This application requires Javascript for optimal performance.

New Vulnerability Coverage - Aug 30, 2010

Threat TypeMultiple Vulnerabilities
IPS Definition
DB Versions
2.849 - 2.856
Coverage Release DateAug 17, 2010 - Aug 27, 2010
Published DateMonday, August 30, 2010
Version #1
  
SeverityNumber of
Vulnerabilities
Active
Exploitation
Critical213
High254
Medium93
Low11
Info4n/a
Total6011

Foreword


The FortiGuard Global Threat Research Team has released new security content to cover multiple vulnerabilities. The FortiGuard Team has observed 11 active exploitations of these vulnerabilities to date.

For more information, visit the FortiGuard Center at www.fortiguardcenter.com.


Threat Remediation


Fortinet provides coverage for the vulnerabilities described below as of the 2.856 IPS Definitions database update. A brief description of each vulnerability is provided as follows, in order of severity.

 Critical ( 16 )

 High ( 15 )

 Medium ( 9 )


red arrow up Top of Section

Enhanced Coverage


The FortiGuard Threat Research team updates security content as new vectors of exploitation are discovered. The table below details the security content enhanced with this release.

plus  Critical ( 36 )

plus  High ( 54 )

plus  Medium ( 9 )

plus  Low ( 1 )

plus  Info ( 4 )


red arrow up Top of Section

Active Exploitation


The FortiGuard Threat Research team uses globally distributed probes to monitor exploit activity. Vulnerabilities can be classified as active and given a magnitude level. The magnitude level is the rate of activity across the probes. The value of the magnitude is set to low, medium or high.

The table below lists the vulnerabilities discussed in this bulletin (specifically new and enhanced detection) and their corresponding exploit activity magnitude. The data below is as of this writing.

plus  Critical ( 3 of 21 )

plus  High ( 4 of 24 )

plus  Medium ( 2 of 9 )


red arrow up Top of Section

Document History

Revision DateVersion Number
Monday, August 30, 20101Initial Documentation.


About Fortinet ( www.fortinet.com )

Fortinet is the pioneer and leading provider of ASIC-accelerated unified threat management, or UTM, security systems, which are used by enterprises and service providers to increase their security while reducing total operating costs. Fortinet solutions were built from the ground up to integrate multiple levels of security protection--including firewall, antivirus, intrusion prevention, VPN, spyware prevention and anti-spam -- designed to help customers protect against network and content level threats. Leveraging a custom ASIC and unified interface, Fortinet solutions offer advanced security functionality that scales from remote office to chassis-based solutions with integrated management and reporting. Fortinet solutions have won multiple awards around the world and are the only security products that are certified in six programs by ICSA Labs: (Firewall, Antivirus, IPSec, SSL, Network IPS, and Anti-Spyware). Fortinet is privately held and based in Sunnyvale, California.

Disclaimer

Although Fortinet has attempted to provide accurate information in these materials, Fortinet assumes no legal responsibility for the accuracy or completeness of the information. Please note that no Fortinet statements herein constitute or contain any guarantee, warranty or legally binding representation. All materials contained in this publication are subject to change without notice, and Fortinet reserves the right to change, modify, transfer, or otherwise revise this publication without notice.


red arrow up Top of page