¡¾Â©¶´Í¨¸æ¡¿Fortinet FortiOS¸ñʽ×Ö·û´®Â©¶´£¨CVE-2024-23113£©

Ðû²¼Ê±¼ä 2024-10-15

Ò»¡¢Â©¶´¸ÅÊö

©¶´Ãû³Æ

  Fortinet   FortiOS¸ñʽ×Ö·û´®Â©¶´

CVE   ID

CVE-2024-23113

©¶´ÀàÐÍ

ʹÓÃÍⲿ¿ØÖƵĸñʽ×Ö·û´®

·¢ÏÖʱ¼ä

2024-02-19

©¶´ÆÀ·Ö

9.8

©¶´Æ·¼¶

¸ßΣ

¹¥»÷ÏòÁ¿

ÍøÂç

ËùÐèȨÏÞ

ÎÞ

ÀûÓÃÄѶÈ

µÍ

Óû§½»»¥

ÎÞ

PoC/EXP

δ¹ûÈ»

ÔÚÒ°ÀûÓÃ

ÒÑ·¢ÏÖ

 

Fortinet£¨·ÉËþ£©¹«Ë¾ÊÇÒ»¼ÒÈ«ÇòÖªÃûµÄÍøÂçÄþ¾²²úÎïºÍÄþ¾²½â¾ö·½°¸ÌṩÉÌ£¬Æä²úÎï°üÂÞ·À»ðǽºÍVPN¡¢·À²¡¶¾Èí¼þ¡¢ÈëÇÖ·ÀÓùϵͳºÍÖÕ¶ËÄþ¾²×é¼þµÈ ¡£FortiOSÊÇFortinet¿ª·¢µÄÒ»Ì×רÓÃÓÚFortiGateÉϵÄÄþ¾²²Ù×÷ϵͳ£¬ÎªÓû§Ìṩ·À»ðǽ¡¢·À²¡¶¾¡¢VPN¡¢WebÄÚÈݹýÂ˺ͷ´À¬»øÓʼþµÈ¶àÖÖÄþ¾²¹¦Ð§ ¡£

2024Äê2ÔÂ19ÈÕ£¬¶«É­Æ½Ì¨¼¯ÍÅVSRC¼à²âµ½FortinetÐû²¼Äþ¾²Í¨¸æ£¬ÐÞ¸´ÁËFortinet¶à¿î²úÎïÖеÄÒ»¸ö¸ñʽ×Ö·û´®Â©¶´£¨CVE-2024-23113£©£¬ÆäCVSSÆÀ·ÖΪ9.8£¬Ä¿Ç°¸Ã©¶´µÄ¼¼Êõϸ½ÚÒѹûÈ»£¬ÇÒÒÑ·¢ÏÖ±»ÀûÓà ¡£

ÓÉÓÚFortinet FortiOS¡¢FortiProxy¡¢FortiPAMºÍFortiWebµÈ²úÎï¶à¸öÊÜÓ°Ïì°æ±¾ÖÐfgfmdÊØ»¤½ø³Ì½ÓÊÜÍⲿ¿ØÖƵĸñʽ×Ö·û´®×÷Ϊ²ÎÊý£¬¿ÉÄܵ¼ÖÂδ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õßͨ¹ýÌØÖÆÇëÇóÔÚÊÜÓ°ÏìÉ豸ÖÐÖ´ÐÐÈÎÒâÃüÁî»ò´úÂë ¡£


¶þ¡¢Ó°Ï췶Χ

ÊÜÓ°Ïì²úÎï

ÊÜÓ°Ïì°æ±¾

Ó°Ï췶Χ

ÐÞ¸´°æ±¾

FortiOS

FortiOS   7.4

7.4.0   - 7.4.2

Éý¼¶µ½7.4.3»ò¸ü¸ß°æ±¾

FortiOS   7.2

7.2.0   - 7.2.6

Éý¼¶µ½7.2.7 »ò¸ü¸ß°æ±¾

FortiOS   7.0

7.0.0   - 7.0.13

Éý¼¶µ½7.0.14 »ò¸ü¸ß°æ±¾

FortiPAM

FortiPAM   1.3

²»ÊÜÓ°Ïì

²»ÊÊÓÃ

FortiPAM   1.2

1.2   ËùÓа汾

ǨÒÆÖÁ1.3»ò¸ü¸ß°æ±¾

FortiPAM   1.1

1.1   ËùÓа汾

ǨÒÆÖÁ1.3»ò¸ü¸ß°æ±¾

FortiPAM   1.0

1.0   ËùÓа汾

ǨÒÆÖÁ1.3»ò¸ü¸ß°æ±¾

FortiProxy

FortiProxy   7.4

7.4.0   - 7.4.2

Éý¼¶µ½ 7.4.3 »ò¸ü¸ß°æ±¾

FortiProxy   7.2

7.2.0   - 7.2.8

Éý¼¶µ½ 7.2.9 »ò¸ü¸ß°æ±¾

FortiProxy   7.0

7.0.0   - 7.0.15

Éý¼¶µ½ 7.0.16 »ò¸ü¸ß°æ±¾

FortiWeb

FortiWeb   7.4

7.4.0   - 7.4.2

Éý¼¶µ½ 7.4.3 »ò¸ü¸ß°æ±¾

 

Èý¡¢Äþ¾²´ëÊ©

3.1 Éý¼¶°æ±¾

FortinetÒÑÔÚ2ÔÂÐû²¼Á˸鶴µÄÐÞ¸´·¨Ê½£¬Shadowserver »ù½ð»á×î½üÐû²¼µÄÒ»·Ý³ÂËßÏÔʾ£¬Ä¿Ç°»¥ÁªÍøÉÏÈÔ´æÔÚ´óÁ¿Ò×Êܹ¥»÷µÄFortinetÉ豸£¬ÊÜÓ°ÏìÓû§¿É²Î¿¼ÉÏ±í¼°Ê±Éý¼¶µ½ÏàÓ¦ÐÞ¸´°æ±¾ ¡£

