¡¾Îó²îͨ¸æ¡¿Fortinet¶à¸öÇå¾²Îó²î

Ðû²¼Ê±¼ä 2021-01-07

0x00 Îó²î¸ÅÊö

²úÆ·Ãû³Æ

CVE   ID

Àà   ÐÍ

Îó²îÆ·¼¶

Ô¶³ÌʹÓÃ

FortiGate   SSL VPN

CVE-2020-29010

ÐÅϢй¶

ÖÐΣ

ÊÇ

FortiWeb

CVE-2020-29015

SQL×¢Èë

ÖÐΣ

ÊÇ

CVE-2020-29016

»º³åÇøÒç³ö

ÖÐΣ

ÊÇ

CVE-2020-29018

ÐÅϢй¶

ÖÐΣ

ÊÇ

CVE-2020-29019

»º³åÇøÒç³ö

ÖÐΣ

ÊÇ

FortiDeceptor

CVE-2020-29017

ÏÂÁî×¢Èë

¸ßΣ

ÊÇ

0x01 Îó²îÏêÇé

2.png


Fortinet£¨·ÉËþ£©ÊÇÃÀ¹úÒ»¼ÒÍøÂçÇå¾²¹«Ë¾£¬ £¬£¬£¬£¬×÷Ϊ¶à²ãÍþв·ÀÓùϵͳµÄÁ¢ÒìÕߺÍÏȷ棬 £¬£¬£¬£¬ÆäÉæ¼°µÄÇ徲ϵͳº­¸Ç·À²¡¶¾¡¢·À»ðǽ¡¢VPN¡¢ÈëÇÖ¼ì²âºÍ·ÀÓù¡¢·´À¬»øÓʼþºÍÁ÷Á¿ÓÅ»¯µÈ¡£¡£¡£¡£¡£

2021Äê01ÔÂ04ÈÕ£¬ £¬£¬£¬£¬FortiGuardʵÑéÊÒÐû²¼Ç徲ͨ¸æ£¬ £¬£¬£¬£¬¹ûÕæÁËÆä¶à¿î²úÆ·ÖеĶà¸öÇå¾²Îó²î£¬ £¬£¬£¬£¬Ï¸½ÚÈçÏ£º

FortiGate SSL VPNÐÅϢй¶Îó²î£¨CVE-2020-29010£©

FortiGate SSL VPNÖб£´æÒ»¸öÐÅϢй¶Îó²î£¬ £¬£¬£¬£¬ÆäCVSSÆÀ·Ö4.9¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔͨ¹ý´ÓCLIÖ´ÐС° get vpn ssl monitor¡±ÏÂÁîÀ´¶ÁÈ¡ÆäËüVDOMÖÐÓû§µÄSSL VPNÊÂÎñÈÕÖ¾¼Í¼£¬ £¬£¬£¬£¬ÆäÖÐÃô¸ÐÊý¾Ý°üÀ¨Óû§Ãû¡¢Óû§×éºÍIPµØµã¡£¡£¡£¡£¡£

Ó°Ïì¹æÄ£

FortiGate 6.0.10¼°Ö®Ç°°æ±¾¡£¡£¡£¡£¡£

FortiGate 6.2.4¼°Ö®Ç°°æ±¾¡£¡£¡£¡£¡£

FortiGate 6.4.1¼°Ö®Ç°°æ±¾¡£¡£¡£¡£¡£

 

FortiWeb SQL×¢ÈëÎó²î£¨CVE-2020-29015£©

FortiWebÓû§½çÃæ±£´æÒ»¸öSQL×¢ÈëÎó²î£¬ £¬£¬£¬£¬ÆäCVSSÆÀ·Ö6.4¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔͨ¹ý·¢ËͰüÀ¨¶ñÒâSQLÓï¾äµÄAuthorization±êÍ·µÄÇëÇóÀ´Ö´ÐÐí§ÒâSQLÅÌÎÊ»òÏÂÁî¡£¡£¡£¡£¡£

Ó°Ïì¹æÄ£

FortiWeb 6.3.7¼°Ö®Ç°°æ±¾¡£¡£¡£¡£¡£

FortiWeb 6.2.3¼°Ö®Ç°°æ±¾¡£¡£¡£¡£¡£

 

FortiWeb»º³åÇøÒç³öÎó²î£¨CVE-2020-29016£©

FortiWebÖб£´æÒ»¸ö»ùÓÚ¿ÍÕ»µÄ»º³åÇøÒç³öÎó²î£¬ £¬£¬£¬£¬ÆäCVSSÆÀ·Ö6.4¡£¡£¡£¡£¡£¹¥»÷ÕßÄܹ»Ê¹ÓôËÎó²îÁýÕÖ¿ÍÕ»µÄÄÚÈÝ£¬ £¬£¬£¬£¬²¢Í¨¹ý·¢ËÍ´øÓÐÖ¤ÊéÃûµÄ¶ñÒâÇëÇóÀ´Ö´ÐÐí§ÒâÏÂÁî»ò´úÂë¡£¡£¡£¡£¡£

