
CVE-2023-34992: Fortinet FortiSIEM Command Injection Proof-of-Concept-Exploit
Proof of Concept-Exploit zur blinden Ausführung von Befehlen als root auf anfälligen FortiSIEM-Geräten
Grundursache und Indikatoren einer Kompromittierung hier: https://www.horizon3.ai/attack-research/disclosures/cve-2023-34992-fortinet-fortisiem-command-injection-deep-dive
% python3 CVE-2023-34992.py -h
usage: CVE-2023-34992.py [-h] -t TARGET [-p PORT] -c COMMAND
options:
-h, --help show this help message and exit
-t TARGET, --target TARGET
The IP address of the target
-p PORT, --port PORT The port of the Phoenix Monitor service
-c COMMAND, --command COMMAND
The command to blindly execute
Diese Software wurde ausschließlich für akademische Forschungszwecke und zur Entwicklung effektiver Abwehrtechniken erstellt und ist nicht dazu bestimmt, Systeme anzugreifen, es sei denn, dies wurde ausdrücklich autorisiert. Die Projektbetreiber übernehmen keine Verantwortung oder Haftung für Missbrauch der Software. Verwenden Sie sie verantwortungsbewusst.