支持本站 — 捐款将帮助我们持续运营

目标: 1000 元,已筹: 1000

100.0%
获取后续新漏洞提醒登录后订阅
一、 漏洞 CVE-2022-40684 基础信息
漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
N/A
来源: 美国国家漏洞数据库 NVD
Vulnerability Description
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6, FortiProxy version 7.2.0 and version 7.0.0 through 7.0.6 and FortiSwitchManager version 7.2.0 and 7.0.0 allows an unauthenticated atttacker to perform operations on the administrative interface via specially crafted HTTP or HTTPS requests.
来源: 美国国家漏洞数据库 NVD
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
来源: 美国国家漏洞数据库 NVD
Vulnerability Type
N/A
来源: 美国国家漏洞数据库 NVD
Vulnerability Title
Fortinet FortiOS 授权问题漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
Fortinet FortiOS是美国飞塔(Fortinet)公司的一套专用于FortiGate网络安全平台上的安全操作系统。该系统为用户提供防火墙、防病毒、IPSec/SSLVPN、Web内容过滤和反垃圾邮件等多种安全功能。 Fortinet FortiOS存在授权问题漏洞。目前尚无此漏洞的相关信息,请随时关注CNNVD或厂商公告。
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD
受影响产品
厂商产品影响版本CPE订阅
FortinetFortinet FortiOS, FortiProxy, FortiSwitchManager FortiOS 7.2.1, 7.2.0, 7.0.6, 7.0.5, 7.0.4, 7.0.3, 7.0.2, 7.0.1, 7.0.0; FortiProxy 7.2.0, 7.0.6, 7.0.5, 7.0.4, 7.0.3, 7.0.2, 7.0.1, 7.0.0; FortiSwitchManager 7.2.0, 7.0.0 -
二、漏洞 CVE-2022-40684 的公开POC
#POC 描述源链接神龙链接
1A proof of concept exploit for CVE-2022-40684 affecting Fortinet FortiOS, FortiProxy, and FortiSwitchManagerhttps://github.com/horizon3ai/CVE-2022-40684POC详情
2PoC for CVE-2022-40684 - Authentication bypass lead to Full device takeover (Read-only)https://github.com/carlosevieira/CVE-2022-40684POC详情
3Bash PoC for Fortinet Auth Bypass - CVE-2022-40684https://github.com/Filiplain/Fortinet-PoC-Auth-BypassPOC详情
4Exploit for CVE-2022-40684 affecting Fortinet FortiOS, FortiProxy, and FortiSwitchManagerhttps://github.com/kljunowsky/CVE-2022-40684-POCPOC详情
5Nonehttps://github.com/secunnix/CVE-2022-40684POC详情
6Nonehttps://github.com/iveresk/CVE-2022-40684POC详情
7Nonehttps://github.com/mhd108/CVE-2022-40684POC详情
8exploit for CVE-2022-40684 Fortinethttps://github.com/ClickCyber/cve-2022-40684POC详情
9Fortinet Critical Authentication Bypass Vulnerability (CVE-2022-40684) [ Mass Exploit ]https://github.com/Chocapikk/CVE-2022-40684POC详情
10Exploit for CVE-2022-40684 vulnerabilityhttps://github.com/mohamedbenchikh/CVE-2022-40684POC详情
11Fortinet Critical Authentication Bypass Vulnerability (CVE-2022-40684) [ Mass Exploit ]https://github.com/HAWA771/CVE-2022-40684POC详情
12Nonehttps://github.com/NeriaBasha/CVE-2022-40684POC详情
13Forti CVE-2022-40684 enumeration script built in Rusthttps://github.com/Grapphy/fortipwnPOC详情
14Nonehttps://github.com/puckiestyle/CVE-2022-40684POC详情
15Nonehttps://github.com/jsongmax/Fortinet-CVE-2022-40684POC详情
16Utilities for exploiting vulnerability CVE-2022-40684 (FortiOS / FortiProxy / FortiSwitchManager - Authentication bypass on administrative interface).https://github.com/und3sc0n0c1d0/CVE-2022-40684POC详情
17Nonehttps://github.com/qingsiweisan/CVE-2022-40684POC详情
18An authentication bypass using an alternate path or channel in Fortinet producthttps://github.com/TaroballzChen/CVE-2022-40684-metasploit-scannerPOC详情
19Exploit Fortigate - CVE-2022-40684https://github.com/gustavorobertux/gotigatePOC详情
20Nonehttps://github.com/hughink/CVE-2022-40684POC详情
21Nonehttps://github.com/notareaperbutDR34P3r/CVE-2022-40684-RustPOC详情
22一键枚举所有用户名以及写入SSH公钥https://github.com/z-bool/CVE-2022-40684POC详情
23Nonehttps://github.com/Anthony1500/CVE-2022-40684POC详情
24Research repository tracking affected IPs from the Fortigate CVE-2022-40684 configuration leak by Belsen Grouphttps://github.com/arsolutioner/fortigate-belsen-leakPOC详情
25Nonehttps://github.com/Rofell0s/Fortigate-Leak-CVE-2022-40684POC详情
26Research repository tracking affected IPs from the Fortigate CVE-2022-40684 configuration leak by Belsen Grouphttps://github.com/AKboss1221/fortigate-belsen-leakPOC详情
27Nonehttps://github.com/XalfiE/Fortigate-Belsen-Leak-Dump-CVE-2022-40684-POC详情
28This repository contains informaion about the Fortigate firewall vulnerability (CVE-2022-40684) and affected data that were publicly disclosed by the Belsen Group. This information is being shared for security research and defensive purposes to help organizations identify if they were impacted.https://github.com/niklasmato/fortileak-01-2025-BePOC详情
29Nonehttps://github.com/Yami0x777/Belsen_Group-et-exploitation-de-la-CVE-2022-40684POC详情
30Fortinet contains an authentication bypass vulnerability via using an alternate path or channel in FortiOS 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6, FortiProxy 7.2.0 and 7.0.0 through 7.0.6, and FortiSwitchManager 7.2.0 and 7.0.0. An attacker can perform operations on the administrative interface via specially crafted HTTP or HTTPS requests, thus making it possible to obtain sensitive information, modify data, and/or execute unauthorized operations. https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2022/CVE-2022-40684.yamlPOC详情
31Nonehttps://github.com/Threekiii/Awesome-POC/blob/master/%E7%BD%91%E7%BB%9C%E8%AE%BE%E5%A4%87%E6%BC%8F%E6%B4%9E/Fortinet%20FortiOS%20admin%20%E8%BF%9C%E7%A8%8B%E5%91%BD%E4%BB%A4%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E%20CVE-2022-40684.mdPOC详情
32Exploit for CVE-2022-40684 vulnerabilityhttps://github.com/dkstar11q/CVE-2022-40684POC详情
33Forti CVE-2022-40684 enumeration script built in Rusthttps://github.com/xtwip/fortipwnPOC详情
34PoC for CVE-2022-40684 - Authentication bypass lead to Full device takeover (Read-only)https://github.com/ccordeiro/CVE-2022-40684POC详情
AI 生成 POC高级

未找到公开 POC。

登录以生成 AI POC
三、漏洞 CVE-2022-40684 的情报信息
Please 登录 to view more intelligence information
四、漏洞 CVE-2022-40684 的评论

暂无评论


发表评论