
CVE-2024-23108: Fortinet FortiSIEM 認証不要の二次コマンドインジェクション
脆弱な FortiSIEM アプライアンス上でルートとしてコマンドを盲目的に実行する概念実証エクスプロイト
根本原因と侵害の痕跡はこちら: https://www.horizon3.ai/attack-research/disclosures/cve-2024-23108-fortinet-fortisiem-2nd-order-command-injection-deep-dive
% python3 CVE-2024-23108.py -h
usage: CVE-2024-23108.py [-h] -t TARGET [-p PORT] -c COMMAND
options:
-h, --help show this help message and exit
-t TARGET, --target TARGET
The IP address of the target
-p PORT, --port PORT The port of the Phoenix Monitor service
-c COMMAND, --command COMMAND
The command to blindly execute
このソフトウェアは、学術研究および効果的な防御技術の開発のみを目的として作成されており、明示的に許可された場合を除き、システムへの攻撃に使用することを意図していません。プロジェクトのメンテナは、ソフトウェアの誤用について一切の責任を負いません。責任を持って使用してください。