目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2024-21762— Fortinet FortiOS 缓冲区错误漏洞

一分钟漏洞结论

影响对象
Fortinet FortiProxy
利用判断
已确认在野利用,应立即处置
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

Fortinet FortiOS是美国飞塔(Fortinet)公司的一套专用于FortiGate网络安全平台上的安全操作系统。该系统为用户提供防火墙、防病毒、IPSec/SSLVPN、Web内容过滤和反垃圾邮件等多种安全功能。 Fortinet FortiOS存在缓冲区错误漏洞,该漏洞源于存在越界写入,允许攻击者通过特制请求执行未经授权的代码或命令。

CVSS 9.6 · Critical KEV · 勒索软件 EPSS 84.28% · P100

影响版本矩阵 13

厂商产品 版本范围状态
Fortinet FortiOS 7.4.0≤ 7.4.2 affected
7.2.0≤ 7.2.6 affected
7.0.0≤ 7.0.13 affected
6.4.0≤ 6.4.14 affected
6.2.0≤ 6.2.15 affected
6.0.0≤ 6.0.17 affected
Fortinet FortiProxy 7.4.0≤ 7.4.2 affected
7.2.0≤ 7.2.8 affected
7.0.0≤ 7.0.14 affected
2.0.0≤ 2.0.13 affected
1.2.0≤ 1.2.13 affected
1.1.0≤ 1.1.6 affected
1.0.0≤ 1.0.7 affected
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2024-21762 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
N/A
来源: CVE Program / CVE List V5
Vulnerability Description
A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, 6.0.0 through 6.0.17, FortiProxy versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0.14, 2.0.0 through 2.0.13, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6, 1.0.0 through 1.0.7 allows attacker to execute unauthorized code or commands via specifically crafted requests
来源: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
来源: CVE Program / CVE List V5
Vulnerability Type
跨界内存写
来源: CVE Program / CVE List V5
Vulnerability Title
Fortinet FortiOS 缓冲区错误漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
Fortinet FortiOS是美国飞塔(Fortinet)公司的一套专用于FortiGate网络安全平台上的安全操作系统。该系统为用户提供防火墙、防病毒、IPSec/SSLVPN、Web内容过滤和反垃圾邮件等多种安全功能。 Fortinet FortiOS存在缓冲区错误漏洞,该漏洞源于存在越界写入,允许攻击者通过特制请求执行未经授权的代码或命令。
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD

神龙十问 — AI 深度分析

十问解析:根本原因、利用方式、修复建议、紧迫性。摘要免费,完整版需登录。

受影响产品

厂商 产品 影响版本 CPE 订阅
Fortinet FortiProxy 7.4.0 ~ 7.4.2 -
Fortinet FortiOS 7.4.0 ~ 7.4.2 -

二、漏洞 CVE-2024-21762 的公开POC

# POC 描述 源链接 神龙链接
1 None https://github.com/Gh71m/CVE-2024-21762-POC POC详情
2 FortiOS 6.0 - 7.4.2 Out of bound exploit --> RCE!!! https://github.com/c0d3b3af/CVE-2024-21762-POC POC详情
3 Safely detect whether a FortiGate SSL VPN is vulnerable to CVE-2024-21762 https://github.com/BishopFox/cve-2024-21762-check POC详情
4 CVE-2024-21762 POC Forti VPN SSL Out of Boundary RCE https://github.com/tr1pl3ight/CVE-2024-21762-POC POC详情
5 FortiOS 6.0 - 7.4.2 Out of bound exploit --> RCE!!! https://github.com/redCode001/CVE-2024-21762-POC POC详情
6 proof-of-concept out-of-bound write vuln in FortiOS ---> RCE https://github.com/c0d3b3af/CVE-2024-21762-Exploit POC详情
7 Real proof-of-concept out-of-bound write vuln in FortiOS ---> RCE https://github.com/RequestXss/CVE-2024-21762-Exploit-POC POC详情
8 CVE-2024-21762 is an out of bounds write vulnerability in fortinet fortios which leads to unauthenticated remote code execution https://github.com/t4ril/CVE-2024-21762-PoC POC详情
9 RCE exploit for FortiOS 6.0-7.4.2 https://github.com/c0d3b3af/CVE-2024-21762-RCE-exploit POC详情
10 This script performs vulnerability scanning for CVE-2024-21762, a Fortinet SSL VPN remote code execution vulnerability. It checks whether a given server is vulnerable to this CVE by sending specific requests and analyzing the responses. https://github.com/cleverg0d/CVE-2024-21762-Checker POC详情
11 The only one working RCE exploit that sells for $5,000 on the darknet https://github.com/JohnHormond/CVE-2024-21762-Fortinet-RCE-WORK POC详情
12 out-of-bounds write in Fortinet FortiOS CVE-2024-21762 vulnerability https://github.com/h4x0r-dz/CVE-2024-21762 POC详情
13 Chequea si tu firewall es vulnerable a CVE-2024-21762 (RCE sin autenticación) https://github.com/r4p3c4/CVE-2024-21762-Exploit-PoC-Fortinet-SSL-VPN-Check POC详情
14 Fortinet CVE 2024 https://github.com/vorotilovaawex/CVE-2024-21762_POC POC详情
15 None https://github.com/TheRedDevil1/CVE-2024-21762 POC详情
16 The PoC demonstrates the potential for remote code execution by exploiting the identified security flaw. https://github.com/d0rb/CVE-2024-21762 POC详情
17 CVE-2024-21762-POC replayse published https://github.com/S0SkiPlosK1/CVE-2024-21762-POC POC详情
18 None https://github.com/lore-is-already-taken/multicheck_CVE-2024-21762 POC详情
19 None https://github.com/lolminerxmrig/multicheck_CVE-2024-21762 POC详情
20 None https://github.com/AlexLondan/CVE-2024-21762-Fortinet-RCE-ALLWORK POC详情
21 None https://github.com/zzcentury/FortiGate-CVE-2024-21762 POC详情
22 Full exploit of Cve-2024-21762! https://github.com/Codeb3af/Cve-2024-21762- POC详情
23 None https://github.com/rdoix/cve-2024-21762-checker POC详情
24 CVE-2024-21762 是 Fortinet 公司的 FortiOS 和 FortiProxy 产品中的一个严重漏洞,存在于其 SSL VPN 组件中。 https://github.com/XiaomingX/cve-2024-21762-poc POC详情
25 Proof-of-concept scanner targeting CVE-2024-21762 in FortiOS SSL VPN’s /remote/hostcheck_validate endpoint with reverse shell payload delivery. https://github.com/abrewer251/CVE-2024-21762_FortiNet_PoC POC详情
26 This script performs vulnerability scanning for CVE-2024-21762, a Fortinet SSL VPN remote code execution vulnerability. It checks whether a given server is vulnerable to this CVE by sending specific requests and analyzing the responses. https://github.com/deFr0ggy/CVE-2024-21762-Checker POC详情
27 None https://github.com/0x13-ByteZer0/CVE-2024-21762 POC详情
28 CVE-2024-21762 是 Fortinet 公司的 FortiOS 和 FortiProxy 产品中的一个严重漏洞,存在于其 SSL VPN 组件中。 https://github.com/CrackerCat/cve-2024-21762-poc POC详情
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2024-21762 的情报信息

登录查看更多情报信息。

CVE-2024-21762 厂商安全公告 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2024-21762

暂无评论


发表评论