PSIRT Advisories

The FortiGuard Labs Product Security Incident Response Team (PSIRT) continually test Fortinet hardware and software products, looking for vulnerabilities and weaknesses. Any such findings are fed back to Fortinet's development teams and serious issues are described along with protective solutions in the advisories below.

An unauthenticated XSS vulnerability could allow an attacker to execute arbitrary scripts in the security context of the browser...

Apr 04, 2017 Risk IR Number: FG-IR-17-011

Apr 04, 2017 Risk IR Number: FG-IR-16-047

Apr 03, 2017 Risk IR Number: FG-IR-16-048

Apr 03, 2017 Risk IR Number: FG-IR-16-035

Feb 09, 2017 Risk IR Number: FG-IR-16-080
FortiManager does not properly validate TLS certificates when probing for devices to administer. This leads to potential pre-shared...

Feb 08, 2017 Risk IR Number: FG-IR-16-055
A read-only administrator may have access to read-write administrators password hashes (not including super-admins) stored on...

Dec 02, 2016 Risk IR Number: FG-IR-16-050
A FortiGate configured to use flow-based protection will stop monitoring network sessions that are active when a scanning engine...

Nov 22, 2016 Risk IR Number: FG-IR-16-088

Nov 22, 2016 Risk IR Number: FG-IR-16-067
BlackNurse is a Denial of Service attack consisting in flooding the target with ICMP Type 3 Code 3 packets. The latter type of...

Nov 15, 2016 Risk IR Number: FG-IR-16-091
The following products are confirmed to be not affected:FortiGate FortiAnalyzerFortiSwitchFortiAP For questions about other Fortinet...

Nov 09, 2016 Risk IR Number: FG-IR-16-063

Nov 09, 2016 Risk IR Number: FG-IR-16-065
The pam.log file generated by FortiWLC contains authenticated users credentials (local admin and users authenticated against external...

Sep 30, 2016 Risk IR Number: FG-IR-16-030
FortiWLC runs a rsyncd server, historically used for High-Availability purpose. This server comes with a hardcoded account, which...

Sep 30, 2016 Risk IR Number: FG-IR-16-029