JSconsole access to Fortigate
Today we received a security audit assessment from a 3rd party security company. They indicated they can login successfully to our border FortiGate firewall using jsconsole from a trusted management interface. The trusted management interface is connected to the Out-of-band (OOB) Management network and is restricted to specific internal users including the 3rd party security company performing the audit.
Can anyone speak to this access, good, bad, indifferent?
Can jsconsole be used to make changes to the firewall?
Is there a way to block jsconsole access?
Thank you
