Contact
FortiBleed: 73,000 Fortinet VPN credentials exposed

Library

FortiBleed: 73,000 Fortinet VPN credentials exposed

← Back to library
Share via

FortiBleed: 73,000 Fortinet VPN credentials exposed

Security researchers at Bitsight published a dataset under the name FortiBleed containing more than 73,000 valid administrator passwords for internet-facing Fortinet FortiGate firewalls. According to the researchers, the data affects approximately half of all FortiGate devices accessible online and covers 194 countries. For organisations using Fortinet at the network edge, this is an immediate warning.

What is happening?

The core issue lies in how FortiOS stores passwords during an upgrade. When a device is upgraded from an older version, administrator passwords remain stored as weak SHA-256 hashes until an administrator manually signs in again after the upgrade. Attackers collected these hashes from previous compromises and cracked them offline using a setup of 45 GPUs. The valid credentials subsequently circulated on Telegram, paste sites and criminal forums. The pattern resembles earlier Fortinet incidents, including CVE-2018-13379, which affected approximately 50,000 devices in 2020.

Risk

A firewall sits at the edge of the network and controls all inbound and outbound traffic. With valid administrator access, an attacker can take full control of the firewall, intercept VPN traffic, create hidden accounts and disable logging. This is often followed by lateral movement into internal systems, ransomware staging and data exfiltration. Because many organisations also connect suppliers and partners through these firewalls, the impact can extend beyond the organisation's own network.

Points to check

  • Is the device running a FortiOS version older than 7.2.11, 7.4.8 or 7.6.1?
  • Have administrators signed in again after the latest upgrade so the old hash was replaced?
  • Is the SSL VPN portal or management interface exposed to the internet?
  • Are there unexpected administrator sign-ins, new accounts or modified firewall rules?
  • Is multi-factor authentication enforced for all administrator and VPN access?

Approach

DeepBlue starts with an external inventory of internet-facing Fortinet devices and their FortiOS versions. We then verify whether administrator and VPN passwords have been rotated and whether known credentials occur in the FortiBleed dataset. We actively hunt for signs of misuse, including tunnelling tools such as Chisel and Neo-reGeorg, sessions outside business hours and geographical access anomalies. Finally, we assist with patching, restricting management access to trusted IP addresses and enforcing multi-factor authentication.

Conclusion

FortiBleed shows that an apparently completed upgrade can still leave an open door. The combination of weak hashes, exposed management interfaces and reused passwords makes firewalls an attractive target. Rotating credentials, patching and investigating now closes that window before attackers exploit it. Edge devices should therefore receive the same care as the organisation's most critical servers.

Contact

Want to understand the impact in your own environment? Contact DeepBlue Security & Intelligence at info@deepbluesecurity.nl or +31 (0) 70 290 6 290.

← Back to library

Direct access to senior cybersecurity expertise

Discuss a security requirement, active risk or complex IT or OT environment with one of our senior specialists. The initial conversation focuses on the technical context, operational constraints and the most appropriate course of action.

  • No mailing lists or automated sales follow-up
  • Information is handled confidentially

Urgent assistance required?

Call +31 (0) 70 290 6 290
or email  info@deepbluesecurity.nl

Thank you. The message has been received and will be reviewed by one of our specialists.
The form could not be submitted. Please try again or contact info@deepbluesecurity.nl.