PoC(概念验证)- 仅用于教育目的
在 FortiManager 中滥用对 SD-WAN Orchestrator 的访问的利用程序,利用了访问控制缺陷(CWE-284)。
漏洞 CVE-2021-24006 影响 FortiManager(版本 6.4.0 至 6.4.3),允许具有受限配置文件的已认证用户直接访问 SD-WAN Orchestrator 面板的 URL,即使没有通过接口获得明确权限。
直接访问有漏洞的 URL:
https://<IP>/fortiwan/maintenance/controller_configuration
此代码仅用于教育和意识提升目的。
请勿在生产环境或未经明确授权的情况下运行。
CVE-2021-24006 fortinet fortimanager sd-wan exploit poc vulnerability access-control bypass