CVE-2018-13379 : Question / Confirmation
Howdie all,
got an e-mail about this threat ( https://www.fortiguard.com/psirt/FG-IR-18-384 ). Upon rereading it now I noticed the line that the only workaround is to unset the source interface completely.
What I did back when it got released is set the source interface to an interface we are not using (status down, not eth cable connected).
Portscan on external interface showed the specified non-standard port was not responding.
My question now is. Is setting non-used interface sufficient? Or is unsetting source interface really the only way to safeguard apart from updating fortigate?
thanks a bunch in advance
