PSIRT Advisories

The FortiGuard Labs Product Security Incident Response Team (PSIRT) continually test Fortinet hardware and software products, looking for vulnerabilities and weaknesses. Any such findings are fed back to Fortinet's development teams and serious issues are described along with protective solutions in the advisories below.

Several vulnerabilities affect the Wi-Fi Protected Access II (WPA2) protocol, potentially enabling Man-in-the-Middle (MitM) attacks...

Oct 16, 2017 Risk IR Number: FG-IR-17-196
The FortiWLC file management AP script download webUI page is affected by an OS Command Injection vulnerability which may allow...

Oct 13, 2017 Risk IR Number: FG-IR-17-119
The FortiWLC admin webUI is affected by XSS vulnerabilities, potentially exploitable by an authenticated user, via non-sanitized...

Oct 13, 2017 Risk IR Number: FG-IR-17-106
There exists a reflected cross-site scripting (XSS) vulnerability on FortiMail customized pre-authentication webmail login page,...

Oct 13, 2017 Risk IR Number: FG-IR-17-099
Multiple Remote Code Execution vulnerabilities (CVE-2017-9805, CVE-2017-9804, CVE-2017-9793) are affecting Apache Struts.

Sep 29, 2017 Risk IR Number: FG-IR-17-205
Server Message Block (SMB) 1.0 - a legacy file and print sharing protocol - has been deprecated by Microsoft due its potential...

Aug 11, 2017 Risk IR Number: FG-IR-17-103
The FortiOS IKE packets which include the Vendor ID embed the FortiOS build version number.

Aug 11, 2017 Risk IR Number: FG-IR-17-073
The HTML source code of the FortiWeb SNMPv3 user edit webui page includes the user's password in cleartext.

Aug 11, 2017 Risk IR Number: FG-IR-17-162
Three XSS vulnerabilities one via the the filter input in "Applications" under FortiView (CVE-2017-3131)the second via the action...

Jul 28, 2017 Risk IR Number: FG-IR-17-104
The LibGD project released advisories on January 18th, 2017, July 22nd, 2016 and June 25th, 2016 describing 12 vulnerabilities,...

Jul 26, 2017 Risk IR Number: FG-IR-17-051
FortiWLM has a hard-coded password for its "upgrade" user account, which it uses to transfer files to and from the FortiWLC controller....

Jun 30, 2017 Risk IR Number: FG-IR-17-115
Two XSS vulnerabilities were reported to us affecting FortiOS that can be exploited to load and run a remote (malicious) Javascript...

Jun 15, 2017 Risk IR Number: FG-IR-17-127
FortiOS is subject to a Cross-Site Scripting vulnerability, due to an improperly sanitized parameter in a hidden CLI configuration...

May 17, 2017 Risk IR Number: FG-IR-17-057
Multiple vulnerabilities impacting FortiPortal were disclosed to Fortinet with details as follows:CVE-2017-7337: Improper Access...

May 15, 2017 Risk IR Number: FG-IR-17-114
The FortiAnalyzer and FortiManager WebUI accept a user-controlled input that specifies a link to an external site, and uses that...

Apr 26, 2017 Risk IR Number: FG-IR-17-014