<?xml version="1.0" encoding="UTF-8"?>
<cvrf:cvrfdoc xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:cvrf-common="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/common" xmlns:cvrf="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/cvrf">
    <cvrf:DocumentTitle>Supermicro will try to use other port if the IPMI is not connected</cvrf:DocumentTitle>
    <cvrf:DocumentType>Fortinet PSIRT Advisories</cvrf:DocumentType>
    <cvrf:DocumentPublisher Type="Vendor">
        <cvrf:ContactDetails>
            Fortinet PSIRT Contact:
            Website: https://fortiguard.fortinet.com/faq/psirt-contact
        </cvrf:ContactDetails>
     </cvrf:DocumentPublisher>
    <cvrf:DocumentTracking>
        <cvrf:Identification>
            <cvrf:ID>FG-IR-17-195</cvrf:ID>
        </cvrf:Identification>
        <cvrf:Status>Final</cvrf:Status>
        <cvrf:Version>1</cvrf:Version>
        <cvrf:RevisionHistory>
            <cvrf:Revision>
                <cvrf:Number>1</cvrf:Number>
                <cvrf:Date>2019-09-17T00:00:00</cvrf:Date>
                <cvrf:Description>Current version</cvrf:Description>
        </cvrf:Revision>
       </cvrf:RevisionHistory>
        <cvrf:InitialReleaseDate>2019-09-17T00:00:00</cvrf:InitialReleaseDate>
        <cvrf:CurrentReleaseDate>2019-09-17T00:00:00</cvrf:CurrentReleaseDate>
    </cvrf:DocumentTracking>
    <cvrf:DocumentNotes>
        <cvrf:Note Title="Summary" Type="Summary" Ordinal="1">
            Some models of FortiAnalyzer and FortiManager have a default setting of &#34;Failover&#34;, for remote IPMI access; this means that if no cable is plugged in the IPMI port, the IPMI implementation will request an IP address on the regular LAN port of the device, via DHCP requests.Should such a DHCP request succeed, access to the IPMI web GUI is then possible on the granted IP address, via the regular LAN port of the device.This presents an operational risk, as this default behavior may not be known or understood by administrators of the device; the latter risk is more important if the default IPMI admin passwords have not been changed.
        </cvrf:Note>
        <cvrf:Note Title="Impact" Type="General" Ordinal="2">
            Improper access control
        </cvrf:Note>
        <cvrf:Note Title="Affected Products" Type="General" Ordinal="3">
            FortiAnalyzer models:FAZ-400E, FAZ-1000E, FAZ-2000E, FAZ-3000F, FAZ-3500F, FAZ-3700FFortiManager models:FMG-300E, FMG-400E, FMG-2000E, FMG-3000FOther models and Fortinet products are confirmed to not have a default Failover setting.
        </cvrf:Note>
        <cvrf:Note Title="Solutions" Type="General" Ordinal="4">
            IPMI firmware has been updated to avoid that potential operational risk, and production shipments after July 2017 do not present that risk. For customer using affected models, Fortinet PSIRT suggests checking the IPMI interface settings and making sure the IPMI port option is set to &#34;Dedicated&#34; instead of &#34;Failover&#34;. The procedure is detailed in this document entry: https://docs.fortinet.com/document/fortimanager/hardware/disable-the-ipmi-port/ As a measure of precaution, and regardless the product, when an IPMI port is present, we also suggest to not leave the IPMI interface admin password to its default value. The procedure to change it is detailed in this document entry: https://docs.fortinet.com/document/fortimanager/hardware/change-the-ipmi-port-password/
        </cvrf:Note>
    </cvrf:DocumentNotes>
    <cvrf:Acknowledgments>
        <cvrf:Acknowledgment>
            <cvrf:Description>Fortinet is pleased to thank &#34;taNET GmbH&#34;, &#34;BOLL Engineering AG&#34; and &#34;CIC Consulting Informatico&#34; for reporting this operational risk under responsible disclosure.</cvrf:Description>
        </cvrf:Acknowledgment>
    </cvrf:Acknowledgments>
    <Vulnerability Ordinal="1">
        <Title>Supermicro will try to use other port if the IPMI is not connected</Title>
        <CVSSScoreSets>
            <ScoreSetV3>
                <BaseScoreV3>0</BaseScoreV3>
            </ScoreSetV3>
        </CVSSScoreSets>
        <References Type="Self">
            <Reference>
                <URL>https://fortiguard.fortinet.com/psirt/FG-IR-17-195</URL>
                <Description>Supermicro will try to use other port if the IPMI is not connected</Description>
            </Reference>Reference>
        </References>
    </Vulnerability>
</cvrf:cvrfdoc>