Description |
This article describes the scenario where the scan result says that FortiOS is vulnerable to CVE-2013-3587 or BREACH.
BREACH is a category of vulnerabilities and not a specific instance affecting a specific piece of software. To be vulnerable, a web application must:
Impact: |
Scope | FortiGate. |
Solution |
FortiOS is not vulnerable to CVE-2013-3587 (BREACH) as there are multiple mitigations in place that prevent the attack from being possible. FortiOS implements a series of CSRF protections across the product to protect sensitive data from such attack. Therefore scan results can be tagged as false positive.
Additionally, for traffic passing through the FortiGate, this vulnerability has been covered in the extended IPS database with the name of 'BREACH.HTTPS.Compression.Information.Disclosure'.
Related document: |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.