Admin Account Persistence after Deletion

Summary

An operation on a resource after expiration or release vulnerability [CWE-672] in FortiManager may allow a Fortigate admin account that is deleted through FortiManager to still be able to login to the FortiGate via valid credentials.

Version Affected Solution
FortiManager 7.6 Not affected Not Applicable
FortiManager 7.4 7.4.0 Upgrade to 7.4.1 or above
FortiManager 7.2 7.2.3 Upgrade to 7.2.4 or above
FortiManager 7.0 7.0.7 through 7.0.8 Upgrade to 7.0.9 or above
FortiManager 6.4 6.4.12 Upgrade to 6.4.13 or above

Workaroud:
Delete the admin account directly from the FortiGate if intended to be done.

Acknowledgement

Fortinet is pleased to thank Saif Ali Momin from Fortinet TAC team for discovering and reporting this vulnerability internally.

Timeline

2025-01-14: Initial publication