PSIRT Advisories

Monthly PSIRT Advisories

The following is a list of advisories for issues resolved in Fortinet products. The resolution of such issues is coordinated by the Fortinet Product Security Incident Response Team (PSIRT), a dedicated, global team that manages the receipt, investigation, and public reporting of information about security vulnerabilities and issues related to Fortinet products and services.  

For details of how to raise a PSIRT Issue with Fortinet, please see our PSIRT Policy here.

There exists a reflected cross-site scripting (XSS) vulnerability on FortiMail customized pre-authentication webmail login...

Oct 13, 2017 Severity light-circle-logo light-circle-logo light-circle-logo light-circle-logo light-circle-logo Medium IR Number: FG-IR-17-099 CVE-2017-7732
Multiple Remote Code Execution vulnerabilities (CVE-2017-9805, CVE-2017-9804, CVE-2017-9793) are affecting Apache Struts.

Sep 29, 2017 Severity light-circle-logo light-circle-logo light-circle-logo light-circle-logo light-circle-logo Critical IR Number: FG-IR-17-205 CVE-2017-9805
The FortiOS IKE packets which include the Vendor ID embed the FortiOS build version number.

FortiOS 5.6.0, 5.4.4, 5.4.3, 5.4.2, 5.4.1, 5.4.0, 5.2.9, 5.2.8, 5.2.7, 5.2.6, 5.2.5, 5.2.4, 5.2.3, 5.2.2, 5.2.11, 5.2.10, 5.2.1, 5.2.0, 5.0.9, 5.0.8, 5.0.7, 5.0.6, 5.0.5, 5.0.4, 5.0.3, 5.0.2, 5.0.14, 5.0.13, 5.0.12, 5.0.11, 5.0.10, 5.0.1, 5.0.0
Aug 11, 2017 Severity light-circle-logo light-circle-logo light-circle-logo light-circle-logo light-circle-logo Informational IR Number: FG-IR-17-073 CVE-2017-3130
The HTML source code of the FortiWeb SNMPv3 user edit webui page includes the user's password in cleartext.

Aug 11, 2017 Severity light-circle-logo light-circle-logo light-circle-logo light-circle-logo light-circle-logo Informational IR Number: FG-IR-17-162 CVE-2017-7737
Three XSS vulnerabilities one via the the filter input in "Applications" under FortiView (CVE-2017-3131)the second via the...

Jul 28, 2017 Severity light-circle-logo light-circle-logo light-circle-logo light-circle-logo light-circle-logo Medium IR Number: FG-IR-17-104 CVE-2017-3131
The LibGD project released advisories on January 18th, 2017, July 22nd, 2016 and June 25th, 2016 describing 12 vulnerabili...

Jul 26, 2017 Severity light-circle-logo light-circle-logo light-circle-logo light-circle-logo light-circle-logo Medium IR Number: FG-IR-17-051 CVE-2016-9317
FortiWLM has a hard-coded password for its "upgrade" user account, which it uses to transfer files to and from the FortiWL...

Jun 30, 2017 Severity light-circle-logo light-circle-logo light-circle-logo light-circle-logo light-circle-logo Critical IR Number: FG-IR-17-115 CVE-2017-7336
Two XSS vulnerabilities were reported to us affecting FortiOS that can be exploited to load and run a remote (malicious) J...

Jun 15, 2017 Severity light-circle-logo light-circle-logo light-circle-logo light-circle-logo light-circle-logo Low IR Number: FG-IR-17-127 CVE-2017-7734
FortiOS is subject to a Cross-Site Scripting vulnerability,  due to an improperly sanitized parameter in a hidden CLI conf...

FortiOS 5.2.9, 5.2.8, 5.2.7, 5.2.6, 5.2.5, 5.2.4, 5.2.3, 5.2.2, 5.2.10, 5.2.1, 5.2.0, 5.0.9, 5.0.8, 5.0.7, 5.0.6, 5.0.5, 5.0.4, 5.0.3, 5.0.2, 5.0.14, 5.0.13, 5.0.12, 5.0.11, 5.0.10, 5.0.1, 5.0.0
May 17, 2017 Severity light-circle-logo light-circle-logo light-circle-logo light-circle-logo light-circle-logo Low IR Number: FG-IR-17-057 CVE-2017-3128
Multiple vulnerabilities impacting FortiPortal were disclosed to Fortinet with details as follows:CVE-2017-7337: Improper ...

May 15, 2017 Severity light-circle-logo light-circle-logo light-circle-logo light-circle-logo light-circle-logo Critical IR Number: FG-IR-17-114 CVE-2017-7337
The FortiAnalyzer and FortiManager WebUI accept a user-controlled input that specifies a link to an external site, and use...

Apr 26, 2017 Severity light-circle-logo light-circle-logo light-circle-logo light-circle-logo light-circle-logo Low IR Number: FG-IR-17-014 CVE-2017-3126
An XSS vulnerability caused by the scrintf parameter input during Firewall Policy Creation can be exploited to load and ru...

FortiOS 5.2.9, 5.2.8, 5.2.7, 5.2.6, 5.2.5, 5.2.4, 5.2.3, 5.2.2, 5.2.10, 5.2.1, 5.2.0
Apr 19, 2017 Severity light-circle-logo light-circle-logo light-circle-logo light-circle-logo light-circle-logo Low IR Number: FG-IR-17-017 CVE-2017-3127
The Site Publisher functionality of FortiWeb has been found vulnerable to a Cross-Site Scripting vulnerability via an impr...

Apr 19, 2017 Severity light-circle-logo light-circle-logo light-circle-logo light-circle-logo light-circle-logo Medium IR Number: FG-IR-17-076 CVE-2017-3129
The lack of input sanitisation for CLI command 'copy running-config' allows a user with 'admin' or 'superuser' privilege l...

Apr 12, 2017 Severity light-circle-logo light-circle-logo light-circle-logo light-circle-logo light-circle-logo High IR Number: FG-IR-17-097 CVE-2017-3134
A race condition in the tty_ioctl function in drivers/tty/tty_io.c in the Linux kernel may allow local users to obtain sen...

Apr 05, 2017 Severity light-circle-logo light-circle-logo light-circle-logo light-circle-logo light-circle-logo Low IR Number: FG-IR-16-013 CVE-2016-0723