PSIRT Advisories
The FortiGuard Labs Product Security Incident Response Team (PSIRT) continually test Fortinet hardware and software products, looking for vulnerabilities and weaknesses. Any such findings are fed back to Fortinet's development teams and serious issues are described along with protective solutions in the advisories below.
OpenSSL released an update in May 2016 to address two high and four low severity vulnerabilities.CVE-2016-2108; CVE-2016-2107;...
When executed, the FortiClient installer (FortiClientOnlineInstaller.exe), if downloaded before August 11th, 2016 (build 0842),...
One of the processes in FortiClient stores VPN credentials unencrypted in memory. A malicious attacker who compromised the workstation...
FortWan 4.2.4 and below is exposed to cross site scripting, information leak and escalation of privilege vulnerabilities.CVE-2016-4965:...
FortiGate firmware (FortiOS) released before Aug 2012 has a cookie parser buffer overflow vulnerability. This vulnerability, when...
Forticloud online service before May 3, 2016 was exposed to cross site scripting web vulnerabilities, which could allow malicious...
A vulnerablity in FortiVoice 5.0 web-application could allow malicious script being injected in the affected module; this potentially...
An XSS vulnerablity in FortiManager/FortiAnalyzer could allow privileged guest user accounts and restricted user accounts to inject...
A vulnerablity in FortiManager/FortiAnalyzer address added page could allow malicious script being injected in the input field;...
A client side XSS vulnerablity in FortiManager/FortiAnalyzer could allow malicious script being injected in the Web-UI; this potentially...
When a low privileged user uploads images in the report section, the filenames are not properly sanitized; this potentially enables...
OpenSSL released an update in January 2016 to address one high and one low severity vulnerabilities.
During an upgrade to version 3.4.1, a FortiSwitch device may let an attacker
log in the rest_admin account without a password,...
There is a CSRF vulnerability with FortiWEB console on dashboard. Attackers may submit local forms to change admin password illegally.
A path traversal vulnerability allows an administrator account with read and write privileges to read arbitrary files using the...