Fortinet urges admins to patch bug with public exploit immediately
To reduce this vulnerability, You can remove the public access of HTTPS from WAN port. along with use custom port for WAN access.
Use SSL-VPN for HTTP access,.
Use MAC based Authentication for SSL-VPN user, Where Firewall authenticate User's Device MAC address before connecting to Firewall it adds one more security layer in your Network.
After Creating the SSL VPN
config vpn ssl web portaledit full-accessset mac-addr-check enableend
2 things required for user to get verified by fortinet1: Username2. MAC address of the device Like this format: 00:00:00:00:00:00