<?xml version="1.0" encoding="UTF-8"?>
<cvrf:cvrfdoc xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:cvrf-common="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/common" xmlns:cvrf="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/cvrf">
    <cvrf:DocumentTitle>FireStorm vulnerability</cvrf:DocumentTitle>
    <cvrf:DocumentType>Fortinet PSIRT Advisories</cvrf:DocumentType>
    <cvrf:DocumentPublisher Type="Vendor">
        <cvrf:ContactDetails>
            Fortinet PSIRT Contact:
            Website: https://fortiguard.fortinet.com/faq/psirt-contact
        </cvrf:ContactDetails>
     </cvrf:DocumentPublisher>
    <cvrf:DocumentTracking>
        <cvrf:Identification>
            <cvrf:ID>FG-IR-15-024</cvrf:ID>
        </cvrf:Identification>
        <cvrf:Status>Final</cvrf:Status>
        <cvrf:Version>1</cvrf:Version>
        <cvrf:RevisionHistory>
            <cvrf:Revision>
                <cvrf:Number>1</cvrf:Number>
                <cvrf:Date>2015-12-15T00:00:00</cvrf:Date>
                <cvrf:Description>Current version</cvrf:Description>
        </cvrf:Revision>
       </cvrf:RevisionHistory>
        <cvrf:InitialReleaseDate>2015-12-15T00:00:00</cvrf:InitialReleaseDate>
        <cvrf:CurrentReleaseDate>2015-12-15T00:00:00</cvrf:CurrentReleaseDate>
    </cvrf:DocumentTracking>
    <cvrf:DocumentNotes>
        <cvrf:Note Title="Summary" Type="Summary" Ordinal="1">
            None
        </cvrf:Note>
        <cvrf:Note Title="Description" Type="General" Ordinal="2">
            Researchers discovered that certain next generation firewalls are designed to permit full TCP handshake with any destination, regardless of firewall rules and client restrictions. They derive from this that they can exfiltrate data to a blacklisted IP (their example is a Botnet C&amp;C Server), by packing data in TCP handshake packets.
        </cvrf:Note>
        <cvrf:Note Title="Impact" Type="General" Ordinal="3">
            Firewall rules bypass
        </cvrf:Note>
        <cvrf:Note Title="Affected Products" Type="General" Ordinal="4">
            None. IP address filtering features of Fortinet products are not affected: Webfiltering: Not Applicable. Indeed Webfiltering is meant to block Web/HTTP access only. Not any other protocol, much less SYN packets. Firewall policies: Not vulnerable. Botnet Servers filtering: Not vulnerable.
        </cvrf:Note>
        <cvrf:Note Title="Solutions" Type="General" Ordinal="5">
            Enabling Botnet Servers filtering is done differently in FOS 5.4 and FOS 5.2: In 5.4, set &#34;Scan Outgoing Connections to Botnet Sites&#34; to &#34;Block&#34; in Network-&gt;Interfaces-&gt;Edit Interface In 5.2 , set &#34;Detect Connections to Botnet C&amp;C Servers&#34; to &#34;Block&#34; in Security Profiles -&gt; AntiVirus.
        </cvrf:Note>
    </cvrf:DocumentNotes>
    <cvrf:DocumentReferences>
        <cvrf:Reference>
            <cvrf:URL>https://fortiguard.fortinet.com/psirt/FG-IR-15-024</cvrf:URL>
            <cvrf:Description>FireStorm vulnerability</cvrf:Description>
        </cvrf:Reference>
        <cvrf:Reference>
            <cvrf:URL>http://www.cynet.com/blog/</cvrf:URL>
            <cvrf:Description>http://www.cynet.com/blog/</cvrf:Description>
        </cvrf:Reference>
    </cvrf:DocumentReferences>
    <Vulnerability Ordinal="1">
        <Title>FireStorm vulnerability</Title>
        <References Type="Self">
            <Reference>
                <URL>https://fortiguard.fortinet.com/psirt/FG-IR-15-024</URL>
                <Description>FireStorm vulnerability</Description>
            </Reference>Reference>
            <Reference>
                <URL>http://www.cynet.com/blog/</URL>
                <Description>http://www.cynet.com/blog/</Description>
            </Reference>
        </References>
    </Vulnerability>
</cvrf:cvrfdoc>