影响 Fortinet FortiOS、FortiProxy 和 FortiSwitchManager 设备的 CVE-2022-40684 概念验证 (POC)
该 POC 利用身份验证绕过漏洞为指定用户设置 SSH 密钥。
root@kali:~# python exploit.py -h
______ __ _ __ ____ ____________
/ ____/___ _____/ /_(_)___ ___ / /_ / __ \/ ____/ ____/
/ /_ / __ \/ ___/ __/ / __ \/ _ \/ __/ / /_/ / / / __/
/ __/ / /_/ / / / /_/ / / / / __/ /_ / _, _/ /___/ /___
/_/ \____/_/ \__/_/_/ /_/\___/\__/ /_/ |_|\____/_____/
CVE-2022-40684 Exploit By Valentin Lobstein (Chocapikk)
usage: exploit.py [-h] [-k KEY] [-u URL] [-l LIST] [-U USERNAME] [-t THREADS] [-o OUTPUT]
options:
-h, --help show this help message and exit
-k KEY, --key KEY Your SSH pubKey id_rsa.pub
-u URL, --url URL Base target uri (ex. http://target-uri/)
-l LIST, --list LIST List of targets (list.txt)
-U USERNAME, --username USERNAME
Username
-t THREADS, --threads THREADS
Threads
-o OUTPUT, --output OUTPUT
Output file
title:"FortiGate"
更新到最新版本,或按照 Fortinet PSIRT 中的说明进行缓解。
本软件仅用于学术研究和开发有效的防御技术,除非明确授权,否则不应用于攻击系统。项目维护者不对软件的滥用负责。请负责任地使用。