STIGQter STIGQter: STIG Summary: Fortinet FortiGate Firewall NDM Security Technical Implementation Guide Version: 1 Release: 5 Benchmark Date: 05 Jan 2026:

The FortiGate device must limit privileges to change the software resident within software libraries.

DISA Rule

SV-234190r960960_rule

Vulnerability Number

V-234190

Group Title

SRG-APP-000133-NDM-000244

Rule Version

FGFW-ND-000155

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Log in to the FortiGate GUI with Super-Admin privilege.

To remove System access permission from an existing low-privileged administrator:

1. Click System.
2. Click Administrators.
3. Identify the administrator role that is unauthorized to update software.
4. Select the administrator role and hover over the profile assigned to the role.
5. Click Edit.
6. For System access, click None.
7. Click OK to save.

Check Contents

Log in to the FortiGate GUI with an Administrator that does not have System setting privileges.

1. Click System.
2. Attempt to click Firmware; this option will not be available.

If the FortiGate device does not limit privileges to change the software resident within software libraries, this is a finding.

Vulnerability Number

V-234190

Documentable

False

Rule Version

FGFW-ND-000155

Severity Override Guidance

Log in to the FortiGate GUI with an Administrator that does not have System setting privileges.

1. Click System.
2. Attempt to click Firmware; this option will not be available.

If the FortiGate device does not limit privileges to change the software resident within software libraries, this is a finding.

Check Content Reference

M

Target Key

5260