PSIRT Advisories

The FortiGuard Labs Product Security Incident Response Team (PSIRT) continually test Fortinet hardware and software products, looking for vulnerabilities and weaknesses. Any such findings are fed back to Fortinet's development teams and serious issues are described along with protective solutions in the advisories below.

Multiple Fortinet products may be affected by the following Linux Kernel vulnerability:CVE-2016-10229 Linux Kernel ipv4/udp.c...

Jul 24, 2019 Risk IR Number: FG-IR-17-118
FortiOS by default enables TCP timestamp response, which may lead to information disclosure.The TCP timestamp response can be...

Jul 24, 2019 Risk IR Number: FG-IR-16-090
Multiple padding oracle vulnerabilities (Zombie POODLE, GOLDENDOODLE, OpenSSL 0-length) in the CBC padding implementation of FortiOS...

Jul 23, 2019 Risk IR Number: FG-IR-19-145
Makers of popular wifi hacking tool hashcat have discovered a way to improve WPA/WPA2 password brute-forcing: Leveraging the PMKID...

Jul 23, 2019 Risk IR Number: FG-IR-18-199
Certificates taken out of service could potentially be improperly re-used. Impact detailFortinet has already taken steps to mitigate...

Jul 19, 2019 Risk IR Number: FG-IR-19-144
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") in FortiNAC admin webUI may allow an unauthenticated...

Jul 16, 2019 Risk IR Number: FG-IR-19-140
The URL part of the report message is not encoded in Fortinet FortiWeb which may allow an attacker to execute unauthorized code...

Jun 12, 2019 Risk IR Number: FG-IR-19-070
Server Message Block (SMB) 1.0 - a legacy file and print sharing protocol - has been deprecated by Microsoft due to multiple weaknesses...

Jun 04, 2019 Risk IR Number: FG-IR-17-103
Failure to sanitize the error or message handling parameters in the SSL VPN web portal may allow an attacker to perform a Cross-site...

May 24, 2019 Risk IR Number: FG-IR-18-383
Failure to sanitize the login redir parameter in the SSL-VPN web portal may allow an attacker to perform a Cross-site Scripting...

May 24, 2019 Risk IR Number: FG-IR-17-242
A Host Header Redirection vulnerability exists in FortiOS SSL-VPN web portal: when an attacker submits specially crafted HTTP...

May 17, 2019 Risk IR Number: FG-IR-19-002
Failure to properly parse message payloads in the SSL VPN portal of FortiOS may allow a non-authenticated attacker to perform...

May 17, 2019 Risk IR Number: FG-IR-18-387
An Unsafe Search Path vulnerability in FortiClient Online Installer may allow an unauthenticated, remote attacker with control...

May 16, 2019 Risk IR Number: FG-IR-19-060
Failure to sanitize input in the customized data pattern webpage of FortiCASB  may allow an authenticated attacker to conduct...

May 15, 2019 Risk IR Number: FG-IR-19-001
The Missing Encryption Of Sensitive Data vulnerability in FortiClient may allow an attacker to access VPN session cookie from...

Apr 23, 2019 Risk IR Number: FG-IR-19-110