fortinet fortios

Published Atomicorp research notes for CVEs affecting fortinet fortios where WAF protections were observed during testing or engineering review.

These notes are not intended to represent the full set of vulnerabilities mitigated by Atomicorp products and should not be interpreted as a coverage matrix, certification list, or census of protected CVEs.

Atomicorp WAF protections are primarily designed around attack techniques and exploit behaviors rather than individual vulnerability identifiers. A published research note documents a positive research finding related to that CVE. If a CVE is absent from these notes, no conclusion should be drawn about protection status.

CVEVulnerabilityCVSSSeverityRules Observed
CVE-2018-13379Fortinet FortiOS - Credentials Disclosure9.8 (v3.1)Critical340007
CVE-2017-3132Fortinet FortiOS < 5.6.0 - Cross-Site Scripting6.1 (v3.0)Medium340147 , 340148 , 341256 , 341266 , 342259 , 344370 , 346755 , 347198 , 350147 , 350148 , 390727 , 392301 , 392648
CVE-2017-3133Fortinet FortiOS < 5.6.0 - Cross-Site Scripting6.1 (v3.0)Medium340147 , 340148 , 341256 , 341266 , 342259 , 344370 , 346755 , 347198 , 350147 , 350148 , 390727 , 392301 , 392648
CVE-2018-13380Fortinet FortiOS - Cross-Site Scripting6.1 (v3.1)Medium333141 , 340147 , 341266 , 342259 , 347198
CVE-2017-14186FortiGate FortiOS SSL VPN Web Portal - Cross-Site Scripting5.4 (v3.0)Medium346755 , 350148
CVE-2017-3131Fortinet FortiOS < 5.6.0 - Cross-Site Scripting5.4 (v3.0)Medium340147 , 340148 , 341256 , 341266 , 342259 , 344370 , 346755 , 347198 , 350147 , 350148 , 390727 , 392301 , 392648
CVE-2015-1880Fortinet FortiOS <=5.2.3 - Cross-Site Scripting4.3 (v2.0)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148