In a collaboration with the IT services of the University of Udine (DISO), we discovered a vulnerability in several Fortigate firewalls: by carefully setting some bits, crafted TCP packets could pass through the firewall despite the IPS rules.
We promptly reported the issue to Fortinet. The vulnerability has now been published as CVE-2023-40718; more details are on the FortiGuard PSIRT page.