Fortinet°²È«²úÆ·Ó²±àÂë¼ÓÃÜÃÜÔ¿·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2019-11-27

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2018-9195£¬Î£ÏÕ¼¶±ð£ºÖÐΣ£¬CVSS·ÖÖµ£º5.9


Ó°Ïì°æ±¾


Fortinet FortiOS 6.0.6¼°Ö®Ç°°æ±¾


FortiClient 6.0.6¼°Ö®Ç°°æ±¾£¨Windows £©ºÍ6.2.1¼°Ö®Ç°°æ±¾£¨Mac£©


·ì϶¸ÅÊö


Fortinet FortiOSºÍFortinet FortiClient¶¼ÊÇÃÀ¹ú·ÉËþ£¨Fortinet£©¹«Ë¾µÄ²úÆ·¡£Fortinet FortiOSÊÇÒ»Ì×רÓÃÓÚFortiGateÍøÂ簲ȫƽ̨Éϵݲȫ²Ù×÷ϵͳ¡£¸ÃϵͳΪÓû§Ìṩ·À»ðǽ¡¢·À²¡¶¾¡¢IPSec/SSLVPN¡¢WebÄÚÈݹýÂ˺ͷ´À¬»øÓʼþµÈ¶àÖÖ°²È«Ö°ÄÜ¡£Fortinet FortiClientÊÇÒ»Ì×ÒÆ¶¯Öն˰²È«½â¾ö¹æ»®¡£¸Ã¹æ»®ÓëFortiGate·À»ðǽÉ豸ÏνÓʱ¿ÉÌṩIPsecºÍSSL¼ÓÃÜ¡¢¹ãÓòÍøÓÅ»¯¡¢Öն˺ϹæºÍË«Òò×ÓÈÏÖ¤µÈÖ°ÄÜ¡£


¸Ã·ì϶ԴÓÚFortiGuard·þÎñͨѶºÍ̸ʹÓÃÁËÓ²±àÂëµÄ¼ÓÃÜÃÜÔ¿¡£ÊÜÓ°ÏìµÄ²úÆ·Ô̺¬FortiGate·À»ðǽÒÔ¼°MacºÍWindows°æ±¾µÄFortiClientÖն˱£»¤Èí¼þ¡£ÕâÈýÖÖ²úƷʹÓÃÈõ¼ÓÃÜ£¨XOR£©²¢ÇÒÊÇÓ²±àÂëµÄ¼ÓÃÜÃÜÔ¿Óë¸÷ÀàFortiGateÔÆ·þÎñ½øÐÐͨѶ¡£¸ÃÃÜÔ¿ÓÃÓÚ¼ÓÃÜFortiGuard Web¹ýÂËÖ°ÄÜ¡¢FortiGuard·´À¬»øÓʼþÖ°ÄܺÍFortiGuard AntiVirusÖ°ÄܵÄÓû§Á÷Á¿¡£¹¥»÷Õß¿ÉÀûÓô˷ì϶Ðá̽Óû§µÄÁ÷Á¿£¬¸ú×ÙËûÃǵÄä¯ÀÀ¼Í¼»òµç×ÓÓʼþÊý¾Ý¡£


·ì϶ÑéÖ¤


ÔÝÎÞEXP/POC¡£


½¨¸´½¨Òé


Ŀǰ³§ÉÌÒѰ䲼Éý¼¶²¹¶¡ÒÔ½¨¸´·ì϶£¬²¹¶¡»ñÈ¡Á´½Ó£º

https://fortiguard.com/psirt/FG-IR-18-100¡£


²Î¿¼Á´½Ó


https://www.zdnet.com/article/some-fortinet-products-shipped-with-hardcoded-encryption-keys/