The Fortinet dumpster fire reignites

OVERKILL

$100 Site Donor 2021
Joined
Apr 28, 2008
Messages
63,162
Location
Ontario, Canada
@Rand is going to love this one!



As @UK_Daniel_Card on Twitter/X says: "if you have fortinet, you might want to review/audit the user accounts on the system. Monitor/Review for new users created..."

Fortinet users seem to get only brief reprieves from gaping holes in what has to be the least secure "Security" products on the planet.
 
Oh, we are SO BACK!!!
1769615046783.webp
 
Work just pulled the plug on Fortinet. Except for a few SonicWalls left for IT use until we figure out how to get Cisco Secure Client to use Modern auth in ConnectWise, we’re on AnyConnect on Meraki firewalls.
 
Haven’t had to touch Fortinet in years, to my great relief :D
I've never subjected myself to any of their products on purpose, but I've been involved in deployment, the worst being their phone systems. I recently binned an HA pair for a Meraki MX, that was a long overdue upgrade.
 
Ahhh, another day, another Fortinet vulnerability!

This one lets attackers bypass LDAP authentication:
https://cybersecuritynews.com/fortios-ldap-authentication-bypass-vulnerability/

Fortinet has disclosed a high-severity authentication bypass vulnerability in FortiOS, tracked as CVE-2026-22153 (FG-IR-25-1052), that could allow unauthenticated attackers to sidestep LDAP authentication for Agentless VPN or Fortinet Single Sign-On (FSSO) policies.

Quality in every line of code!
 
We just bought an 81E since we have a new fips-validated requirement. I had a pool of Palo Alto’s at my last post - the Palos were smoother machines but th PE annual fees were easily 5x higher… I did the purchasing.
 
Back
Top Bottom