Description
This article explains how non-admin users can use the presence of a maintainer account to gain unauthorized access to the Firewall and how to prevent it in FortiGate versions before 7.2.4.
Scope
Versions before 7.2.4.
Solution
Situations may arise where local users in the network have physical access to the firewall even though they are not the admin users. If one of these users has the serial number and console access to the device, the user can reset the admin password and gain access to the firewall.
See the following document for instructions on how to disable the feature:
Note: Starting with FortiOS 7.2.4, the maintainer account is removed by default.
See the following article to reset a lost admin password:
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.