cisagov / cyhy-system

Cyber Hygiene system and overall documentation/issue tracking
Creative Commons Zero v1.0 Universal
6 stars 0 forks source link

Port 2000 and 5060 - Vulnerability / Potentially Risky Service #119

Open cfx47 opened 5 months ago

cfx47 commented 5 months ago

šŸ’” Summary

A large number of IPs have BOTH and ONLY port 2000 and 5060, seemingly pointing to a Fortigate firewall detection. This is causing a large number of potential "false hosts" and a large increase in scan utilization. In an attempt to reduce these from being detected as hosts, we would like to notify stakeholders via by making this a low-medium severity vulnerability on their reports.

Motivation and context

Bringing these vulnerabilities to the attention of stakeholders provides an avenue for remediation. Should remediation be completed, scanner utilization would decrease exponentially.

How stakeholder could resolve issue: https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-Port-5060-and-port-2000-receives-getting-a/ta-p/290960

Implementation notes

Acceptance criteria