FORTINET Security Advisory
Published Date: Not specified
Advisory Summary
⬛ Title: ➤ Broken access control in the RADIUS type admin group (FortiWeb)
⚠️ What’s new / impact (CWE-287, Improper Authentication | CVSS 8.8)
FortiWeb’s Remote Radius Type Admin Authentication—when configured with specific, non-default settings—can expose an authentication weakness where a remote, unauthenticated attacker may be able to log into the FortiWeb GUI/CLI using a random username and password.
🔍 Why this matters for datacenters & infrastructure
Successful access to the FortiWeb management plane can enable follow-on actions such as configuration changes, creation of malicious admin accounts, traffic manipulation, and disruption of protected applications—impacting both security posture and operational availability.
🛡️ Potential exploitation path (high-level)
1) Attacker targets the FortiWeb management authentication flow configured for Remote RADIUS admin.
2) Due to the improper authentication behavior, attacker attempts login with effectively guessed/invalid credentials.
3) If successful, attacker gains administrative access to GUI/CLI.
- Whether Remote RADIUS Type Admin is enabled on your FortiWeb instances
- Whether your setup matches the “specific, non-default settings” referenced in the advisory
- Any exposure of FortiWeb management endpoints to untrusted networks (internet/side networks)
- Apply the PSIRT-recommended patch/mitigation from the referenced bulletin as soon as possible.
- If a patch is not yet applied, temporarily limit management access (IP allowlisting/VPN-only) and ensure RADIUS admin authentication is configured according to Fortinet’s guidance.
- Validate externally reachable management surfaces are protected by strong network controls and authentication hardening.
- Restrict GUI/CLI access to trusted admin networks only
- Implement MFA for administrative access where supported in your deployment pattern
- Monitor authentication logs for abnormal login attempts consistent with random credential success
📌
-287
Reference: Vendor Advisory