¡¾Îó²îͨ¸æ¡¿Fortinet FortiOSÓëFortiProxyÉí·ÝÑéÖ¤ÈÆ¹ýÎó²î(CVE-2024-55591)

Ðû²¼Ê±¼ä 2025-01-16

Ò»¡¢Îó²î¸ÅÊö


Îó²îÃû³Æ

Fortinet FortiOSÓëFortiProxyÉí·ÝÑéÖ¤ÈÆ¹ýÎó²î

CVE   ID

CVE-2024-55591

Îó²îÀàÐÍ

Éí·ÝÑéÖ¤ÈÆ¹ý

·¢Ã÷ʱ¼ä

2025-01-16

Îó²îÆÀ·Ö

9.8

Îó²îÆ·¼¶

ÑÏÖØ

¹¥»÷ÏòÁ¿

ÍøÂç

ËùÐèȨÏÞ

µÍ

ʹÓÃÄѶÈ

µÍ

Óû§½»»¥

ÎÞ

PoC/EXP

δ¹ûÕæ

ÔÚҰʹÓÃ

ÒÑ·¢Ã÷


FortiOS ÊÇ Fortinet ÌṩµÄ²Ù×÷ϵͳ£¬£¬£¬£¬£¬£¬£¬ÓÃÓÚÆäÇå¾²×°±¸£¨Èç·À»ðǽ£©¡£¡£¡£¡£¡£¡£FortiProxy ÊÇ FortiOS µÄÒ»¸ö×é¼þ£¬£¬£¬£¬£¬£¬£¬Ö÷ÒªÓÃÓÚÊðÀíЧÀÍ£¬£¬£¬£¬£¬£¬£¬Ìṩ·´ÏòÊðÀí¡¢Web Ó¦Ó÷À»ðǽµÈ¹¦Ð§£¬£¬£¬£¬£¬£¬£¬×ÊÖúÆóÒµ±£»£»£»£»£»¤Æä Web Ó¦ÓÃÃâÊܹ¥»÷²¢ÓÅ»¯ÍøÂçÁ÷Á¿¡£¡£¡£¡£¡£¡£


2025Äê1ÔÂ16ÈÕ£¬£¬£¬£¬£¬£¬£¬¼øºÚµ£±£Íø¼¯ÍÅVSRC¼à²âµ½Fortinet ¹Ù·½Ðû²¼Ç徲ͨ¸æ£¬£¬£¬£¬£¬£¬£¬Ö¸³ö FortiOS ºÍ FortiProxy ±£´æÒ»¸öÉí·ÝÑéÖ¤ÈÆ¹ýÎó²î£¨CVE-2024-55591£©£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿Éͨ¹ýÈ«ÐĽṹµÄÇëÇ󣬣¬£¬£¬£¬£¬£¬Ê¹Óà Node.js WebSocket Ä£¿ £¿£¿£¿£¿£¿£¿é£¬£¬£¬£¬£¬£¬£¬ÈƹýÉí·ÝÑéÖ¤²¢»ñÈ¡³¬µÈÖÎÀíԱȨÏÞ¡£¡£¡£¡£¡£¡£¸ÃÎó²îµÄ CVSS Îó²îÆÀ·ÖΪ 9.8 ·Ö£¬£¬£¬£¬£¬£¬£¬Îó²î¼¶±ðΪÑÏÖØ£¬£¬£¬£¬£¬£¬£¬¿ÉÄܵ¼ÖÂÔ¶³Ì¹¥»÷Õß¶ÔÊÜÓ°ÏìϵͳµÄÍêÈ«¿ØÖÆ¡£¡£¡£¡£¡£¡£


¶þ¡¢Ó°Ïì¹æÄ£


7.0.0 <= FortiOS 7.0 <= 7.0.16

7.2.0 <= FortiProxy 7.2 <= 7.2.12
7.0.0 <= FortiProxy 7.0 <= 7.0.19


Èý¡¢Çå¾²²½·¥


3.1 Éý¼¶°æ±¾


ÏÖÔÚ¸ÃÎó²îÒѾ­ÐÞ¸´£¬£¬£¬£¬£¬£¬£¬ÊÜÓ°ÏìÓû§¿ÉÉý¼¶µ½ÒÔϰ汾£º
FortiOS 7.0 >= 7.0.17
FortiProxy 7.2 >= 7.2.13
FortiProxy 7.0 >= 7.0.20


ÏÂÔØÁ´½Ó£º

https://docs.fortinet.com/upgrade-tool


3.2 ÔÝʱ²½·¥


½ûÓà HTTP/HTTPS ÖÎÀí½çÃæ»òÕßͨ¹ýÍâµØÈëÕ¾Õ½ÂÔÏÞÖÆ¿ÉÒÔ»á¼ûÖÎÀí½çÃæµÄ IP µØµã


3.3 ͨÓý¨Òé


? °´ÆÚ¸üÐÂϵͳ²¹¶¡£¬£¬£¬£¬£¬£¬£¬ïÔ̭ϵͳÎó²î£¬£¬£¬£¬£¬£¬£¬ÌáÉýЧÀÍÆ÷µÄÇå¾²ÐÔ¡£¡£¡£¡£¡£¡£
ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬£¬£¬£¬£¬£¬£¬Ð޸ķÀ»ðǽսÂÔ£¬£¬£¬£¬£¬£¬£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻòЧÀÍ£¬£¬£¬£¬£¬£¬£¬ïÔÌ­½«Î£ÏÕЧÀÍ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬£¬£¬£¬£¬£¬£¬ïÔÌ­¹¥»÷Ãæ¡£¡£¡£¡£¡£¡£
ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬£¬£¬£¬£¬£¬£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£¡£¡£¡£¡£¡£
ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬£¬£¬£¬£¬£¬£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔ­Ôò£¬£¬£¬£¬£¬£¬£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏÞ¶È¡£¡£¡£¡£¡£¡£
ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£¡£¡£¡£¡£¡£


3.4 ²Î¿¼Á´½Ó


https://www.fortiguard.com/psirt/FG-IR-24-535
https://nvd.nist.gov/vuln/detail/CVE-2024-55591