PSIRT Advisories

The FortiGuard Labs Product Security Incident Response Team (PSIRT) continually test Fortinet hardware and software products, looking for vulnerabilities and weaknesses. Any such findings are fed back to Fortinet's development teams and serious issues are described along with protective solutions in the advisories below.

Makers of popular wifi hacking tool hashcat have discovered a way to improve WPA/WPA2 password brute-forcing: Leveraging the PMKID...

Sep 10, 2018 Risk IR Number: FG-IR-18-199
Two new attacks on IPsec IKE (Internet Key Exchange) were recently disclosed [1], involving multiple ways to perform attacks against...

Aug 27, 2018 Risk IR Number: FG-IR-18-214
A plaintext recovery of encrypted messages or a Man-in-the-middle (MiTM) attack on RSA PKCS #1 v1.5 encryption may be possible...

Aug 27, 2018 Risk IR Number: FG-IR-17-302
On May 23, 2018, Talos disclosed in a blog post the discovery of a modular malware system they deemed "VPNFilter", affecting multiple...

Aug 27, 2018 Risk IR Number: FG-IR-18-106
A standard user with adom assignment can read the interface settings of vdoms unrelated to his/her adom.

Aug 27, 2018 Risk IR Number: FG-IR-18-016
Before August, 2018, parameters at /loginmgrlogin in forticloud.com were vulnerable to a Cross-Site-Scripting (XSS) attack.

Aug 24, 2018 Risk IR Number: FG-IR-18-026
FortiCloud password reset link requested by the user takes one hour to expire even after password was changed successfully,...

Aug 24, 2018 Risk IR Number: FG-IR-18-074
The default replacement message in FortiOS' Application control block page reveals the private IP as well as the hostname of the...

Aug 23, 2018 Risk IR Number: FG-IR-18-085
FortiWeb's "Recursive URL Decoding" feature can detect URL-based attacks (among which XSS and SQL injection attempts) even when...

Aug 23, 2018 Risk IR Number: FG-IR-18-058
The OpenSSL project released an advisory on Jan 26th, 2017, describing 3 Moderate, 1 Low severity vulnerabilities, as listed below: CVE-2017-3731:...

Jul 13, 2018 Risk IR Number: FG-IR-17-019
Javascript code and HTML tags can be injected into the CN value of CA and CRL certificates via the import CA and CRL certificates...

Jul 05, 2018 Risk IR Number: FG-IR-17-305
An information disclosure vulnerability exists in the SSL-VPN web portal of FortiOS: when pages bookmarked in the web portal use...

Jun 22, 2018 Risk IR Number: FG-IR-18-027
An open redirect vulnerability exists in FortiAnalyzer and FortiManager when a user of the GUI is converting an HTML table to...

Jun 22, 2018 Risk IR Number: FG-IR-18-022
An improper access control vulnerability exists in FortiAnalyzer and FortiManager, whereby a regular user of the GUI can edit...

Jun 22, 2018 Risk IR Number: FG-IR-18-014
A potential Cross-site Scripting (XSS) vulnerability exists in FortiManager: Displayed data is not sanitized when an administrator...

Jun 22, 2018 Risk IR Number: FG-IR-18-006