¡¾Îó²îͨ¸æ¡¿Fortinet¶à¸öÇå¾²Îó²î
Ðû²¼Ê±¼ä 2021-01-070x00 Îó²î¸ÅÊö
²úÆ·Ãû³Æ | CVE ID | Àà ÐÍ | Îó²îÆ·¼¶ | Ô¶³ÌʹÓà |
FortiGate SSL VPN | CVE-2020-29010 | ÐÅϢй¶ | ÖÐΣ | ÊÇ |
FortiWeb | CVE-2020-29015 | SQL×¢Èë | ÖÐΣ | ÊÇ |
CVE-2020-29016 | »º³åÇøÒç³ö | ÖÐΣ | ÊÇ | |
CVE-2020-29018 | ÐÅϢй¶ | ÖÐΣ | ÊÇ | |
CVE-2020-29019 | »º³åÇøÒç³ö | ÖÐΣ | ÊÇ | |
FortiDeceptor | CVE-2020-29017 | ÏÂÁî×¢Èë | ¸ßΣ | ÊÇ |
0x01 Îó²îÏêÇé
Fortinet£¨·ÉËþ£©ÊÇÃÀ¹úÒ»¼ÒÍøÂçÇå¾²¹«Ë¾£¬£¬£¬£¬£¬×÷Ϊ¶à²ãÍþв·ÀÓùϵͳµÄÁ¢ÒìÕߺÍÏȷ棬£¬£¬£¬£¬ÆäÉæ¼°µÄÇ徲ϵͳº¸Ç·À²¡¶¾¡¢·À»ðǽ¡¢VPN¡¢ÈëÇÖ¼ì²âºÍ·ÀÓù¡¢·´À¬»øÓʼþºÍÁ÷Á¿ÓÅ»¯µÈ¡£¡£¡£¡£¡£
2021Äê01ÔÂ04ÈÕ£¬£¬£¬£¬£¬FortiGuardʵÑéÊÒÐû²¼Ç徲ͨ¸æ£¬£¬£¬£¬£¬¹ûÕæÁËÆä¶à¿î²úÆ·ÖеĶà¸öÇå¾²Îó²î£¬£¬£¬£¬£¬Ï¸½ÚÈçÏ£º
FortiGate SSL VPNÐÅϢй¶Îó²î£¨CVE-2020-29010£©
FortiGate SSL VPNÖб£´æÒ»¸öÐÅϢй¶Îó²î£¬£¬£¬£¬£¬ÆäCVSSÆÀ·Ö4.9¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔͨ¹ý´ÓCLIÖ´ÐС° get vpn ssl monitor¡±ÏÂÁîÀ´¶ÁÈ¡ÆäËüVDOMÖÐÓû§µÄSSL VPNÊÂÎñÈÕÖ¾¼Í¼£¬£¬£¬£¬£¬ÆäÖÐÃô¸ÐÊý¾Ý°üÀ¨Óû§Ãû¡¢Óû§×éºÍIPµØµã¡£¡£¡£¡£¡£
Ó°Ïì¹æÄ£
FortiGate 6.0.10¼°Ö®Ç°°æ±¾¡£¡£¡£¡£¡£
FortiGate 6.2.4¼°Ö®Ç°°æ±¾¡£¡£¡£¡£¡£
FortiGate 6.4.1¼°Ö®Ç°°æ±¾¡£¡£¡£¡£¡£
FortiWeb SQL×¢ÈëÎó²î£¨CVE-2020-29015£©
FortiWebÓû§½çÃæ±£´æÒ»¸öSQL×¢ÈëÎó²î£¬£¬£¬£¬£¬ÆäCVSSÆÀ·Ö6.4¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔͨ¹ý·¢ËͰüÀ¨¶ñÒâSQLÓï¾äµÄAuthorization±êÍ·µÄÇëÇóÀ´Ö´ÐÐí§ÒâSQLÅÌÎÊ»òÏÂÁî¡£¡£¡£¡£¡£
Ó°Ïì¹æÄ£
FortiWeb 6.3.7¼°Ö®Ç°°æ±¾¡£¡£¡£¡£¡£
FortiWeb 6.2.3¼°Ö®Ç°°æ±¾¡£¡£¡£¡£¡£
FortiWeb»º³åÇøÒç³öÎó²î£¨CVE-2020-29016£©
FortiWebÖб£´æÒ»¸ö»ùÓÚ¿ÍÕ»µÄ»º³åÇøÒç³öÎó²î£¬£¬£¬£¬£¬ÆäCVSSÆÀ·Ö6.4¡£¡£¡£¡£¡£¹¥»÷ÕßÄܹ»Ê¹ÓôËÎó²îÁýÕÖ¿ÍÕ»µÄÄÚÈÝ£¬£¬£¬£¬£¬²¢Í¨¹ý·¢ËÍ´øÓÐÖ¤ÊéÃûµÄ¶ñÒâÇëÇóÀ´Ö´ÐÐí§ÒâÏÂÁî»ò´úÂë¡£¡£¡£¡£¡£
Ó°Ïì¹æÄ£
FortiWeb 6.3.5¼°Ö®Ç°°æ±¾¡£¡£¡£¡£¡£
FortiWeb 6.2.3¼°Ö®Ç°°æ±¾¡£¡£¡£¡£¡£
FortiDeceptorÏÂÁî×¢ÈëÎó²î£¨CVE-2020-29017£©
