¡¾Îó²îͨ¸æ¡¿Fortinet FortiOSÓëFortiProxyÉí·ÝÑéÖ¤ÈÆ¹ýÎó²î(CVE-2024-55591)
Ðû²¼Ê±¼ä 2025-01-16Ò»¡¢Îó²î¸ÅÊö
Îó²îÃû³Æ | Fortinet FortiOSÓëFortiProxyÉí·ÝÑéÖ¤ÈÆ¹ýÎó²î | ||
CVE ID | CVE-2024-55591 | ||
Îó²îÀàÐÍ | Éí·ÝÑéÖ¤ÈÆ¹ý | ·¢Ã÷ʱ¼ä | 2025-01-16 |
Îó²îÆÀ·Ö | 9.8 | Îó²îÆ·¼¶ | ÑÏÖØ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | µÍ |
ʹÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ÎÞ |
PoC/EXP | δ¹ûÕæ | ÔÚҰʹÓà | ÒÑ·¢Ã÷ |
FortiOS ÊÇ Fortinet ÌṩµÄ²Ù×÷ϵͳ£¬£¬£¬£¬£¬£¬£¬ÓÃÓÚÆäÇå¾²×°±¸£¨Èç·À»ðǽ£©¡£¡£¡£¡£¡£¡£FortiProxy ÊÇ FortiOS µÄÒ»¸ö×é¼þ£¬£¬£¬£¬£¬£¬£¬Ö÷ÒªÓÃÓÚÊðÀíЧÀÍ£¬£¬£¬£¬£¬£¬£¬Ìṩ·´ÏòÊðÀí¡¢Web Ó¦Ó÷À»ðǽµÈ¹¦Ð§£¬£¬£¬£¬£¬£¬£¬×ÊÖúÆóÒµ±£»£»£»£»£»¤Æä Web Ó¦ÓÃÃâÊܹ¥»÷²¢ÓÅ»¯ÍøÂçÁ÷Á¿¡£¡£¡£¡£¡£¡£
2025Äê1ÔÂ16ÈÕ£¬£¬£¬£¬£¬£¬£¬¼øºÚµ£±£Íø¼¯ÍÅVSRC¼à²âµ½Fortinet ¹Ù·½Ðû²¼Ç徲ͨ¸æ£¬£¬£¬£¬£¬£¬£¬Ö¸³ö FortiOS ºÍ FortiProxy ±£´æÒ»¸öÉí·ÝÑéÖ¤ÈÆ¹ýÎó²î£¨CVE-2024-55591£©£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿Éͨ¹ýÈ«ÐĽṹµÄÇëÇ󣬣¬£¬£¬£¬£¬£¬Ê¹Óà Node.js WebSocket Ä£¿£¿£¿£¿£¿£¿£¿é£¬£¬£¬£¬£¬£¬£¬ÈƹýÉí·ÝÑéÖ¤²¢»ñÈ¡³¬µÈÖÎÀíԱȨÏÞ¡£¡£¡£¡£¡£¡£¸ÃÎó²îµÄ CVSS Îó²îÆÀ·ÖΪ 9.8 ·Ö£¬£¬£¬£¬£¬£¬£¬Îó²î¼¶±ðΪÑÏÖØ£¬£¬£¬£¬£¬£¬£¬¿ÉÄܵ¼ÖÂÔ¶³Ì¹¥»÷Õß¶ÔÊÜÓ°ÏìϵͳµÄÍêÈ«¿ØÖÆ¡£¡£¡£¡£¡£¡£
¶þ¡¢Ó°Ïì¹æÄ£
7.0.0 <= FortiOS 7.0 <= 7.0.16
Èý¡¢Çå¾²²½·¥
3.1 Éý¼¶°æ±¾
ÏÂÔØÁ´½Ó£º