Fortinet FortiSIEM是美国飞塔(Fortinet)公司的一套安全信息和事件管理系统。该系统包括资产发现、工作流程自动化和统一管理等功能。 Fortinet FortiSIEM存在操作系统命令注入漏洞,该漏洞源于对特殊元素中和不当。攻击者利用该漏洞通过特制的API请求执行未经授权的代码或命令。以下版本受到影响:7.1.0版本至7.1.1版本、7.0.0版本至7.0.2版本、6.7.0版本至6.7.8版本、6.6.0版本至6.6.3版本、6.5.0版本至6.5.2版本、6.4.0版本至6.4.
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
| # | POC 描述 | 源链接 | 神龙链接 |
|---|---|---|---|
| 1 | CVE-2024-23108: Fortinet FortiSIEM Unauthenticated 2nd Order Command Injection | https://github.com/horizon3ai/CVE-2024-23108 | POC详情 |
| 2 | POC iteration for CVE-2024-23108 | https://github.com/hitem/CVE-2024-23108 | POC详情 |
| 3 | FortiSIEM versions 6.4.0 through 7.1.1 contain an OS command injection vulnerability in the Phoenix Monitor service. The vulnerability exists in the XML parsing of TEST_STORAGE elements where the mount_point field is not properly sanitized before being passed to shell commands, allowing unauthenticated remote code execution. | https://github.com/projectdiscovery/nuclei-templates/blob/main/network/cves/2024/CVE-2024-23108.yaml | POC详情 |
未找到公开 POC。
登录以生成 AI POC暂无评论