FortiDeceptorµÄ×Ô½çËµÒ³ÃæÖб£´æÒ»¸öOSÏÂÁî×¢ÈëÎó²î£¬£¬£¬£¬£¬ÆäCVSSÆÀ·Ö8.1¡£¡£¡£¡£¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔÔÚϵͳÉÏÖ´ÐÐí§ÒâÏÂÁî¡£¡£¡£¡£¡£
Ó°Ïì¹æÄ£
FortiDeceptor 3.1.0¼°Ö®Ç°°æ±¾¡£¡£¡£¡£¡£
FortiDeceptor 3.0.1¼°Ö®Ç°°æ±¾¡£¡£¡£¡£¡£
FortiWebÐÅϢй¶Îó²î£¨CVE-2020-29018£©
FortiWebÖб£´æÒ»¸öÃûÌÃ×Ö·û´®Îó²î£¬£¬£¬£¬£¬ÆäCVSSÆÀ·Ö5.3¡£¡£¡£¡£¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷¿ÉÒÔͨ¹ýredir²ÎÊý¶ÁÈ¡ÄÚ´æÄÚÈݲ¢¼ìË÷Ãô¸ÐÊý¾Ý¡£¡£¡£¡£¡£
Ó°Ïì¹æÄ£
FortiWeb 6.3.5¼°Ö®Ç°°æ±¾¡£¡£¡£¡£¡£
FortiWeb»º³åÇøÒç³öÎó²î£¨CVE-2020-29019£©
FortiWebÖб£´æÒ»¸ö»ùÓÚ¿ÍÕ»µÄ»º³åÇøÒç³öÎó²î£¬£¬£¬£¬£¬ÆäCVSSÆÀ·Ö6.4¡£¡£¡£¡£¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔͨ¹ý·¢ËÍ´øÓжñÒâCookie±êÍ·µÄÇëÇóÀ´Ê¹httpdÊØ»¤³ÌÐòÏß³ÌÍ߽⣬£¬£¬£¬£¬×îÖÕµ¼Ö¾ܾøÐ§ÀÍ¡£¡£¡£¡£¡£
Ó°Ïì¹æÄ£
FortiWeb 6.3.7¼°Ö®Ç°°æ±¾¡£¡£¡£¡£¡£
FortiWeb 6.2.3¼°Ö®Ç°°æ±¾¡£¡£¡£¡£¡£
0x02 ´¦Öóͷ£½¨Òé
ÏÖÔÚFortinetÒѾÐÞ¸´ÁËÏà¹ØÎó²î£¬£¬£¬£¬£¬½¨Òé²Î¿¼Ï±íʵʱÉý¼¶¡£¡£¡£¡£¡£
Îó²î±àºÅ | ÐÞ¸´°æ±¾ |
CVE-2020-29010 | FortiGate 6.0.11»ò¸ü¸ß°æ±¾¡£¡£¡£¡£¡£ FortiGate 6.2.5»ò¸ü¸ß°æ±¾¡£¡£¡£¡£¡£ FortiGate 6.4.2»ò¸ü¸ß°æ±¾¡£¡£¡£¡£¡£ |
CVE-2020-29015 | FortiWeb 6.3.8»ò¸ü¸ß°æ±¾¡£¡£¡£¡£¡£ FortiWeb 6.2.4»ò¸ü¸ß°æ±¾¡£¡£¡£¡£¡£ |
CVE-2020-29016 | FortiWeb 6.3.6»ò¸ü¸ß°æ±¾¡£¡£¡£¡£¡£ FortiWeb 6.2.4»ò¸ü¸ß°æ±¾¡£¡£¡£¡£¡£ |
CVE-2020-29017 | FortiDeceptor 3.2.0»ò¸ü¸ß°æ±¾¡£¡£¡£¡£¡£ FortiDeceptor 3.1.1»ò¸ü¸ß°æ±¾¡£¡£¡£¡£¡£ FortiDeceptor 3.0.2»ò¸ü¸ß°æ±¾¡£¡£¡£¡£¡£ |
CVE-2020-29018 | FortiWeb 6.3.6»ò¸ü¸ß°æ±¾¡£¡£¡£¡£¡£ |
CVE-2020-29019 | FortiWeb 6.3.8»ò¸ü¸ß°æ±¾¡£¡£¡£¡£¡£ FortiWeb 6.2.4»ò¸ü¸ß°æ±¾¡£¡£¡£¡£¡£ |
0x03 ²Î¿¼Á´½Ó
https://www.fortiguard.com/psirt
https://www.fortiguard.com/psirt/%20FG-IR-20-124
https://www.fortinet.com/resources?
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-29015
0x04 ʱ¼äÏß
2021-01-04 FortiGuardÐû²¼Ç徲ͨ¸æ
2021-01-07 VSRCÐû²¼Ç徲ͨ¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/