SSH backdoor at Fortinet too?
Summary
In January 2016 a Python script appeared on Full Disclosure that provided unauthorised SSH access to Fortinet’s FortiGate firewalls in versions 4.x to 5.0.7. The undocumented mechanism looked suspiciously like a backdoor; Fortinet had already quietly fixed the problem in 2014. Shortly before, Juniper had had to admit that its products contained several backdoors.
Ideas
- A hard-coded access bypassed normal authentication.
- Fixing silently without notice leaves customers in the dark about their risk.
- Ralf-Philipp Weinmann confirmed the backdoor shortly after publication.
Insights
- Undocumented access cannot be distinguished from backdoors, however it was intended.
- Transparency about security fixes is part of product quality.
Facts
- FortiOS 4.x to 5.0.7 was affected.
- Fortinet had applied the change in 2014 without notice.
- Fortinet spoke of a “management authentication issue” and a patch from July 2014.
- The release notes of FortiOS 5.0.8 did not mention an SSH hole.
References
Critique
- The report cannot clarify Fortinet’s intention and leaves the question of purpose open.
Recommendations
- Only make the SSH and web interfaces of firewalls reachable from a management network.
- Treat silent security fixes as a warning sign when choosing a vendor.
Links to the original source and the Web Archive open in a new tab.