STIGQter STIGQter: STIG Summary: Fortinet FortiGate Firewall NDM Security Technical Implementation Guide Version: 1 Release: 5 Benchmark Date: 05 Jan 2026:

The FortiGate device must not have any default manufacturer passwords when deployed.

DISA Rule

SV-234209r984088_rule

Vulnerability Number

V-234209

Group Title

SRG-APP-000080-NDM-000345

Rule Version

FGFW-ND-000250

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Log in to the FortiGate GUI with Super-Admin privilege.

1. Open a CLI console, via SSH or available from the GUI.
2. Run the following commands:
# config system admin
# edit admin
# set password {password}
# end

Check Contents

Attempt to log in to the FortiGate GUI using the username admin with the default (blank) password.

Attempt to log in to the CLI over SSH with the username admin with the default (blank) password.

If either of these logins are successful, this is a finding.

Vulnerability Number

V-234209

Documentable

False

Rule Version

FGFW-ND-000250

Severity Override Guidance

Attempt to log in to the FortiGate GUI using the username admin with the default (blank) password.

Attempt to log in to the CLI over SSH with the username admin with the default (blank) password.

If either of these logins are successful, this is a finding.

Check Content Reference

M

Target Key

5260