STIGQter STIGQter: STIG Summary: Fortinet FortiGate Firewall NDM Security Technical Implementation Guide Version: 1 Release: 5 Benchmark Date: 05 Jan 2026:

The FortiGate device must only install patches or updates that are validated by the vendor via digital signature or hash.

DISA Rule

SV-234220r984089_rule

Vulnerability Number

V-234220

Group Title

SRG-APP-000131-NDM-000243

Rule Version

FGFW-ND-000305

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Administrators can download software directly from a FortiGuard or FortiManager server. These servers are authenticated using digital certificates that ensure identity and non-repudiation of the source packages. This is a preferred method of applying updates.

The Administrator can also download the software from Fortinet's support website portal. The website includes a file checksum to verify file integrity prior to uploading.

Develop a process to download the update files from the Fortinet website, and manually compare the download hash to the hash value provided on the vendor site before applying the update files to the system.

Check Contents

Verify the process used to apply updates and patches to the system.

If the system is updated via a FortiGuard or FortiManager server, those solutions meet the requirement and this is NOT a finding.

If the system is not using a FortiGuard or FortiManager server, and a process is not defined to manually verify the update hash value with the vendor site, this is a finding.

Vulnerability Number

V-234220

Documentable

False

Rule Version

FGFW-ND-000305

Severity Override Guidance

Verify the process used to apply updates and patches to the system.

If the system is updated via a FortiGuard or FortiManager server, those solutions meet the requirement and this is NOT a finding.

If the system is not using a FortiGuard or FortiManager server, and a process is not defined to manually verify the update hash value with the vendor site, this is a finding.

Check Content Reference

M

Target Key

5260