PSIRT Advisories

Monthly PSIRT Advisories

The following is a list of advisories for issues resolved in Fortinet products. The resolution of such issues is coordinated by the Fortinet Product Security Incident Response Team (PSIRT), a dedicated, global team that manages the receipt, investigation, and public reporting of information about security vulnerabilities and issues related to Fortinet products and services.  

For details of how to raise a PSIRT Issue with Fortinet, please see our PSIRT Policy here.

A FortiGate configured to use flow-based protection will stop monitoring network sessions that are active when a scanning ...

FortiOS 5.4.1, 5.4.0, 5.2.9, 5.2.8, 5.2.7, 5.2.6, 5.2.5, 5.2.4, 5.2.3, 5.2.2, 5.2.15, 5.2.14, 5.2.13, 5.2.12, 5.2.11, 5.2.10, 5.2.1, 5.2.0, 5.0.9, 5.0.8, 5.0.7, 5.0.6, 5.0.5, 5.0.4, 5.0.3, 5.0.2, 5.0.14, 5.0.13, 5.0.12, 5.0.11, 5.0.10, 5.0.1, 5.0.0
Nov 22, 2016 Risk IR Number: FG-IR-16-088 CVE-2016-7541
When devices use ANSI X9.31 RNG (which was removed from the list of FIPS-approved random number generation algorithms in J...

Nov 22, 2016 Risk IR Number: FG-IR-16-067 CVE-2016-8492
BlackNurse is a Denial of Service attack consisting in flooding the target with ICMP Type 3 Code 3 packets. The latter typ...

Nov 15, 2016 Risk IR Number: FG-IR-16-091
The following products are confirmed to be not affected:FortiGate FortiAnalyzerFortiSwitchFortiAP For questions about othe...

Nov 09, 2016 Risk IR Number: FG-IR-16-063 CVE-2016-5195
FortiWLC comes with a hardcoded account named 'core' which is used by Meru Access Points to send core dumps to the FortiWL...

Nov 09, 2016 Risk IR Number: FG-IR-16-065 CVE-2016-8491