¡¾Îó²îͨ¸æ¡¿Fortinet 8Ô¶à¸öÇå¾²Îó²î
Ðû²¼Ê±¼ä 2021-08-040x00 Îó²î¸ÅÊö
2021Äê8ÔÂ3ÈÕ£¬£¬£¬Fortinet£¨·ÉËþ£©Ðû²¼Ç徲ͨ¸æ£¬£¬£¬ÐÞ¸´ÁËÆä²úÆ·ÖеÄ22¸öÇå¾²Îó²î£¬£¬£¬ÕâЩÎó²îÉæ¼°FortiSandbox ¡¢FortiPortal¡¢ FortiManager¡¢FortiAnalyzer¡¢ FortiOSºÍFortiAuthenticator¡£¡£¡£
0x01 Îó²îÏêÇé

ÔÚ±¾´Î´ËÐÞ¸´µÄ22¸öÎó²îÖУ¬£¬£¬×îΪÑÏÖØµÄÊÇFortiPortalÖеÄÒ»¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-32588£©ºÍÒ»¸öSQL×¢ÈëÎó²î£¨CVE-2021-32590£©£¬£¬£¬¹¥»÷Õß¿ÉÒÔʹÓÃÕâ2¸öÎó²îÔÚδÊÚȨµÄÇéÐÎÏÂÖ´ÐÐí§ÒâÏÂÁî¡£¡£¡£
FortiPortalÊÇFortinet¹«Ë¾µÄÍйÜÔÆÇå¾²Õ½ÂÔÖÎÀíºÍÍþвÆÊÎö²úÆ·£¬£¬£¬×¨ÎªÖª×ãÍйÜЧÀÍÌṩÉÌ (MSP) µÄÍйÜЧÀÍÐèÇó¶øÉè¼Æ£¬£¬£¬ÆäÔÚ¶à×â»§¡¢¶à²ã¼¶ÖÎÀí¿ò¼ÜÄÚÌṩһÌ×ÖÜÈ«µÄ Wi-Fi ºÍÇå¾²ÖÎÀí¹¦Ð§£¬£¬£¬Ê¹µÃMSP Äܹ»Í¨¹ý¼òµ¥ÖÎÀíÆ½Ì¨Éó²é²¢ÖÎÀíÆä¿Í»§ÍøÂç¡£¡£¡£
Îó²îÏêÇéÈçÏ£º
FortiPortal Ô¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-32588£©
ÓÉÓÚFortiPortalÖб£´æÓ²±àÂëÆ¾Ö¤£¨CWE-798£©Îó²î£¬£¬£¬Î´¾ÈÏÖ¤µÄÔ¶³Ì¹¥»÷Õß¿ÉÒÔͨ¹ýʹÓÃĬÈϵÄÓ²±àÂëTomcatÖÎÀíÆ÷Óû§ÃûºÍÃÜÂëÉÏ´«ºÍ°²ÅŶñÒâWebÓ¦ÓóÌÐò´æµµÎļþ£¬£¬£¬²¢ÒÔrootÉí·ÝÖ´ÐÐí§ÒâÏÂÁ£¬£¬¸ÃÎó²îµÄCVSSv3ÆÀ·ÖΪ9.3¡£¡£¡£
Ó°Ïì¹æÄ£
FortiPortal 5.2.5 ¼°ÒÔϰ汾
FortiPortal 5.3.5 ¼°ÒÔϰ汾
FortiPortal 6.0.4 ¼°ÒÔϰ汾
FortiPortal 5.0.x
FortiPortal 5.1.x
FortiPortal SQL×¢ÈëÎó²î£¨CVE-2021-32590£©
FortiPortalÖб£´æSQL×¢ÈëÎó²î£¨CWE-89£©£¬£¬£¬¾ßÓÐͨË×Óû§È¨Ï޵Ĺ¥»÷Õß¿ÉÒÔͨ¹ý¶ñÒâÖÆ×÷µÄHTTPÇëÇóÔڵײãSQLÊý¾Ý¿âÉÏÖ´ÐÐí§ÒâÏÂÁ£¬£¬¸ÃÎó²îµÄCVSSv3ÆÀ·ÖΪ9.4¡£¡£¡£
Ó°Ïì¹æÄ£
FortiPortal 6.0.4 ¼°ÒÔϰ汾
FortiPortal 5.3.5 ¼°ÒÔϰ汾
FortiPortal 5.2.5 ¼°ÒÔϰ汾
FortiPortal 5.1.2 ¼°ÒÔϰ汾
FortiPortal 5.0.3 ¼°ÒÔϰ汾
FortiPortal 4.2.4 ¼°ÒÔϰ汾
FortiPortal 4.1.2 ¼°ÒÔϰ汾
FortiPortal 4.0.4 ¼°ÒÔϰ汾
FortiPortal 3.2.2 ¼°ÒÔϰ汾