ÏÂÔØÁ´½Ó£º

https://docs.fortinet.com/product/fortigate/7.4

3.2 ÁÙʱ´ëÊ©

¶ÔÓÚÿ¸ö½Ó¿Ú£¬¿Éͨ¹ýÒƳý¶ÔÒ×Êܹ¥»÷µÄ fgfmd ÊØ»¤½ø³ÌµÄ·ÃÎÊ£¬ÀýÈ罫£º

config system interface

edit "portX"

set allowaccess ping https ssh fgfm

next

end

¸ü¸ÄΪ£º

config system interface

edit "portX"

set allowaccess ping https ssh

next

end

×¢Ò⣬Õ⽫×èÖ¹FortiManager ·¢ÏÖ FortiGate£¬µ«ÈÔÈ»¿ÉÒÔͨ¹ýÆäËû·½Ê½ÓëFortiManager»òÆäËûÍøÂçÉ豸½øÐÐͨÐźÍÁ¬½Ó ¡£

´ËÍ⣬¹ÜÀíÔ±¿Éʵʩµ±µØ¼Æı£¬ÏÞÖƽöÔÊÐíÌض¨IPµØÖ·µÄ FGFM Á¬½Ó£¬ÒÔ¼õÉÙ¹¥»÷Ãæ ¡£

3.3 ͨÓý¨Òé

l  ¶¨ÆÚ¸üÐÂϵͳ²¹¶¡£¬¼õÉÙϵͳ©¶´£¬ÌáÉý·þÎñÆ÷µÄÄþ¾²ÐÔ ¡£

l  ¼ÓǿϵͳºÍÍøÂçµÄ·ÃÎÊ¿ØÖÆ£¬Ð޸ķÀ»ðǽ¼Æı£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻò·þÎñ£¬¼õÉÙ½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬¼õÉÙ¹¥»÷Ãæ ¡£

l  ʹÓÃÆóÒµ¼¶Äþ¾²²úÎÌáÉýÆóÒµµÄÍøÂçÄþ¾²ÐÔÄÜ ¡£

l  ¼ÓǿϵͳÓû§ºÍȨÏÞ¹ÜÀí£¬ÆôÓöàÒòËØÈÏÖ¤»úÖƺÍ×îСȨÏÞÔ­Ôò£¬Óû§ºÍÈí¼þȨÏÞÓ¦±£³ÖÔÚ×îµÍÏÞ¶È ¡£

l  ÆôÓÃÇ¿ÃÜÂë¼Æı²¢ÉèÖÃΪ¶¨ÆÚÐÞ¸Ä ¡£

3.4 ²Î¿¼Á´½Ó

https://www.fortiguard.com/psirt/FG-IR-24-029

https://nvd.nist.gov/vuln/detail/CVE-2024-23113

https://x.com/Shadowserver/status/1845478432479846737

https://labs.watchtowr.com/fortinet-fortigate-cve-2024-23113-a-super-complex-vulnerability-in-a-super-secure-appliance-in-2024/


ËÄ¡¢°æ±¾ÐÅÏ¢

°æ±¾

ÈÕÆÚ

±¸×¢

V1.0

2024-10-15

Ê×´ÎÐû²¼

 


Îå¡¢¸½Â¼

5.1 ¶«É­Æ½Ì¨¼ò½é

¶«É­Æ½Ì¨½¨Á¢ÓÚ1996Ä꣬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ´´½¨µÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢Äþ¾²¸ß¿Æ¼¼ÆóÒµ ¡£ÊǹúÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Äþ¾²²úÎï¡¢Äþ¾²·þÎñ½â¾ö·½°¸µÄÁ캽ÆóÒµÖ®Ò» ¡£

¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°¶«É­Æ½Ì¨´óÏ㬹«Ë¾Ô±¹¤6000ÓàÈË£¬Ñз¢ÍŶÓ1200ÓàÈË, ¼¼Êõ·þÎñÍŶÓ1300ÓàÈË ¡£ÔÚÈ«¹ú¸÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬ÓµÓÐÁýÕÖÈ«¹úµÄÏúÊÛÌåϵ¡¢ÇþµÀÌåϵºÍ¼¼ÊõÖ§³ÖÌåϵ ¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐС°å¹ÒÅÆÉÏÊÐ ¡££¨¹ÉƱ´úÂ룺002439£©

¶àÄêÀ´£¬¶«É­Æ½Ì¨ÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷´´ÐµÄÄþ¾²²úÎïºÍ×î¼Ñʵ¼ù·þÎñ£¬×ÊÖú¿Í»§È«ÃæÌáÉýÆäIT»ù´¡ÉèÊ©µÄÄþ¾²ÐÔºÍÉú²úЧÄÜ£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Äþ¾²¹¤ÒµÁì¾üÆ·Åƶø²»Ð¸Å¬Á¦ ¡£

5.2 ¹ØÓÚ¶«É­Æ½Ì¨

¶«É­Æ½Ì¨Äþ¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÒÑÐû²¼1000¶à¸ö©¶´Í¨¸æºÍ·çÏÕÔ¤¾¯£¬ÎÒÃǽ«Á¬Ðø¸ú×ÙÈ«Çò×îеÄÍøÂçÄþ¾²Ê¼þºÍ©¶´£¬ÎªÆóÒµµÄÐÅÏ¢Äþ¾²±£¼Ý»¤º½ ¡£

¹Ø×¢ÎÒÃÇ£º

image.png