
Library
Security researchers at Bitsight published a dataset under the name FortiBleed containing more than 73,000 valid administrator passwords for internet-facing Fortinet FortiGate firewalls. According to the researchers, the data affects approximately half of all FortiGate devices accessible online and covers 194 countries. For organisations using Fortinet at the network edge, this is an immediate warning.
Researchers reported a dataset containing verified administrative credentials for more than 73,000 internet-facing FortiGate systems. Such publication should not automatically be interpreted as evidence of one new vulnerability or of current compromise of every listed device. The material may include previously obtained credentials, reused passwords, historical configurations or accounts that have since been changed. The relevant question is whether an organisation appears in the dataset and whether the associated account, appliance or authentication material remains valid. Internet exposure, firmware level, management interfaces, VPN configuration and recent changes therefore need to be assessed together. Resetting one password is not sufficient if active sessions, tokens, certificates or downstream accounts may also have been affected.
Valid administrative or VPN credentials can provide access to network configuration, user data, routes, security policies and logging settings. From an edge appliance, an attacker may identify internal systems, trusted connections or credentials reused elsewhere. Exposure can persist when a password is changed but active sessions, API tokens, local accounts or cryptographic material are not revoked. An attacker may also alter logging or traffic handling, reducing defensive visibility. A match with a public dataset is not proof that access succeeded, but it is a specific reason to perform incident validation. Conversely, absence from the dataset does not prove that an environment is unaffected, because public datasets are rarely complete or continuously current.
DeepBlue treats a potential match as a scoped incident investigation. Assets, serial numbers, firmware, external interfaces and administrative identities are inventoried first. Credentials are then changed, sessions and tokens revoked, and relevant patching and hardening controls verified. Firewall, identity-provider, VPN and adjacent-system logs are preserved and correlated for anomalous sign-ins, configuration changes, newly created accounts and unusual network flows. Where indicators justify it, the investigation extends to lateral movement and reuse of exposed credentials. Structural measures include phishing-resistant MFA for administration, restriction of management access to trusted zones, separate administrative identities, minimal external exposure and continuous monitoring. Findings are prioritised according to demonstrated impact, preventing remediation from ending with a generic password reset.
FortiBleed shows that an apparently completed upgrade can still leave an open door. The combination of weak hashes, exposed management interfaces and reused passwords makes firewalls an attractive target. Rotating credentials, patching and investigating now closes that window before attackers exploit it. Edge devices should therefore receive the same care as the organisation's most critical servers.
Want to understand the impact in your own environment? Contact DeepBlue Security & Intelligence at info@deepbluesecurity.nl or +31 (0) 70 290 6 290.
Discuss a security requirement, active risk or complex IT or OT environment with one of our senior specialists. The initial conversation focuses on the technical context, operational constraints and the most appropriate course of action.
Urgent assistance required?
Call +31 (0) 70 290 6 290
or email info@deepbluesecurity.nl