# N/A
## 概述
FortiManager 和 FortiManager Cloud 多个版本存在一个关键功能的认证缺失漏洞,允许攻击者通过精心构造的请求执行任意代码或命令。
## 影响版本
- FortiManager 7.6.0
- FortiManager 7.4.0 到 7.4.4
- FortiManager 7.2.0 到 7.2.7
- FortiManager 7.0.0 到 7.0.12
- FortiManager 6.4.0 到 6.4.14
- FortiManager 6.2.0 到 6.2.12
- Fortinet FortiManager Cloud 7.4.1 到 7.4.4
- FortiManager Cloud 7.2.1 到 7.2.7
- FortiManager Cloud 7.0.1 到 7.0.12
- FortiManager Cloud 6.4.1 到 6.4.7
## 细节
该漏洞源自某一关键功能的认证守护进程未被正确实施,导致未经身份验证的攻击者可以通过特别构造的HTTP请求访问并执行任意代码或命令。这一问题直接影响了多个版本的FortiManager及FortiManager Cloud产品。
## 影响
攻击者可能利用此漏洞通过未经认证的访问和对系统进行未授权的操作,包括但不限于数据泄露、系统篡改以及执行恶意活动,从而严重威胁系统的安全性和稳定性。
| # | POC 描述 | 源链接 | 神龙链接 |
|---|---|---|---|
| 1 | None | https://github.com/maybelookis/CVE-2024-47575 | POC详情 |
| 2 | None | https://github.com/HazeLook/CVE-2024-47575 | POC详情 |
| 3 | None | https://github.com/Jaden1419/CVE-2024-47575 | POC详情 |
| 4 | None | https://github.com/hatvix1/CVE-2024-47575 | POC详情 |
| 5 | None | https://github.com/hazesecurity/CVE-2024-47575 | POC详情 |
| 6 | CVE-2024-47575: Critical Remote Code Execution (RCE) Vulnerability in VMware Horizon | https://github.com/groshi/CVE-2024-47575-POC | POC详情 |
| 7 | CVE-2024-47575 POC | https://github.com/zgimszhd61/CVE-2024-47575-POC | POC详情 |
| 8 | None | https://github.com/ShawtyTwo/CVE-2024-47575 | POC详情 |
| 9 | CVE-2024-47575: FortiManager Missing Authentication | https://github.com/Fruktolzzz/CVE-2024-47575 | POC详情 |
| 10 | None | https://github.com/krmxd/CVE-2024-47575 | POC详情 |
| 11 | CVE-2024-47575: FortiManager Missing Authentication | https://github.com/groshi324/CVE-2024-47575 | POC详情 |
| 12 | CVE-2024-47575: FortiManager Missing Authentication | https://github.com/VIRKiss/CVE-2024-47575 | POC详情 |
| 13 | CVE-2024-47575: FortiManager Missing Authentication | https://github.com/Jomq12/CVE-2024-47575 | POC详情 |
| 14 | CVE-2024-47575: FortiManager Missing Authentication | https://github.com/youngwhale21/CVE-2024-47575 | POC详情 |
| 15 | CVE-2024-47575: FortiManager Missing Authentication | https://github.com/gifretg/CVE-2024-47575 | POC详情 |
| 16 | CVE-2024-47575: FortiManager Missing Authentication | https://github.com/LayNMR/CVE-2024-47575 | POC详情 |
| 17 | CVE-2024-47575: FortiManager Missing Authentication | https://github.com/TaliBander/CVE-2024-47575 | POC详情 |
| 18 | CVE-2024-47575: FortiManager Missing Authentication | https://github.com/WotleAks/CVE-2024-47575 | POC详情 |
| 19 | CVE-2024-47575: FortiManager Missing Authentication | https://github.com/DaresNone/CVE-2024-47575 | POC详情 |
| 20 | Fortimanager Unauthenticated Remote Code Execution AKA fortijump CVE-2024-47575 | https://github.com/watchtowrlabs/Fortijump-Exploit-CVE-2024-47575 | POC详情 |
| 21 | None | https://github.com/expl0itsecurity/CVE-2024-47575 | POC详情 |
| 22 | FortiManager Unauthenticated Remote Code Execution (CVE-2024-47575) | https://github.com/skyalliance/exploit-cve-2024-47575 | POC详情 |
| 23 | CVE-2024-47575是Fortinet的FortiManager和FortiManager Cloud产品中的一个严重漏洞,源于fgfmsd守护进程缺乏对关键功能的身份验证。 | https://github.com/XiaomingX/cve-2024-47575-poc | POC详情 |
| 24 | CVE-2024-47575是Fortinet的FortiManager和FortiManager Cloud产品中的一个严重漏洞,源于fgfmsd守护进程缺乏对关键功能的身份验证。 | https://github.com/XiaomingX/cve-2024-47575-exp | POC详情 |
| 25 | CVE POC Exploit | https://github.com/Axi0n1ze/CVE-2024-47575-POC | POC详情 |
| 26 | CVE POC Exploit | https://github.com/Laonhearts/CVE-2024-47575-POC | POC详情 |
| 27 | CVE POC Exploit | https://github.com/Raygrants/CVE-2024-47575-POC | POC详情 |
| 28 | FortiManager Unauthenticated Remote Code Execution (CVE-2024-47575) | https://github.com/SkyGodling/exploit-cve-2024-47575 | POC详情 |
| 29 | CVE POC Exploit | https://github.com/KaztoRay/CVE-2024-47575-POC | POC详情 |
| 30 | CVE POC Exploit | https://github.com/revanslbw/CVE-2024-47575-POC | POC详情 |
| 31 | PoC for CVE-2024-47575 | https://github.com/AnnnNix/CVE-2024-47575 | POC详情 |
| 32 | A missing authentication vulnerability in Fortinet FortiManager allows a remote unauthenticated attacker to execute arbitrary code or commands via specially crafted requests to the fgfmd daemon. This vulnerability affects FortiManager versions 7.6.0, 7.4.0 through 7.4.4, 7.2.0 through 7.2.7, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14, 6.2.0 through 6.2.12, and all versions of 6.0. | https://github.com/projectdiscovery/nuclei-templates/blob/main/code/cves/2024/CVE-2024-47575.yaml | POC详情 |
暂无评论