- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
fortigate-tech-support user
Hi,
a strange thing happened to me today.
My home firewall 40F (7.2.1) rebooted unexpectedly.
I looked in the log and found that the reboot was done by the user "fortigate-tech-support" and the reason was a firmware upgrade (7.2.1->7.2.2)
In system/Administrator this user was created and I don't know about it.
My admin password is set to 17 characters (including special characters) and another administrator has an equally strong password.
FortiGate is added to FortiCloud.
Passwords remained unchanged, all configuration looks ok.
How should I explain it? I'm assuming it's not a trusted event... or is it something to do with the new CVE?
Thank you.
Jirka
- Labels:
-
FortiGate
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Ok,
according to this it is exactly the CVE problem - https://www.fortiguard.com/psirt/FG-IR-22-377
What are the best practices for this (other than upgrading to a patched version)?
Besides the user "fortigate-tech-support" that I deleted, is there anything else to watch out for? I checked the configuration several times (using PSpad) and found nothing out of the ordinary.
Thank you.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
And one more question: the passwords are encrypted in the configuration file. If someone downloads the configuration file, is it possible to decrypt these passwords?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Greetings,
I would strongly recommend opening a case with TAC to take further steps.
Ahmad
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks,
ticket created.
J.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @Jirka1 - what was reported by Fortigate.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Got any updates?
Is this a new vulnerability? Because https://www.fortiguard.com/psirt/FG-IR-22-377 advise doing a firmware upgrade to 7.0.7.
But the thing is we got the same admin account 'fortigate-tech-support' logged in to the firewall and performed a firmware upgrade to 7.0.7.
As of know, we got 3 cases with 'fortigate-tech-support' account involved.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Wonder why the attacker exploit it and do the firmware upgrade to mitigate https://www.fortiguard.com/psirt/FG-IR-22-377.
Unsung hero?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Same thing happend on my firewall also, anything suspicious..
