PSIRT Advisories
The following is a list of advisories for issues resolved in Fortinet products. The resolution of such issues is coordinated by the Fortinet Product Security Incident Response Team (PSIRT), a dedicated, global team that manages the receipt, investigation, and public reporting of information about security vulnerabilities and issues related to Fortinet products and services.
For details of how to raise a PSIRT Issue with Fortinet, please see our PSIRT Policy here.
FortiWeb 5.0.2 and lower are vulnerable to cross-site scripting (CVE-2014-1955), HTTP header injection (CVE-2014-1956) and privilege...
FortiOS 5.0.5 and earlier versions contain a cross-site scripting vulnerability. The mkey parameter in the URL /firewall/schedule/recurrdlg...
Fortiweb 5.0.3 and earlier versions contain a cross-site scripting vulnerability. The filter parameter in the URL "/user/ldap_user/add"...
Authenticated administrative users can store injected Javascript content into a specific field on the web management interface....
Authenticated admin users may be able to obtain access to a system shell from the command line interface.
Multiple CSRF vulnerabilities exist in the FortiAnalyzer web administration console due to an error in CSRF token validation....
Multiple CSRF (Cross-Site Request Forgery) vulnerabilities exist in FortiGate because GUI pages are not protected by CSRF token....
Improper Guest User Permission Management issue exists in FortiGate.
Under certain conditions, FortiClient VPN may be susceptible to a certificate validation vulnerability which would allow an attacker...
Input filter bypass and exception handling vulnerabilities can be used by an attacker to hijack administrator or customer sessions...
FortiDB does not sanitize user input properly under limited circumstances. The vulnerability could allow an attacker to inject...
FortiWeb does not sanitize user input properly under limited circumstances. The vulnerability could allow an attacker to inject...
FortiWeb fails to sanitize user input. The vulnerability allows an attacker to inject script code.
FortiMail fails to sanitize user input. The vulnerability allows an attacker to bypass its input filtering routine, which could...
Vulnerability-lab.com publicly released news of discovered vulnerabilities discovered in FortiGate UTM WAF Appliances platforms.