<?xml version="1.0" encoding="UTF-8"?>
<cvrf:cvrfdoc xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:cvrf-common="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/common" xmlns:cvrf="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/cvrf">
    <cvrf:DocumentTitle>FortiOS flow-mode detection bypass under certain conditions</cvrf:DocumentTitle>
    <cvrf:DocumentType>Fortinet PSIRT Advisories</cvrf:DocumentType>
    <cvrf:DocumentPublisher Type="Vendor">
        <cvrf:ContactDetails>
            Fortinet PSIRT Contact:
            Website: https://fortiguard.fortinet.com/faq/psirt-contact
        </cvrf:ContactDetails>
     </cvrf:DocumentPublisher>
    <cvrf:DocumentTracking>
        <cvrf:Identification>
            <cvrf:ID>FG-IR-16-088</cvrf:ID>
        </cvrf:Identification>
        <cvrf:Status>Final</cvrf:Status>
        <cvrf:Version>1</cvrf:Version>
        <cvrf:RevisionHistory>
            <cvrf:Revision>
                <cvrf:Number>1</cvrf:Number>
                <cvrf:Date>2016-11-22T00:00:00</cvrf:Date>
                <cvrf:Description>Current version</cvrf:Description>
        </cvrf:Revision>
       </cvrf:RevisionHistory>
        <cvrf:InitialReleaseDate>2016-11-22T00:00:00</cvrf:InitialReleaseDate>
        <cvrf:CurrentReleaseDate>2016-11-22T00:00:00</cvrf:CurrentReleaseDate>
    </cvrf:DocumentTracking>
    <cvrf:DocumentNotes>
        <cvrf:Note Title="Summary" Type="Summary" Ordinal="1">
            A FortiGate configured to use flow-based protection will stop monitoringnetwork sessions that are active when a scanning engine isreloaded after an update (nearly instantaneous process).This tends to impact long lived network sessions, with chances to be aliveduring and after an update, such as SMBv3 sessions.
        </cvrf:Note>
        <cvrf:Note Title="Description" Type="General" Ordinal="2">
            A FortiGate configured to use flow-based protection will stop monitoring network sessions that are active when a scanning engine is reloaded after an update (nearly instantaneous process).This tends to impact long lived network sessions, with chances to be alive during and after an update, such as SMBv3 sessions.
        </cvrf:Note>
        <cvrf:Note Title="Impact" Type="General" Ordinal="3">
            Improper access control
        </cvrf:Note>
        <cvrf:Note Title="Affected Products" Type="General" Ordinal="4">
            FortiOS version 5.0.xFortiOS version 5.2.x
        </cvrf:Note>
        <cvrf:Note Title="Solutions" Type="General" Ordinal="5">
            FortiGates in routed mode:Upgrade to FortiOS 5.4.0 or above, or stay in proxy-based protection mode (default).FortiGates in transparent mode:Upgrade to FortiOS 5.4.0 or above.For FortiOS 5.2 branch:Load FortiOS 5.2 compatible[] IPS engine 3.299 or above.[] Reach out to your local TAC for the compatibility support.
        </cvrf:Note>
    </cvrf:DocumentNotes>
    <cvrf:Acknowledgments>
        <cvrf:Acknowledgment>
            <cvrf:Description>We are pleased to thank Yves Bieri, Stefan Frei, Christof Jungo of the Swisscom security group, who discovered the issue while it was in the process of being fixed, and committed to responsible disclosure.</cvrf:Description>
        </cvrf:Acknowledgment>
    </cvrf:Acknowledgments>
    <Vulnerability Ordinal="1">
        <Title>FortiOS flow-mode detection bypass under certain conditions</Title>
        <cvrf:CVE>CVE-2016-7541</cvrf:CVE>
        <CVSSScoreSets>
            <ScoreSetV3>
                <BaseScoreV3>4.9</BaseScoreV3>
                <VectorV3>CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:U/RL:X/RC:X</VectorV3>
            </ScoreSetV3>
        </CVSSScoreSets>
        <References Type="Self">
            <Reference>
                <URL>https://fortiguard.fortinet.com/psirt/FG-IR-16-088</URL>
                <Description>FortiOS flow-mode detection bypass under certain conditions</Description>
            </Reference>Reference>
        </References>
    </Vulnerability>
</cvrf:cvrfdoc>