PSIRT Advisories

Monthly PSIRT Advisories

The following is a list of advisories for issues resolved in Fortinet products. The resolution of such issues is coordinated by the Fortinet Product Security Incident Response Team (PSIRT), a dedicated, global team that manages the receipt, investigation, and public reporting of information about security vulnerabilities and issues related to Fortinet products and services.  

For details of how to raise a PSIRT Issue with Fortinet, please see our PSIRT Policy here.

A standard user with adom assignment can read the interface settings of vdoms unrelated to his/her adom.

FortiManager 6.0.1, 6.0.0, 5.6.9, 5.6.8, 5.6.7, 5.6.6, 5.6.5, 5.6.4, 5.6.3, 5.6.2, 5.6.11, 5.6.10, 5.6.1, 5.6.0
Aug 27, 2018 Risk IR Number: FG-IR-18-016 CVE-2018-1353
Before August, 2018, parameters at /loginmgrlogin in forticloud.com were vulnerable to a Cross-Site-Scripting (XSS) attack.

Aug 24, 2018 Risk IR Number: FG-IR-18-026
FortiCloud password reset link requested by the user takes one hour to expire even after password was changed successful...

Aug 24, 2018 Risk IR Number: FG-IR-18-074
The default replacement message in FortiOS' Application control block page reveals the private IP as well as the hostname ...

FortiOS 6.0.1, 6.0.0, 5.6.5, 5.6.4, 5.6.3, 5.6.2, 5.6.1, 5.6.0
Aug 23, 2018 Risk IR Number: FG-IR-18-085 CVE-2018-13365
FortiWeb's "Recursive URL Decoding" feature can detect URL-based attacks (among which XSS and SQL injection attempts) even...

Aug 23, 2018 Risk IR Number: FG-IR-18-058
The OpenSSL project released an advisory on Jan 26th, 2017, describing 3 Moderate, 1 Low severity vulnerabilities, as list...

Jul 13, 2018 Risk IR Number: FG-IR-17-019 CVE-2016-7055
Javascript code and HTML tags can be injected into the CN value of CA and CRL certificates via the import CA and CRL certi...

FortiManager 6.0.0, 5.6.4, 5.6.3, 5.6.2, 5.6.1, 5.6.0, 5.4.7, 5.4.6, 5.4.5, 5.4.4, 5.4.3, 5.4.2, 5.4.1, 5.4.0 FortiAnalyzer 6.0.0, 5.6.4, 5.6.3, 5.6.2, 5.6.1, 5.6.0, 5.4.7, 5.4.6, 5.4.5, 5.4.4, 5.4.3, 5.4.2, 5.4.1, 5.4.0
Jul 05, 2018 Risk IR Number: FG-IR-17-305 CVE-2017-17541
An information disclosure vulnerability exists in the SSL-VPN web portal of FortiOS: when pages bookmarked in the web port...

FortiOS 6.0.0, 5.6.5, 5.6.4, 5.6.2, 5.6.1, 5.6.0, 5.4.9, 5.4.8, 5.4.7, 5.4.6, 5.4.5, 5.4.4, 5.4.3, 5.4.2, 5.4.13, 5.4.12, 5.4.11, 5.4.10, 5.4.1, 5.4.0, 5.2.9, 5.2.8, 5.2.7, 5.2.6, 5.2.5, 5.2.4, 5.2.3, 5.2.2, 5.2.15, 5.2.14, 5.2.13, 5.2.12, 5.2.11, 5.2.10, 5.2.1, 5.2.0, 5.0.9, 5.0.8, 5.0.7, 5.0.6, 5.0.5, 5.0.4, 5.0.3, 5.0.2, 5.0.14, 5.0.13, 5.0.12, 5.0.11, 5.0.10, 5.0.1, 5.0.0
Jun 22, 2018 Risk IR Number: FG-IR-18-027 CVE-2018-9185
An open redirect vulnerability exists in FortiAnalyzer and FortiManager when a user of the GUI is converting an HTML table...

Jun 22, 2018 Risk IR Number: FG-IR-18-022 CVE-2018-1355
An improper access control vulnerability exists in FortiAnalyzer and FortiManager, whereby a regular user of the GUI can e...

Jun 22, 2018 Risk IR Number: FG-IR-18-014 CVE-2018-1354
A potential Cross-site Scripting (XSS) vulnerability exists in FortiManager: Displayed data is not sanitized when an admin...

FortiManager 6.0.0, 5.6.6, 5.6.5, 5.6.4, 5.6.3, 5.6.2, 5.6.1, 5.6.0, 5.4.7, 5.4.6, 5.4.5, 5.4.4, 5.4.3, 5.4.2, 5.4.1, 5.4.0
Jun 22, 2018 Risk IR Number: FG-IR-18-006 CVE-2018-1351
Multiple Denial of Service (DoS) or process crash vulnerabilities (CVE-2018-5737, CVE-2018-5736) are affecting ISC BIND.

Jun 05, 2018 Risk IR Number: FG-IR-18-112 CVE-2018-5736
On FortiAuthenticator, a HTML page is returned to the user when the CSRF validation fails on referer mismatch. This page d...

May 29, 2018 Risk IR Number: FG-IR-18-059 CVE-2018-9186
A SSL VPN user logged in via the web portal can access internal FortiOS configuration information (eg: addresses) via spec...

FortiOS 5.6.2, 5.6.1, 5.6.0, 5.4.8, 5.4.7, 5.4.6, 5.4.5, 5.4.4, 5.4.3, 5.4.2, 5.4.1, 5.4.0, 5.2.9, 5.2.8, 5.2.7, 5.2.6, 5.2.5, 5.2.4, 5.2.3, 5.2.2, 5.2.15, 5.2.14, 5.2.13, 5.2.12, 5.2.11, 5.2.10, 5.2.1, 5.2.0
May 18, 2018 Risk IR Number: FG-IR-17-231 CVE-2017-14185
An admin user with super_admin privileges can execute an arbitrary binary contained on an USB drive plugged to a FortiGate...

FortiOS 5.6.2, 5.6.1, 5.6.0, 5.4.8, 5.4.7, 5.4.6, 5.4.5, 5.4.4, 5.4.3, 5.4.2, 5.4.1, 5.4.0, 5.2.9, 5.2.8, 5.2.7, 5.2.6, 5.2.5, 5.2.4, 5.2.3, 5.2.2, 5.2.15, 5.2.14, 5.2.13, 5.2.12, 5.2.11, 5.2.10, 5.2.1, 5.2.0
May 18, 2018 Risk IR Number: FG-IR-17-245 CVE-2017-14187