³ýÉÏÊöÎó²îÍ⣬£¬£¬ÐèÒª×¢ÖØµÄ£¶¸ö¸ßΣÎó²î°üÀ¨£º
l FortiManager & FortiAnalyzerÖеÄSSRFÎó²î£¨CVE-2021-32603£©£º¹¥»÷Õß¿ÉʹÓôËÎó²îÖ´ÐÐδÊÚȨµÄ´úÂë»òÏÂÁî¡£¡£¡£
l FortiManager & FortiAnalyzer£¦FortiPortalÖеÄÏÂÁî×¢ÈëÎó²î£¨CVE-2021-26104£©£º¹¥»÷Õß¿ÉÒÔʹÓôËÎó²îÒÔ root Éí·ÝÖ´ÐÐí§Òâ shell ÏÂÁî¡£¡£¡£
l FortiSandboxÖеÄÏÂÁî×¢ÈëÎó²î£¨CVE-2021-26097£©£º¹¥»÷Õß¿ÉÒÔͨ¹ý·¢ËͶñÒâ HTTP ÇëÇóÖ´ÐÐδÊÚȨµÄ´úÂë»òÏÂÁî¡£¡£¡£
l FortiSandboxÖеÄ·¾¶±éÀúÎó²î£¨CVE-2021-24010£©£º¹¥»÷Õß¿ÉÒÔʹÓôËÎó²îʵÏÖδÊÚȨ»á¼ûÎļþ¡£¡£¡£
l FortiSandboxÖеÄSQL×¢ÈëÎó²î£¨CVE-2020-29011£©£º¹¥»÷Õß¿ÉÒÔʹÓôËÎó²îÔڵײãSQLÚ¹ÊÍÆ÷ÉÏÖ´ÐÐδÊÚȨµÄ´úÂë»òÏÂÁî¡£¡£¡£
l FortiSandbox £¦ FortiAuthenticatorÖеľܾøÐ§ÀÍÎó²î£¨CVE-2021-22124£©£ºÎ´¾Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔͨ¹ý·¢ËͶñÒâÇëÇóʹװ±¸½øÈëÎÞÏìӦ״̬¡£¡£¡£
0x02 ´¦Öóͷ£½¨Òé
ÏÖÔÚÕâЩÎó²îÒѾÐÞ¸´¡£¡£¡£
Õë¶ÔCVE-2021-32588£¬£¬£¬½¨ÒéʵʱÉý¼¶µ½ÒÔϰ汾£º
FortiPortal 5.2.6 »ò¸ü¸ß°æ±¾
FortiPortal 5.3.6 »ò¸ü¸ß°æ±¾
FortiPortal 6.0.5 »ò¸ü¸ß°æ±¾
Õë¶ÔCVE-2021-32590£¬£¬£¬½¨ÒéʵʱÉý¼¶µ½ÒÔϰ汾£º
FortiPortal 6.0.5 »ò¸ü¸ß°æ±¾
FortiPortal 5.3.6 »ò¸ü¸ß°æ±¾
FortiPortal 5.2.6 »ò¸ü¸ß°æ±¾
£¨×¢£º5.1¡¢5.0¡¢4.2¡¢4.1¡¢4.0ºÍ3.2°æ±¾µÄ²¹¶¡ÓдýÈ·ÈÏ¡£¡£¡££©
ÏÂÔØÁ´½Ó£º
https://www.fortinet.com/cn
0x03 ²Î¿¼Á´½Ó
https://www.fortiguard.com/psirt?date=08-2021
https://www.fortiguard.com/psirt/FG-IR-21-077
https://www.fortiguard.com/psirt/FG-IR-21-084
0x04 ¸üа汾
°æ±¾ | ÈÕÆÚ | ÐÞ¸ÄÄÚÈÝ |
V1.0 | 2021-08-04 | Ê×´ÎÐû²¼ |
0x05 Îĵµ¸½Â¼
CNVD£ºwww.cnvd.org.cn
CNNVD£ºwww.cnnvd.org.cn
CVE£ºcve.mitre.org
NVD£ºnvd.nist.gov
CVSS£ºwww.first.org
0x06 ¹ØÓÚc7c7ÓéÀÖÆ½Ì¨
¹Ø×¢ÒÔϹ«Öںţ¬£¬£¬»ñÈ¡¸ü¶à×ÊѶ£º



¾©¹«Íø°²±¸11010802024551ºÅ