Skip to content
KitploitKITPLOIT
工具博客
提交
工具博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
CVE-2022-40684 — Fortinet 关键认证绕过漏洞 (CVE-2022-40684) [ 大规模利用 ] | Kitploit
工具/GitHubGitHub/hawa771/cve-2022-40684
漏洞分析漏洞利用Web安全渗透测试身份验证红队
GitHubhawa771/cve-2022-40684

CVE-2022-40684

Fortinet 关键认证绕过漏洞 (CVE-2022-40684) [ 大规模利用 ]

查看仓库
283年前尚未审核

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享

CVE-2022-40684 (CVSS 评分: 9.6)

影响 Fortinet FortiOS、FortiProxy 和 FortiSwitchManager 设备的 CVE-2022-40684 概念验证 (POC)

受影响产品

  • FortiOS 版本 7.0.0 – 7.0.6 和 7.2.0 – 7.2.1
  • FortiProxy 版本 7.0.0 – 7.0.6 和版本 7.2.0
  • FortiSwitchManager 版本 7.0.0 和 7.2.0

资源

https://socradar.io/what-do-you-need-to-know-about-fortinet-critical-authentication-bypass-vulnerability-cve-2022-40684/

摘要

该 POC 利用身份验证绕过漏洞为指定用户设置 SSH 密钥。

使用方法

root@kitploit:~
root@kali:~# python exploit.py -h
 
     ______           __  _            __     ____  ____________
    / ____/___  _____/ /_(_)___  ___  / /_   / __ \/ ____/ ____/
   / /_  / __ \/ ___/ __/ / __ \/ _ \/ __/  / /_/ / /   / __/   
  / __/ / /_/ / /  / /_/ / / / /  __/ /_   / _, _/ /___/ /___   
 /_/    \____/_/   \__/_/_/ /_/\___/\__/  /_/ |_|\____/_____/ 


    CVE-2022-40684 Exploit By Valentin Lobstein (Chocapikk)


usage: exploit.py [-h] [-k KEY] [-u URL] [-l LIST] [-U USERNAME] [-t THREADS] [-o OUTPUT]

options:
  -h, --help            show this help message and exit
  -k KEY, --key KEY     Your SSH pubKey id_rsa.pub
  -u URL, --url URL     Base target uri (ex. http://target-uri/)
  -l LIST, --list LIST  List of targets (list.txt)
  -U USERNAME, --username USERNAME
                        Username
  -t THREADS, --threads THREADS
                        Threads
  -o OUTPUT, --output OUTPUT
                        Output file

Zoomeye 搜索语法

root@kitploit:~

title:"FortiGate"

缓解措施

更新到最新版本,或按照 Fortinet PSIRT 中的说明进行缓解。

  • https://www.fortiguard.com/psirt/FG-IR-22-377

免责声明

本软件仅用于学术研究和开发有效的防御技术,除非明确授权,否则不应用于攻击系统。项目维护者不对软件的滥用负责。请负责任地使用。

下载工具