PSIRT Advisories

Monthly PSIRT Advisories

The following is a list of advisories for issues resolved in Fortinet products. The resolution of such issues is coordinated by the Fortinet Product Security Incident Response Team (PSIRT), a dedicated, global team that manages the receipt, investigation, and public reporting of information about security vulnerabilities and issues related to Fortinet products and services.  

For details of how to raise a PSIRT Issue with Fortinet, please see our PSIRT Policy here.

A race condition in the tty_ioctl function in drivers/tty/tty_io.c in the Linux kernel may allow local users to obtain sen...

Apr 05, 2017 Risk IR Number: FG-IR-16-013 CVE-2016-0723
The first run of the FortiClient SSLVPN script results in the subproc file becoming  suid & root owned binary. The issue l...

Apr 05, 2017 Risk IR Number: FG-IR-16-041 CVE-2016-8497
The first launch of FortiClient SSLVPN Linux creates a log file without any prior check. By previously creating a symbolic...

Apr 05, 2017 Risk IR Number: FG-IR-16-069 CVE-2016-8496
Of multiple vulnerabilities released affecting Linux kernels through 4.6.3, FortiOS was found vulnerable to the following ...

Apr 05, 2017 Risk IR Number: FG-IR-16-052 CVE-2016-3713
An unauthenticated XSS vulnerability could allow an attacker to execute arbitrary scripts in the security context of the b...

FortiMail 5.3.8, 5.3.7, 5.3.6, 5.3.5, 5.3.4, 5.3.3, 5.3.2, 5.3.1, 5.3.0, 5.2.9, 5.2.8, 5.2.7, 5.2.6, 5.2.5, 5.2.4, 5.2.3, 5.2.2, 5.2.1, 5.2.0, 5.1.6, 5.1.5, 5.1.4, 5.1.3, 5.1.2, 5.1.1, 5.1.0, 5.0.9, 5.0.8, 5.0.7, 5.0.6, 5.0.5, 5.0.4, 5.0.3, 5.0.2, 5.0.11, 5.0.10, 5.0.1, 5.0.0
Apr 04, 2017 Risk IR Number: FG-IR-17-011 CVE-2017-3125
net/ipv4/tcp_input.c in certain Linux kernel versions does not properly determine the rate of challenge ACK segments, whic...

Apr 04, 2017 Risk IR Number: FG-IR-16-047 CVE-2016-5696
The OpenSSL project released an advisory on Sept 22nd, 2016, describing 1 High, 1 Medium and 12 Low severity vulnerabiliti...

Apr 03, 2017 Risk IR Number: FG-IR-16-048 CVE-2016-2177
ntp released an announcement on 26th April 2016, describing 4 low and 7 medium severity vulnerabilities, as listed below: ...

Apr 03, 2017 Risk IR Number: FG-IR-16-035 CVE-2015-7704
A webui administrator may create a new theme that performs arbitrary code execution on the system.

Feb 09, 2017 Risk IR Number: FG-IR-16-080 CVE-2016-8494
FortiManager does not properly validate TLS certificates when probing for devices to administer. This leads to potential p...

Feb 08, 2017 Risk IR Number: FG-IR-16-055 CVE-2016-8495
A read-only administrator may have access to read-write administrators password hashes (not including super-admins) stored...

FortiOS 5.4.1, 5.4.0, 5.2.9, 5.2.8, 5.2.7, 5.2.6, 5.2.5, 5.2.4, 5.2.3, 5.2.2, 5.2.10, 5.2.1, 5.2.0
Dec 02, 2016 Risk IR Number: FG-IR-16-050 CVE-2016-7542
A FortiGate configured to use flow-based protection will stop monitoring network sessions that are active when a scanning ...

FortiOS 5.4.1, 5.4.0, 5.2.9, 5.2.8, 5.2.7, 5.2.6, 5.2.5, 5.2.4, 5.2.3, 5.2.2, 5.2.15, 5.2.14, 5.2.13, 5.2.12, 5.2.11, 5.2.10, 5.2.1, 5.2.0, 5.0.9, 5.0.8, 5.0.7, 5.0.6, 5.0.5, 5.0.4, 5.0.3, 5.0.2, 5.0.14, 5.0.13, 5.0.12, 5.0.11, 5.0.10, 5.0.1, 5.0.0
Nov 22, 2016 Risk IR Number: FG-IR-16-088 CVE-2016-7541
When devices use ANSI X9.31 RNG (which was removed from the list of FIPS-approved random number generation algorithms in J...

Nov 22, 2016 Risk IR Number: FG-IR-16-067 CVE-2016-8492
BlackNurse is a Denial of Service attack consisting in flooding the target with ICMP Type 3 Code 3 packets. The latter typ...

Nov 15, 2016 Risk IR Number: FG-IR-16-091
The following products are confirmed to be not affected:FortiGate FortiAnalyzerFortiSwitchFortiAP For questions about othe...

Nov 09, 2016 Risk IR Number: FG-IR-16-063 CVE-2016-5195