PSIRT Advisories

The FortiGuard Labs Product Security Incident Response Team (PSIRT) continually test Fortinet hardware and software products, looking for vulnerabilities and weaknesses. Any such findings are fed back to Fortinet's development teams and serious issues are described along with protective solutions in the advisories below.

Since glibc 2.9, the glibc DNS client side resolver is vulnerable to a stack-based buffer overflow when the getaddrinfo() library...

Feb 25, 2016 Risk IR Number: FG-IR-16-002
The Graphical User Interface (GUI) of FortiManager v5.2.2 is vulnerable to two reflected Cross-Site Scripting (XSS) vulnerabilities. 2...

Sep 24, 2015 Risk IR Number: FG-IR-15-022
Installing Forticlient SSLVPN Linux client build 2312 and lower in a home directory that is world readable-executable yields a...

Jul 24, 2015 Risk IR Number: FG-IR-15-017
The Web User Interface of FortiSandbox version 2.0.4 and below is vulnerable to multiple reflected Cross-Site Scripting vulnerabilities. 5...

Jul 24, 2015 Risk IR Number: FG-IR-15-019

Feb 05, 2015 Risk IR Number: FG-IR-15-003

Jan 28, 2015 Risk IR Number: FG-IR-15-001

Dec 18, 2014 Risk IR Number: FG-IR-14-034

Oct 15, 2014 Risk IR Number: FG-IR-14-031
A temporary denial of service condition can be created using a specially crafted request sent to the FortiManager protocol service...

Aug 19, 2014 Risk IR Number: FG-IR-14-006
FortiWeb 5.0, 5.1 and 5.2.0 are vulnerable to multiple reflective cross-site scripting issues. Several parameters in the web management...

Jul 10, 2014 Risk IR Number: FG-IR-14-012
The OpenSSL project released an advisory on June 5th, 2014, which describes the following vulnerabilities: SSL/TLS MITM vulnerability...

Jun 06, 2014 Risk IR Number: FG-IR-14-018
Multiple CSRF vulnerabilities exist in the FortiWeb web administration console due to lack of CSRF token protection. This could...

May 02, 2014 Risk IR Number: FG-IR-14-013
The web administration interface on FortiADC D-series versions 3.2.0 and lower have a reflective cross-site scripting vulnerability...

Apr 03, 2014 Risk IR Number: FG-IR-14-004
FortiWeb 5.0.2 and lower are vulnerable to cross-site scripting (CVE-2014-1955), HTTP header injection (CVE-2014-1956) and privilege...

Feb 13, 2014 Risk IR Number: FG-IR-13-009
FortiOS 5.0.5 and earlier versions contain a cross-site scripting vulnerability. The mkey parameter in the URL /firewall/schedule/recurrdlg...

Feb 03, 2014 Risk IR Number: FG-IR-14-003