Skip to main content
dbowen
New Member
July 20, 2026
Question

Problems when I upgraded to 7.0.0601 last may

  • July 20, 2026
  • 1 reply
  • 22 views

When I went from 6.4.1879 to 7.0.0601 last May I ended up with extra accounts that where setup with super_admin access, like the following

forticloud tech

admin_vpn_access_work

admin_vpn_access

fortinet_tech

plus other ones does any one know how these got in there? I have since removed them and replaced the 100F to the 120G

 

    1 reply

    RBA
    Staff
    Staff
    July 21, 2026

    It appears that you may be affected by CVE-2022-40684/FG-IR-22-377

    I recommend referring to these PSIRT articles for more details on the abused vulnerabilities.
    https://www.fortiguard.com/psirt/FG-IR-22-377

    Perform a Factory reset and configure the device from scratch. Change all passwords, private keys.
    https://community.fortinet.com/t5/FortiGate/Technical-Tip-Recommended-steps-to-execute-in-case-of-a/ta-p/230694
    https://community.fortinet.com/t5/FortiGate/Technical-Tip-Loading-FortiGate-firmware-image-using-TFTP/ta-p/197600

    Restore the configuration from a known good backup.
    Restrict all admin logins to trusted hosts only https://docs.fortinet.com/document/fortigate/6.4.0/hardening-your-fortigate/582009/system-administrator-best-practices
    Ddisable administrative access to any external (internet-facing) interface. Perform administrative tasks over an out-of-band network
    Change GUI and SSH administrative access to non default ports
    Hardening: https://docs.fortinet.com/document/fortigate/6.4.0/hardening-your-fortigate

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!