πΎ - π¨ Connection to Fortinet Fortigate UTM π§± with default TLS Certificate π exposed on Internet (Possible FortiClient VPN)
Sourcepawpatrules
CreatedMarch 15, 2023
UpdatedMarch 15, 2023
Classificationpolicy-violation
alert tls $EXTERNAL_NET any -> any any (msg:"πΎ - π¨ Connection to Fortinet Fortigate UTM π§± with default TLS Certificate π exposed on Internet (Possible FortiClient VPN)"; flow:to_client, stateless; tls.cert_issuer; content:"C=US"; nocase; content:"ST=California"; nocase; content:"L=Sunnyvale"; nocase; content:"O=Fortinet"; nocase; content:"OU=Certificate Authority"; nocase; fast_pattern; content:"CN=fortinet-subca2001"; nocase; content:"support@fortinet.com"; nocase; reference:url,https://www.fortinet.com/fr/products/next-generation-firewall; metadata:created_at 2023_03_15, updated_at 2023_03_15; sid:3300289; rev:1; classtype:policy-violation;)
Metadata
created at2023_03_15
updated at2023_03_15
Comments (0)
Please sign in to leave a comment.
Sign inNo comments yet. Be the first to comment!