PSIRT Advisories

The FortiGuard Labs Product Security Incident Response Team (PSIRT) continually test Fortinet hardware and software products, looking for vulnerabilities and weaknesses. Any such findings are fed back to Fortinet's development teams and serious issues are described along with protective solutions in the advisories below.

Server Message Block (SMB) 1.0 - a legacy file and print sharing protocol - has been deprecated by Microsoft due its potential...

Aug 11, 2017 Risk IR Number: FG-IR-17-103
Three XSS vulnerabilities one via the the filter input in "Applications" under FortiView (CVE-2017-3131)the second via the action...

Jul 28, 2017 Risk IR Number: FG-IR-17-104
The LibGD project released advisories on January 18th, 2017, July 22nd, 2016 and June 25th, 2016 describing 12 vulnerabilities,...

Jul 26, 2017 Risk IR Number: FG-IR-17-051
The Site Publisher functionality of FortiWeb has been found vulnerable to a Cross-Site Scripting vulnerability via an improperly...

Apr 19, 2017 Risk IR Number: FG-IR-17-076
An unauthenticated XSS vulnerability could allow an attacker to execute arbitrary scripts in the security context of the browser...

Apr 04, 2017 Risk IR Number: FG-IR-17-011
net/ipv4/tcp_input.c in certain Linux kernel versions does not properly determine the rate of challenge ACK segments, which makes...

Apr 04, 2017 Risk IR Number: FG-IR-16-047
The OpenSSL project released an advisory on Sept 22nd, 2016, describing 1 High, 1 Medium and 12 Low severity vulnerabilities,...

Apr 03, 2017 Risk IR Number: FG-IR-16-048
A webui administrator may create a new theme that performs arbitrary code execution on the system.

Feb 09, 2017 Risk IR Number: FG-IR-16-080
A read-only administrator may have access to read-write administrators password hashes (not including super-admins) stored on...

Dec 02, 2016 Risk IR Number: FG-IR-16-050
A FortiGate configured to use flow-based protection will stop monitoring network sessions that are active when a scanning engine...

Nov 22, 2016 Risk IR Number: FG-IR-16-088
FortiOS 4.3 used to implement the ANSI X9.31 RNG to decrypt TLS/IPSec traffic.It is now superseded by the CTR_DRBG implementation...

Nov 22, 2016 Risk IR Number: FG-IR-16-067
BlackNurse is a Denial of Service attack consisting in flooding the target with ICMP Type 3 Code 3 packets. The latter type of...

Nov 15, 2016 Risk IR Number: FG-IR-16-091
The following products are confirmed to be not affected:FortiGate FortiAnalyzerFortiSwitchFortiAP For questions about other Fortinet...

Nov 09, 2016 Risk IR Number: FG-IR-16-063
OpenSSL released an update in May 2016 to address two high and four low severity vulnerabilities.CVE-2016-2108; CVE-2016-2107;...

Sep 22, 2016 Risk IR Number: FG-IR-16-026
When executed, the FortiClient installer (FortiClientOnlineInstaller.exe), if downloaded before August 11th, 2016 (build 0842),...

Sep 12, 2016 Risk IR Number: FG-IR-16-046