This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Sophos XG 17.5 MR12 Mandatory Password Reset Page???

We updated our Sophos XG Firewall to the latest firmware (17.5 MR12) last week. One of the local administrators logged in today to monitor the firewall and this appeared. 

 

Is this legitimate or can anyone send me an article about this from Sophos?

 

We already reset our local and device administrator password last April 2020 and again they are requiring us to change again our passwords.

 

Thank you in advance for those who will help. God bless us all.



This thread was automatically locked due to age.
Parents
  • Hello, 

    We are running Sophos XG with Firmware 17.5 MR-11 . 

     

    Today we saw the same screen "Mandatory Password reset" on our firewall. 

     

    Can anyone please confirm that this is legitimate action by Sophos pushed by the Company itself. because we got no information from Sophos.

     

    we would like to mention that our device was recently compromised and patched by Sophos against the recent "SQL Injection" attack. and we already have changed our password according to the given KB.

  • Hi All,

    Sophos is enforcing a password reset for the XG administrator and all other local administrator accounts that have not reset passwords since the security hotfix was applied at 2200 UTC on April 25, 2020. Where required, administrative accounts will be prompted to change passwords upon logging into an XG Firewall. The password reset is shown only on an XG Firewall that was identified as impacted AND the password has not been changed since 2200 UTC on April 25, 2020.

    Admins will still receive the password reset request even if multi-factor authentication is enabled. The last date/time check for the password change is determined locally on the firewall from logged events. In the event a positive determination cannot be made, admins will be forced to change their password.

  • Hi Flo,

    Thank you for explaining this to us.

    You have mentioned that the mandatory password reset is for firewalls that are affected and the password has not been changed since 2200H UTC on April 25,2020.

     

    As per my understanding it is an AND statement not an OR statement.

     

    We've have already changed our password last 26th of April as per checking via Admin events thus removing us from the coverage bracket of the AND statement above. 

     

    I am really wondering why I myself or my other teammates will still again redo this even if we areaare done with it and followed the recommendations that you have provided on KB.

  • Is there a way to remove the "password reset required flags" manually? (We reset the passwords after the hotfix had been applied to our firewall but before the Sophos cutoff time of 22:00 UTC, when the hotfix had been applied to all hotfix-enabled firewalls.)

Reply Children
No Data