Ó°Ïì¹æÄ£

FortiWeb 6.3.5¼°Ö®Ç°°æ±¾¡£¡£¡£¡£¡£

FortiWeb 6.2.3¼°Ö®Ç°°æ±¾¡£¡£¡£¡£¡£

 

FortiDeceptorÏÂÁî×¢ÈëÎó²î£¨CVE-2020-29017£©

FortiDeceptorµÄ×Ô½çËµÒ³ÃæÖб£´æÒ»¸öOSÏÂÁî×¢ÈëÎó²î£¬ £¬£¬£¬£¬ÆäCVSSÆÀ·Ö8.1¡£¡£¡£¡£¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔÔÚϵͳÉÏÖ´ÐÐí§ÒâÏÂÁî¡£¡£¡£¡£¡£

Ó°Ïì¹æÄ£

FortiDeceptor 3.1.0¼°Ö®Ç°°æ±¾¡£¡£¡£¡£¡£

FortiDeceptor 3.0.1¼°Ö®Ç°°æ±¾¡£¡£¡£¡£¡£

 

FortiWebÐÅϢй¶Îó²î£¨CVE-2020-29018£©

FortiWebÖб£´æÒ»¸öÃûÌÃ×Ö·û´®Îó²î£¬ £¬£¬£¬£¬ÆäCVSSÆÀ·Ö5.3¡£¡£¡£¡£¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷¿ÉÒÔͨ¹ýredir²ÎÊý¶ÁÈ¡ÄÚ´æÄÚÈݲ¢¼ìË÷Ãô¸ÐÊý¾Ý¡£¡£¡£¡£¡£

Ó°Ïì¹æÄ£

FortiWeb 6.3.5¼°Ö®Ç°°æ±¾¡£¡£¡£¡£¡£

 

FortiWeb»º³åÇøÒç³öÎó²î£¨CVE-2020-29019£©

FortiWebÖб£´æÒ»¸ö»ùÓÚ¿ÍÕ»µÄ»º³åÇøÒç³öÎó²î£¬ £¬£¬£¬£¬ÆäCVSSÆÀ·Ö6.4¡£¡£¡£¡£¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔͨ¹ý·¢ËÍ´øÓжñÒâCookie±êÍ·µÄÇëÇóÀ´Ê¹httpdÊØ»¤³ÌÐòÏß³ÌÍ߽⣬ £¬£¬£¬£¬×îÖÕµ¼Ö¾ܾøÐ§ÀÍ¡£¡£¡£¡£¡£

Ó°Ïì¹æÄ£

FortiWeb 6.3.7¼°Ö®Ç°°æ±¾¡£¡£¡£¡£¡£

FortiWeb 6.2.3¼°Ö®Ç°°æ±¾¡£¡£¡£¡£¡£

 

0x02 ´¦Öóͷ£½¨Òé

ÏÖÔÚFortinetÒѾ­ÐÞ¸´ÁËÏà¹ØÎó²î£¬ £¬£¬£¬£¬½¨Òé²Î¿¼Ï±íʵʱÉý¼¶¡£¡£¡£¡£¡£

Îó²î±àºÅ

ÐÞ¸´°æ±¾

CVE-2020-29010

FortiGate 6.0.11»ò¸ü¸ß°æ±¾¡£¡£¡£¡£¡£

FortiGate 6.2.5»ò¸ü¸ß°æ±¾¡£¡£¡£¡£¡£

FortiGate 6.4.2»ò¸ü¸ß°æ±¾¡£¡£¡£¡£¡£

CVE-2020-29015

FortiWeb 6.3.8»ò¸ü¸ß°æ±¾¡£¡£¡£¡£¡£

FortiWeb 6.2.4»ò¸ü¸ß°æ±¾¡£¡£¡£¡£¡£

CVE-2020-29016

FortiWeb 6.3.6»ò¸ü¸ß°æ±¾¡£¡£¡£¡£¡£

FortiWeb 6.2.4»ò¸ü¸ß°æ±¾¡£¡£¡£¡£¡£

CVE-2020-29017

FortiDeceptor 3.2.0»ò¸ü¸ß°æ±¾¡£¡£¡£¡£¡£

FortiDeceptor 3.1.1»ò¸ü¸ß°æ±¾¡£¡£¡£¡£¡£

FortiDeceptor 3.0.2»ò¸ü¸ß°æ±¾¡£¡£¡£¡£¡£

CVE-2020-29018

FortiWeb 6.3.6»ò¸ü¸ß°æ±¾¡£¡£¡£¡£¡£

CVE-2020-29019

FortiWeb 6.3.8»ò¸ü¸ß°æ±¾¡£¡£¡£¡£¡£

FortiWeb 6.2.4»ò¸ü¸ß°æ±¾¡£¡£¡£¡£¡£

0x03 ²Î¿¼Á´½Ó

https://www.fortiguard.com/psirt

https://www.fortiguard.com/psirt/%20FG-IR-20-124

https://www.fortinet.com/resources?

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-29015

 

0x04 ʱ¼äÏß

2021-01-04  FortiGuardÐû²¼Ç徲ͨ¸æ

2021-01-07  VSRCÐû²¼Ç徲ͨ¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/


1.png