PSIRT Advisories

The FortiGuard Labs Product Security Incident Response Team (PSIRT) continually test Fortinet hardware and software products, looking for vulnerabilities and weaknesses. Any such findings are fed back to Fortinet's development teams and serious issues are described along with protective solutions in the advisories below.

A FortiGate configured to use flow-based protection will stop monitoring network sessions that are active when a scanning engine...

Nov 22, 2016 Risk IR Number: FG-IR-16-088
When devices use ANSI X9.31 RNG (which was removed from the list of FIPS-approved random number generation algorithms in January...

Nov 22, 2016 Risk IR Number: FG-IR-16-067
BlackNurse is a Denial of Service attack consisting in flooding the target with ICMP Type 3 Code 3 packets. The latter type of...

Nov 15, 2016 Risk IR Number: FG-IR-16-091
The following products are confirmed to be not affected:FortiGate FortiAnalyzerFortiSwitchFortiAP For questions about other Fortinet...

Nov 09, 2016 Risk IR Number: FG-IR-16-063
FortiWLC comes with a hardcoded account named 'core' which is used by Meru Access Points to send core dumps to the FortiWLC and...

Nov 09, 2016 Risk IR Number: FG-IR-16-065