PSIRT Advisories

The FortiGuard Labs Product Security Incident Response Team (PSIRT) continually test Fortinet hardware and software products, looking for vulnerabilities and weaknesses. Any such findings are fed back to Fortinet's development teams and serious issues are described along with protective solutions in the advisories below.

An XSS vulnerability caused by the scrintf parameter input during Firewall Policy Creation can be exploited to load and run a...

Apr 19, 2017 Risk IR Number: FG-IR-17-017
The Site Publisher functionality of FortiWeb has been found vulnerable to a Cross-Site Scripting vulnerability via an improperly...

Apr 19, 2017 Risk IR Number: FG-IR-17-076
The lack of input sanitisation for CLI command 'copy running-config' allows a user with 'admin' or 'superuser' privilege level...

Apr 12, 2017 Risk IR Number: FG-IR-17-097
A race condition in the tty_ioctl function in drivers/tty/tty_io.c in the Linux kernel may allow local users to obtain sensitive...

Apr 05, 2017 Risk IR Number: FG-IR-16-013
The first run of the FortiClient SSLVPN script results in the subproc file becoming suid & root owned binary. The issue lays in...

Apr 05, 2017 Risk IR Number: FG-IR-16-041
The first launch of FortiClient SSLVPN Linux creates a log file without any prior check. By previously creating a symbolic or...

Apr 05, 2017 Risk IR Number: FG-IR-16-069
Of multiple vulnerabilities released affecting Linux kernels through 4.6.3, FortiOS was found vulnerable to the following two:CVE-2016-3713CVE-2016-5829

Apr 05, 2017 Risk IR Number: FG-IR-16-052
An unauthenticated XSS vulnerability could allow an attacker to execute arbitrary scripts in the security context of the browser...

Apr 04, 2017 Risk IR Number: FG-IR-17-011
net/ipv4/tcp_input.c in certain Linux kernel versions does not properly determine the rate of challenge ACK segments, which makes...

Apr 04, 2017 Risk IR Number: FG-IR-16-047
The OpenSSL project released an advisory on Sept 22nd, 2016, describing 1 High, 1 Medium and 12 Low severity vulnerabilities,...

Apr 03, 2017 Risk IR Number: FG-IR-16-048
ntp released an announcement on 26th April 2016, describing 4 low and 7 medium severity vulnerabilities, as listed below: CVE-2016-1551CVE-2016-1549CVE-2016-2516CVE-2016-2517CVE-2016-2518CVE-2016-2519CVE-2016-1547CVE-2016-1548CVE-2015-7704...

Apr 03, 2017 Risk IR Number: FG-IR-16-035
A webui administrator may create a new theme that performs arbitrary code execution on the system.

Feb 09, 2017 Risk IR Number: FG-IR-16-080
FortiManager does not properly validate TLS certificates when probing for devices to administer. This leads to potential pre-shared...

Feb 08, 2017 Risk IR Number: FG-IR-16-055
A read-only administrator may have access to read-write administrators password hashes (not including super-admins) stored on...

Dec 02, 2016 Risk IR Number: FG-IR-16-050
A FortiGate configured to use flow-based protection will stop monitoring network sessions that are active when a scanning engine...

Nov 22, 2016 Risk IR Number: FG-IR-16-088