bk99.de entertain the web since 1997

SSH backdoor at Fortinet too?

Summary

In January 2016 a Python script appeared on Full Disclosure that provided unauthorised SSH access to Fortinet’s FortiGate firewalls in versions 4.x to 5.0.7. The undocumented mechanism looked suspiciously like a backdoor; Fortinet had already quietly fixed the problem in 2014. Shortly before, Juniper had had to admit that its products contained several backdoors.

Ideas

  • A hard-coded access bypassed normal authentication.
  • Fixing silently without notice leaves customers in the dark about their risk.
  • Ralf-Philipp Weinmann confirmed the backdoor shortly after publication.

Insights

  • Undocumented access cannot be distinguished from backdoors, however it was intended.
  • Transparency about security fixes is part of product quality.

Facts

  • FortiOS 4.x to 5.0.7 was affected.
  • Fortinet had applied the change in 2014 without notice.
  • Fortinet spoke of a “management authentication issue” and a patch from July 2014.
  • The release notes of FortiOS 5.0.8 did not mention an SSH hole.

References

Critique

  • The report cannot clarify Fortinet’s intention and leaves the question of purpose open.

Recommendations

  • Only make the SSH and web interfaces of firewalls reachable from a management network.
  • Treat silent security fixes as a warning sign when choosing a vendor.

Read the original article

Search the Web Archive