Fortinet fixes authentication flaws in FortiWeb and FortiManager
Source headline: Fortinet Patches Authentication Flaws in FortiWeb and FortiManager
Intelligence Summary
Fortinet has patched authentication flaws affecting FortiWeb and FortiManager. The issues could allow attackers to log in using random usernames and passwords. The flaws also could enable impersonation of any FortiGate appliance. These are authentication-related weaknesses that increase the risk of unauthorized access. Patch availability and impact details are provided in the SecurityWeek coverage. Update FortiWeb and FortiManager with the vendor’s fixes to close the authentication paths.
Recommended Action
Inventory where Fortinet runs in your environment and treat this as an active remediation item. Until then, watch authentication and outbound traffic logs for the indicators described in the source. This signal rests on a single report, so corroborate it before acting on anything irreversible.