PSIRT Advisories

The FortiGuard Labs Product Security Incident Response Team (PSIRT) continually test Fortinet hardware and software products, looking for vulnerabilities and weaknesses. Any such findings are fed back to Fortinet's development teams and serious issues are described along with protective solutions in the advisories below.

FortiOS VM appliance lack of root file system integrity check may allow an attacker with read/write access to the VM image (before...

May 17, 2019 Risk IR Number: FG-IR-19-017
Failure to properly parse message payloads in the SSL VPN portal of FortiOS may allow a non-authenticated attacker to perform...

May 17, 2019 Risk IR Number: FG-IR-18-387
Failure to sanitize input in the customized data pattern webpage of FortiCASB  may allow an authenticated attacker to conduct...

May 15, 2019 Risk IR Number: FG-IR-19-001
Some FortiAP models are vulnerable to the Bleeding Bit Vulnerability (CVE-2018-16986) present in the Texas Instruments WiFi chips.CVE-2018-16986:Texas...

Apr 10, 2019 Risk IR Number: FG-IR-18-356
FortiSwitch is vulnerable to multiple Cross-site Scripting (XSS) attacks present in the jQuery javascript libraryCVE-2015-9251:jQuery...

Apr 10, 2019 Risk IR Number: FG-IR-18-013
A reflected Cross-Site-Scripting (XSS) vulnerability in Fortinet FortiSandbox may allow an attacker to execute unauthorized code...

Apr 03, 2019 Risk IR Number: FG-IR-18-024
An improper access control vulnerability in FortiClientMac may allow an attacker to affect the application's performance via modifying...

Apr 02, 2019 Risk IR Number: FG-IR-19-003
Multiple information exposure vulnerabilities in FortiOS may allow an unauthenticated attacker to perform some information gathering...

Mar 29, 2019 Risk IR Number: FG-IR-19-043
The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday...

Feb 07, 2019 Risk IR Number: FG-IR-17-173
A researcher has disclosed several vulnerabilities against FortiClient for Windows, the combination of these vulnerabilities can...

Dec 22, 2018 Risk IR Number: FG-IR-18-108
An attacker could send DHCP request containing malicious scripts in the HOSTNAME parameter. The malicious script code is executed...

Nov 16, 2018 Risk IR Number: FG-IR-18-121
Two new attacks on IPsec IKE (Internet Key Exchange) were recently disclosed [1], involving multiple ways to perform attacks against...

Aug 27, 2018 Risk IR Number: FG-IR-18-214
A plaintext recovery of encrypted messages or a Man-in-the-middle (MiTM) attack on RSA PKCS #1 v1.5 encryption may be possible...

Aug 27, 2018 Risk IR Number: FG-IR-17-302
Before August, 2018, parameters at /loginmgrlogin in forticloud.com were vulnerable to a Cross-Site-Scripting (XSS) attack.

Aug 24, 2018 Risk IR Number: FG-IR-18-026
FortiWeb's "Recursive URL Decoding" feature can detect URL-based attacks (among which XSS and SQL injection attempts) even when...

Aug 23, 2018 Risk IR Number: FG-IR-18-058