Skip to content
KitploitKITPLOIT
HerramientasBlog
Enviar
HerramientasBlog
Enviar

¡Herramientas de Hacking, PenTest y Ciberseguridad para tu Arsenal de Seguridad!

Kitploit es un directorio de herramientas de hacking, ciberseguridad y pentesting. Descubre las últimas actualizaciones de proyectos para encontrar vulnerabilidades, analizar sistemas, automatizar pruebas y fortalecer tu seguridad.

··Feeds·Contacto·Privacidad·© 2026 Kitploit

Directorio de Herramientas

Categorías

Ver todas las categorías
Loading categories
CVE-2022-40684 — Exploit de bypass de autenticación para CVE-2022-40684 dirigido a FortiOS, FortiProxy y FortiSwitchManager. Comprueba la vulnerabilidad y sobrescribe las claves SSH de administrador. | Kitploit
Herramientas/GitHubGitHub/dkstar11q/cve-2022-40684
Análisis de VulnerabilidadesExplotaciónSeguridad WebPruebas de PenetraciónAutenticaciónRed Teaming
GitHubdkstar11q/cve-2022-40684

CVE-2022-40684

Exploit de bypass de autenticación para CVE-2022-40684 dirigido a FortiOS, FortiProxy y FortiSwitchManager. Comprueba la vulnerabilidad y sobrescribe las claves SSH de administrador.

Ver Repositorio
12hace 3 añosAún no revisado

Más Populares

Ver todos →

Descubre las herramientas más usadas por nuestra comunidad.

Explora todas las herramientas

Explora nuestra colección de herramientas

Ver todas las herramientas →
Compartir

Descripción

Exploit para la vulnerabilidad de omisión de autenticación CVE-2022-40684 que afecta a los dispositivos FortiOS, FortiProxy y FortiSwitchManager.

Descargo de responsabilidad

Esta herramienta está destinada únicamente con fines de demostración, úsela solo contra sistemas donde tenga autorización explícita. El mantenedor del proyecto no es responsable del uso indebido del software.

Uso

root@kitploit:~

              .,-:;//;:=,
          . :H@@@MM@M#H/.,+%;,
       ,/X+ +M@@M@MM%=,-%HMMM@X/,
     -+@MM; $M@@MH+-,;XMMMM@MMMM@+-
    ;@M@@M- XM@X;. -+XXXXXHHH@M@M#@/.
  ,%MM@@MH ,@%=             .---=-=:=,.
  =@#@@@MX.,                -%HX$$%%%:;
 =-./@M@M$                   .;@MMMM@MM:
 X@/ -$MM/    Developed by:    . +MM@@@M$
,@M@H: :@:   Mohamed Benchikh  . =X#@@@@-
,@@@MMX, .  (@mohamedbenchikh)  /H- ;@M@M=
.H@@@@M@+,                      %MM+..%#$.
 /MMMM@MMH/.                   XM@MH; =;
  /%+%$XHH@$=               , .H@@@@MX,
   .=--------.           -%H.,@@@@@MX,
   .%MM@@@HHHXX$$$%+- .:$MMX =M@@MM%.
     =XMMM@MM@MM#H;,-+HMM@M+ /MMMX=
       =%@M@M#@$-.=$@MM@@@M; %M%=
         ,:+$+-,/H#MMMMMMM@= =,
               =++%%%%+/:-.

Authentication Bypass Exploit (CVE-2022-40684)
Affected Products: FortiOS, FortiProxy and FortiSwitchManager
Use at your own risk!

usage: CVE-2022-40684.py [-h] [-t TARGET] [-c] [-a] [-v] [-k KEY_FILE]

optional arguments:
  -h, --help            show this help message and exit
  -t TARGET, --target TARGET
                        The IP address of the target
  -c, --check           Check if the target is vulnerable
  -a, --attack          Overwrite admin ssh key
  -v, --verbose         Increase Verbosity
  -k KEY_FILE, --key-file KEY_FILE
                        The SSH key file

Mitigaciones

Actualice a la última versión o mitigue siguiendo las instrucciones a continuación

  • https://www.fortiguard.com/psirt/FG-IR-22-377
Descargar herramienta