PSIRT Advisories

The FortiGuard Labs Product Security Incident Response Team (PSIRT) continually test Fortinet hardware and software products, looking for vulnerabilities and weaknesses. Any such findings are fed back to Fortinet's development teams and serious issues are described along with protective solutions in the advisories below.

FortiWeb 5.0, 5.1 and 5.2.0 are vulnerable to multiple reflective cross-site scripting issues. Several parameters in the web management...

Jul 09, 2014 Risk IR Number: FG-IR-14-012
The OpenSSL project released an advisory on June 5th, 2014, which describes the following vulnerabilities: SSL/TLS MITM vulnerability...

Jun 05, 2014 Risk IR Number: FG-IR-14-018
Multiple CSRF vulnerabilities exist in the FortiWeb web administration console due to lack of CSRF token protection. This could...

May 01, 2014 Risk IR Number: FG-IR-14-013
The web administration interface on FortiADC D-series versions 3.2.0 and lower have a reflective cross-site scripting vulnerability...

Apr 02, 2014 Risk IR Number: FG-IR-14-004
FortiWeb 5.0.2 and lower are vulnerable to cross-site scripting (CVE-2014-1955), HTTP header injection (CVE-2014-1956) and privilege...

Feb 12, 2014 Risk IR Number: FG-IR-13-009
FortiOS 5.0.5 and earlier versions contain a cross-site scripting vulnerability. The mkey parameter in the URL /firewall/schedule/recurrdlg...

Feb 02, 2014 Risk IR Number: FG-IR-14-003
Fortiweb 5.0.3 and earlier versions contain a cross-site scripting vulnerability. The filter parameter in the URL "/user/ldap_user/add"...

Feb 02, 2014 Risk IR Number: FG-IR-14-002
Authenticated administrative users can store injected Javascript content into a specific field on the web management interface....

Jan 16, 2014 Risk IR Number: FG-IR-14-001
Authenticated admin users may be able to obtain access to a system shell from the command line interface.

Dec 12, 2013 Risk IR Number: FG-IR-13-016
Input filter bypass and exception handling vulnerabilities can be used by an attacker to hijack administrator or customer sessions...

Jan 28, 2013 Risk IR Number: FG-IR-013-001
FortiMail fails to sanitize user input. The vulnerability allows an attacker to bypass its input filtering routine, which could...

Oct 24, 2012 Risk IR Number: FG-IR-012-005
Fortinet has verified a potential issue during HTTP session authentication that could lead to a buffer overflow condition on the...

Aug 19, 2012 Risk IR Number: FG-IR-012-003