• Filter by Date
  • Filter by Risk
  • Filter by Affected Product

PSIRT Advisories

The FortiGuard Labs Product Security Incident Response Team (PSIRT) continually test Fortinet hardware and software products, looking for vulnerabilities and weaknesses. Any such findings are fed back to Fortinet's development teams and serious issues are described along with protective solutions in the advisories below.

A Host Header Redirection vulnerability exists in FortiOS SSL-VPN web portal: when an attacker submits specially crafted HTTP...

May 17, 2019 Risk IR Number: FG-IR-19-002
FortiOS VM appliance lack of root file system integrity check may allow an attacker with read/write access to the VM image (before...

May 17, 2019 Risk IR Number: FG-IR-19-017
Failure to properly parse message payloads in the SSL VPN portal of FortiOS may allow a non-authenticated attacker to perform...

May 17, 2019 Risk IR Number: FG-IR-18-387
A heap buffer overflow vulnerability in the FortiOS SSL VPN web portal may cause the SSL VPN web service termination for logged...

May 17, 2019 Risk IR Number: FG-IR-18-388
An Unsafe Search Path vulnerability in FortiClient Online Installer may allow an unauthenticated, remote attacker with control...

May 16, 2019 Risk IR Number: FG-IR-19-060
Failure to sanitize input in the customized data pattern webpage of FortiCASB  may allow an authenticated attacker to conduct...

May 15, 2019 Risk IR Number: FG-IR-19-001