Admin Account Persistence after Deletion
Summary
An operation on a resource after expiration or release vulnerability [CWE-672] in FortiManager may allow a Fortigate admin account that is deleted through FortiManager to still be able to login to the FortiGate via valid credentials.
| Version | Affected | Solution |
|---|---|---|
| FortiManager 7.6 | Not affected | Not Applicable |
| FortiManager 7.4 | 7.4.0 | Upgrade to 7.4.1 or above |
| FortiManager 7.2 | 7.2.3 | Upgrade to 7.2.4 or above |
| FortiManager 7.0 | 7.0.7 through 7.0.8 | Upgrade to 7.0.9 or above |
| FortiManager 6.4 | 6.4.12 | Upgrade to 6.4.13 or above |
Workaroud:
Delete the admin account directly from the FortiGate if intended to be done.