| Description | This article describes how to use FortiGate to mitigate the ROBOT vulnerability found on TLSv1.2 using AES256-SHA with a weak oracle. |
| Scope | All FortiGate Firmware |
| Solution |
This vulnerability exploits ciphers. To prevent the vulnerability being used, disable ciphers in the CLI.
Before making any changes, make sure to have the latest backup and then enter the following commands in the FortiGate CLI:
config vpn ssl settings set banned-cipher CAMELLIA end
Run a scan again after blocking the CAMELLIA cipher suites. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2026 Fortinet, Inc. All Rights Reserved.