Skip to main content
Hosemacht
Explorer
May 15, 2019
Solved

FortiOS 5.6.9 is out

  • May 15, 2019
  • 3 replies
  • 35492 views

with only one weird bugfix in the release notes:

 

529745 FortiOS 5.4.11

is no longer vulnerable to the following CVEReference: l CVE-2018-1338

 

https://docs.fortinet.com.../fortios-release-notes

    Best answer by rojekj

    Beware, as this release has a major bug in SSL VPN. When uer is in multiple groups that grants different access in SSL VPN, only the first group is working. For example:

    User x is in group vpn_a, and vpn_b, group vpn_a grants access to 1.1.1.1 and group vpn_b grants access to 2.2.2.2. After upgrading to 5.6.9, user can no longer access 2.2.2.2. After removing him from vpn_a group he can access 2.2.2.2 again.

     

    Once again - our VPN gateway is broken after upgrade.

    When it will be fixed? In 6 months? or 7? So I must live with vulnerable VPN till then?

    Seriously, I don't have words for fortinets' QA. Because it does not exist!

    3 replies

    ddskier
    New Member
    May 15, 2019

    I don't get this release.  Only bug fix is:

     

    529745 FortiOS 5.4.11 is no longer vulnerable to the following CVE Reference:  CVE-2018-13382

     

    Not sure how a 5.4.11 fix applies going from 5.6.8 to 5.6.9.

     

    dedmonds_FTNT
    Staff
    Staff
    May 15, 2019

    The 5.4.11 reference is a typo.  It should read 5.6.9.  You have an outdated copy of the release notes.  Download the document again.

    FlavioB
    New Member
    May 18, 2019

    OK but anyway: where to find exact description/information about that CVE? I'm not finding any...

    F.

    Hosemacht
    HosemachtAuthor
    Explorer
    May 21, 2019

    indeed there is no CVE Record for: CVE-2018-1338

    maybe another typo?

    FlavioB
    New Member
    May 21, 2019

    the_giraffe_that_wasnt_president wrote:

    indeed there is no CVE Record for: CVE-2018-1338

    maybe another typo?

    No typo.

    It's simply been reported as "responsible disclosure".

     

    ddskier
    New Member
    May 21, 2019

    I applied this update on numerous 100D and 200D.  No issues.

    rojekj
    rojekjAnswer
    New Member
    May 29, 2019

    Beware, as this release has a major bug in SSL VPN. When uer is in multiple groups that grants different access in SSL VPN, only the first group is working. For example:

    User x is in group vpn_a, and vpn_b, group vpn_a grants access to 1.1.1.1 and group vpn_b grants access to 2.2.2.2. After upgrading to 5.6.9, user can no longer access 2.2.2.2. After removing him from vpn_a group he can access 2.2.2.2 again.

     

    Once again - our VPN gateway is broken after upgrade.

    When it will be fixed? In 6 months? or 7? So I must live with vulnerable VPN till then?

    Seriously, I don't have words for fortinets' QA. Because it does not exist!

    FlavioB
    New Member
    May 29, 2019

    To all:

    https://fortiguard.com/psirt/FG-IR-18-389

    So finally CVE-2018-13382 is fixed in 5.4.11, 5.6.9, 6.0.5, 6.2.0 and above

     

    F.

    XavierMP
    New Member
    May 29, 2019

    It's not the same CVE:

    CVE-2018-13382 vs CVE-2019-5586

    FG-IR-18-389 vs FG-IR-19-034