Build1 publisher2 min readPublished
Outsourced Fortinet firewalls turn ACSC's rotate-everything advice into an ownership question
Australia's ACSC told Fortinet users on 18 June to rotate all admin and VPN credentials immediately, the first of six steps in its alert. On hosted or co-managed gateways, each step first needs someone to settle who holds the accounts and who has to act.
The Engineer · Build desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- The alert cites public reporting of a widespread campaign against Fortinet firewalls and VPN gateways that largely relies on exposed credentials and credential-based attacks.
- Beyond rotation, it tells organisations to patch older firmware, keep management interfaces off the internet, enforce MFA externally, move to PBKDF2 hashing and review logs.
- The alert points readers to a Fortinet blog post and additional guidance, and tells affected organisations to review and monitor it.
- A dev.to analysis argues that on outsourced gateways someone must first settle who holds the admin accounts, the VPN directory and the logs, and who must act on what timeline.
Compiled by The EngineerSomething wrong?How this is made
Why it matters
- decision Managed-service customers have to inventory the Fortinet devices they answer for before a 'please rotate credentials' ticket to their provider can be acted on.
- constraint With no CVE or affected-version list in the alert, a customer cannot rule a gateway out by checking its firmware, so every Fortinet device it relies on stays in scope.
- exposure A customer that cannot see its gateway's authentication and access logs has no way to check for the abnormal logins or changes the alert asks about by itself.
A dev.to analysis of the alert lists what credential rotation takes: knowing which accounts exist, where they are stored, and which service accounts may break when the password changes [9]. The post calls the advice itself conventional for a credential-exposure event [19].
The PBKDF2 step shows the dependency most plainly. For existing accounts, the alert says, the stored hash changes to PBKDF2 only after someone logs back in to the admin account following the update [5]. Nobody can log back in to an admin account they were never given. The analysis notes that this step requires an actor who holds admin credentials [13].
The remaining steps depend on the contract. Patching against older-firmware vulnerabilities needs a change window negotiated with the managed service provider [10]. On shared hardware, that negotiation often includes the provider's other customers as well [10]. Internet-reachable management is frequently a design choice made when the contract was signed, and the provider may rely on it to administer the box [11]. MFA on external interfaces may be limited by the provider's authentication stack [12].
That reachable management plane is the exposure the alert describes. Leaked credentials, it says, "could enable malicious actor's remote access to the devices and connected networks, as well as allow changes to various settings, including security controls" [3]. On a co-managed gateway, closing that interface can also cut off the provider's own way in [11].
The 18 June alert [1] is addressed to "all Australians and Australian organisations that use Fortinet devices" [8]. The analysis does not fault the advice. "None of this makes the advisory wrong. It makes it incomplete for a specific class of reader," the author wrote [16]. I think that verdict is correct. The six steps [1] are standard work for whoever holds the admin password. On an outsourced gateway, finding that person is the first job.
For the triage that has to happen before any rotation, the post proposes internet-exposure measurements, including ZoomEye observations of the Fortinet footprint, to support asset identification [18].
What to watch
- Whether Fortinet's PSIRT guidance, which the alert references, adds indicators or version details that let customers scope gateways by firmware.
- Whether ACSC updates the alert with a CVE, an affected version list, or a count of affected devices or organisations.
- Notices from managed service providers to their customers stating who will rotate Fortinet credentials and by when.