¡¾Â©¶´Í¨¸æ¡¿Fortinet FortiOSÓëFortiProxyÉí·ÝÑéÖ¤Èƹý©¶´(CVE-2024-55591)
Ðû²¼Ê±¼ä 2025-01-16Ò»¡¢Â©¶´¸ÅÊö
©¶´Ãû³Æ | Fortinet FortiOSÓëFortiProxyÉí·ÝÑéÖ¤Èƹý©¶´ | ||
CVE ID | CVE-2024-55591 | ||
©¶´ÀàÐÍ | Éí·ÝÑéÖ¤Èƹý | ·¢ÏÖʱ¼ä | 2025-01-16 |
©¶´ÆÀ·Ö | 9.8 | ©¶´Æ·¼¶ | ÑÏÖØ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | µÍ |
ÀûÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ÎÞ |
PoC/EXP | δ¹ûÈ» | ÔÚÒ°ÀûÓà | ÒÑ·¢ÏÖ |
FortiOS ÊÇ Fortinet ÌṩµÄ²Ù×÷ϵͳ£¬ÓÃÓÚÆäÄþ¾²É豸£¨Èç·À»ðǽ£©¡£FortiProxy ÊÇ FortiOS µÄÒ»¸ö×é¼þ£¬Ö÷ÒªÓÃÓÚÊðÀí·þÎñ£¬Ìṩ·´ÏòÊðÀí¡¢Web Ó¦Ó÷À»ðǽµÈ¹¦Ð§£¬×ÊÖúÆóÒµ±£»¤Æä Web Ó¦ÓÃÃâÊܹ¥»÷²¢ÓÅ»¯ÍøÂçÁ÷Á¿¡£
2025Äê1ÔÂ16ÈÕ£¬¶«Éƽ̨¼¯ÍÅVSRC¼à²âµ½Fortinet ¹Ù·½Ðû²¼Äþ¾²Í¨¸æ£¬Ö¸³ö FortiOS ºÍ FortiProxy ´æÔÚÒ»¸öÉí·ÝÑéÖ¤Èƹý©¶´£¨CVE-2024-55591£©£¬¹¥»÷Õß¿Éͨ¹ý¾«ÐĽṹµÄÇëÇó£¬ÀûÓà Node.js WebSocket Ä£¿é£¬ÈƹýÉí·ÝÑéÖ¤²¢»ñÈ¡³¬¼¶¹ÜÀíԱȨÏÞ¡£¸Ã©¶´µÄ CVSS ©¶´ÆÀ·ÖΪ 9.8 ·Ö£¬Â©¶´¼¶±ðΪÑÏÖØ£¬¿ÉÄܵ¼ÖÂÔ¶³Ì¹¥»÷Õ߶ÔÊÜÓ°ÏìϵͳµÄÍêÈ«¿ØÖÆ¡£
¶þ¡¢Ó°Ï췶Χ
7.0.0 <= FortiOS 7.0 <= 7.0.16
Èý¡¢Äþ¾²´ëÊ©
3.1 Éý¼¶°æ±¾
ÏÂÔØÁ´½Ó£º