All versions of FortiOS from 5.0.8 and later as well as FortiOS 4.3.17 and later are not impacted by this issue.Īccording to the exploit code, the undisclosed authentication works on versions 4.3 up to 5.0.7.
After careful analysis and investigation, we were able to verify this issue was not due to any malicious activity by any party, internal or external. The issue was identified by our Product Security team as part of their regular review and testing efforts. This was not a 'backdoor' vulnerability issue but rather a management authentication issue.
This issue was resolved and a patch was made available in July 2014 as part of Fortinet¹s commitment to ensuring the quality and integrity of our codebase. In a statement, Fortinet officials rejected the backdoor characterization.