16-015
When a low privileged user uploads images in the report section, the filenames are not properly sanitized; this potentially enables...

Jul 14, 2016 Risk IR Number: FG-IR-16-014
There is a CSRF vulnerability with FortiWEB console on dashboard. Attackers may submit local forms to change admin password illegally.

Jun 23, 2016 Risk IR Number: FG-IR-16-010
The Security Account Manager Remote Protocol [MS-SAMR] and the Local Security Authority (Domain Policy) Remote Protocol [MS-LSAD] are...

Apr 14, 2016 Risk IR Number: FG-IR-16-007
Since glibc 2.9, the glibc DNS client side resolver is vulnerable to a stack-based buffer overflow when the getaddrinfo() library...

Feb 25, 2016 Risk IR Number: FG-IR-16-002
The Graphical User Interface (GUI) of FortiManager v5.2.2 is vulnerable to two reflected Cross-Site Scripting (XSS) vulnerabilities. 2...

Sep 24, 2015 Risk IR Number: FG-IR-15-022
The Web User Interface of FortiSandbox version 2.0.4 and below is vulnerable to multiple reflected Cross-Site Scripting vulnerabilities. 5...

Jul 24, 2015 Risk IR Number: FG-IR-15-019
Installing Forticlient SSLVPN Linux client build 2312 and lower in a home directory that is world readable-executable yields a...

Jul 24, 2015 Risk IR Number: FG-IR-15-017