PSIRT Advisories

The FortiGuard Labs Product Security Incident Response Team (PSIRT) continually test Fortinet hardware and software products, looking for vulnerabilities and weaknesses. Any such findings are fed back to Fortinet's development teams and serious issues are described along with protective solutions in the advisories below.

An information exposure vulnerability in the admin portal of FortiSIEM may allow an authenticated admin to retrieve the LDAP server...

Mar 29, 2019 Risk IR Number: FG-IR-18-382
The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday...

Feb 07, 2019 Risk IR Number: FG-IR-17-173
There is a format string vulnerability in the SSH username handling when connecting to FortiOS 5.6.0, that may lead to memory...

Jan 11, 2019 Risk IR Number: FG-IR-18-018
There is a Null pointer dereference in the NDIS Miniport drivers in FortiClient on Windows, which may be leveraged by an unprivileged...

Jan 11, 2019 Risk IR Number: FG-IR-18-092
A researcher has disclosed several vulnerabilities against FortiClient for Windows, the combination of these vulnerabilities can...

Dec 22, 2018 Risk IR Number: FG-IR-18-108
An uninitialized memory buffer leak exists in FortiOS web proxy's disclaimer response web pages, potentially causing sensitive...

Nov 22, 2018 Risk IR Number: FG-IR-18-325
New types of side channel attacks impact most processors including Intel, AMD, ARM, etc. These attacks allow malicious userspace...

Nov 22, 2018 Risk IR Number: FG-IR-18-002
libssh versions 0.6 and above have an authentication bypass vulnerability inthe server code. By presenting the server an SSH2_MSG_USERAUTH_SUCCESS...

Nov 21, 2018 Risk IR Number: FG-IR-18-336
An attacker could send DHCP request containing malicious scripts in the HOSTNAME parameter. The malicious script code is executed...

Nov 16, 2018 Risk IR Number: FG-IR-18-121
Fortigate PPTP service reveals serial number of FortiGate in the hostname field defined in connection control setup packets of...

Nov 16, 2018 Risk IR Number: FG-IR-18-101
Fortigate's read-only admins are able to point a LDAP server connectivity test request to a rogue LDAP server instead of the configured...

Nov 16, 2018 Risk IR Number: FG-IR-18-157
Makers of popular wifi hacking tool hashcat have discovered a way to improve WPA/WPA2 password brute-forcing: Leveraging the PMKID...

Sep 10, 2018 Risk IR Number: FG-IR-18-199
Two new attacks on IPsec IKE (Internet Key Exchange) were recently disclosed [1], involving multiple ways to perform attacks against...

Aug 27, 2018 Risk IR Number: FG-IR-18-214
A plaintext recovery of encrypted messages or a Man-in-the-middle (MiTM) attack on RSA PKCS #1 v1.5 encryption may be possible...

Aug 27, 2018 Risk IR Number: FG-IR-17-302
On May 23, 2018, Talos disclosed in a blog post the discovery of a modular malware system they deemed "VPNFilter", affecting multiple...

Aug 27, 2018 Risk IR Number: FG-IR-18-106