¡¾·ì϶¹«¸æ¡¿Fortinet¶à¸ö°²È«·ì϶
°ä²¼¹¦·ò 2021-01-070x00 ·ì϶¸ÅÊö
²úÆ·Ãû³Æ | CVE ID | Àà ÐÍ | ·ì϶µÈ¼¶ | Ô¶³ÌÀûÓà |
FortiGate SSL VPN | CVE-2020-29010 | ÐÅϢй¶ | ÖÐΣ | ÊÇ |
FortiWeb | CVE-2020-29015 | SQL×¢Èë | ÖÐΣ | ÊÇ |
CVE-2020-29016 | »º³åÇøÒç³ö | ÖÐΣ | ÊÇ | |
CVE-2020-29018 | ÐÅϢй¶ | ÖÐΣ | ÊÇ | |
CVE-2020-29019 | »º³åÇøÒç³ö | ÖÐΣ | ÊÇ | |
FortiDeceptor | CVE-2020-29017 | ºÅÁî×¢Èë | ¸ßΣ | ÊÇ |
0x01 ·ì϶ÏêÇé

Fortinet£¨·ÉËþ£©ÊÇÃÀ¹úÒ»¼ÒÍøÂ簲ȫ¹«Ë¾£¬×÷Ϊ¶à²ãÍþв·ÀÓùϵͳµÄ´´ÐÂÕߺÍǰ·æ£¬ÆäÉæ¼°µÄ°²Õû¸öϵº¸Ç·À²¡¶¾¡¢·À»ðǽ¡¢VPN¡¢ÈëÇÖ¼ì²âºÍ·ÀÓù¡¢·´À¬»øÓʼþºÍÁ÷Á¿ÓÅ»¯µÈ¡£
2021Äê01ÔÂ04ÈÕ£¬FortiGuard³¢ÊÔÊÒ°ä²¼°²È«²¼¸æ£¬¹«¿ªÁËÆä¶à¿î²úÆ·ÖеĶà¸ö°²È«·ì϶£¬Ï¸½ÚÈçÏ£º
FortiGate SSL VPNÐÅϢй¶·ì϶£¨CVE-2020-29010£©
FortiGate SSL VPNÖдæÔÚÒ»¸öÐÅϢй¶·ì϶£¬ÆäCVSSÆÀ·Ö4.9¡£¹¥»÷ÕßÄܹ»Í¨¹ý´ÓCLIÖ´ÐÓ×° get vpn ssl monitor¡±ºÅÁîÀ´¶ÁÈ¡ÆäËüVDOMÖÐÓû§µÄSSL VPNÊÂÎñÈÕÖ¾¼Í¼£¬ÆäÖÐÃô¸ÐÊý¾ÝÔ̺¬Óû§Ãû¡¢Óû§×éºÍIPµØÖ·¡£
Ó°ÏìÁìÓò
FortiGate 6.0.10¼°Ö®Ç°°æ±¾¡£
FortiGate 6.2.4¼°Ö®Ç°°æ±¾¡£
FortiGate 6.4.1¼°Ö®Ç°°æ±¾¡£
FortiWeb SQL×¢Èë·ì϶£¨CVE-2020-29015£©
FortiWebÓû§½çÃæ´æÔÚÒ»¸öSQL×¢Èë·ì϶£¬ÆäCVSSÆÀ·Ö6.4¡£¹¥»÷ÕßÄܹ»Í¨¹ý·¢ËÍÔ̺¬¶ñÒâSQLÓï¾äµÄAuthorization±êÍ·µÄÒªÇóÀ´Ö´ÐÐËÁÒâSQL²éÎÊ»òºÅÁî¡£
Ó°ÏìÁìÓò
FortiWeb 6.3.7¼°Ö®Ç°°æ±¾¡£
FortiWeb 6.2.3¼°Ö®Ç°°æ±¾¡£
FortiWeb»º³åÇøÒç¶Âí½Å£¨CVE-2020-29016£©
FortiWebÖдæÔÚÒ»¸ö»ùÓÚ²Ö¿âµÄ»º³åÇøÒç¶Âí½Å£¬ÆäCVSSÆÀ·Ö6.4¡£¹¥»÷Õß¿ÉÄÜÀûÓô˷ì϶¸²¸Ç²Ö¿âµÄÄÚÈÝ£¬²¢Í¨¹ý·¢ËÍ´øÓÐÖ¤ÊéÃûµÄ¶ñÒâÒªÇóÀ´Ö´ÐÐËÁÒâºÅÁî»ò´úÂë¡£
Ó°ÏìÁìÓò
FortiWeb 6.3.5¼°Ö®Ç°°æ±¾¡£
FortiWeb 6.2.3¼°Ö®Ç°°æ±¾¡£
FortiDeceptorºÅÁî×¢Èë·ì϶£¨CVE-2020-29017£©
FortiDeceptorµÄ×Ô½çËµÒ³ÃæÖдæÔÚÒ»¸öOSºÅÁî×¢Èë·ì϶£¬ÆäCVSSÆÀ·Ö8.1¡£³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷ÕßÄܹ»ÔÚϵͳÉÏÖ´ÐÐËÁÒâºÅÁî¡£
Ó°ÏìÁìÓò
FortiDeceptor 3.1.0¼°Ö®Ç°°æ±¾¡£
FortiDeceptor 3.0.1¼°Ö®Ç°°æ±¾¡£
FortiWebÐÅϢй¶·ì϶£¨CVE-2020-29018£©
FortiWebÖдæÔÚÒ»¸ö±ðʽ×Ö·û´®·ì϶£¬ÆäCVSSÆÀ·Ö5.3¡£³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷Äܹ»Í¨¹ýredir²ÎÊý¶ÁÈ¡ÄÚ´æÄÚÈݲ¢¼ìË÷Ãô¸ÐÊý¾Ý¡£
Ó°ÏìÁìÓò
FortiWeb 6.3.5¼°Ö®Ç°°æ±¾¡£
FortiWeb»º³åÇøÒç¶Âí½Å£¨CVE-2020-29019£©
FortiWebÖдæÔÚÒ»¸ö»ùÓÚ²Ö¿âµÄ»º³åÇøÒç¶Âí½Å£¬ÆäCVSSÆÀ·Ö6.4¡£³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷ÕßÄܹ»Í¨¹ý·¢ËÍ´øÓжñÒâCookie±êÍ·µÄÒªÇóÀ´Ê¹httpdÊØ»¤·¨Ê½Ï̱߳ÀÀ££¬×îÖÕµ¼Ö»ؾø·þÎñ¡£
Ó°ÏìÁìÓò
FortiWeb 6.3.7¼°Ö®Ç°°æ±¾¡£
FortiWeb 6.2.3¼°Ö®Ç°°æ±¾¡£
0x02 ´ëÖý¨Òé
ĿǰFortinetÒѾ½¨¸´ÁËÓйطì϶£¬½¨Òé²Î¿¼Ï±íʵʱÉý¼¶¡£
·ì϶±àºÅ | ½¨¸´°æ±¾ |
CVE-2020-29010 | FortiGate 6.0.11»ò¸ü¸ß°æ±¾¡£ FortiGate 6.2.5»ò¸ü¸ß°æ±¾¡£ FortiGate 6.4.2»ò¸ü¸ß°æ±¾¡£ |
CVE-2020-29015 | FortiWeb 6.3.8»ò¸ü¸ß°æ±¾¡£ FortiWeb 6.2.4»ò¸ü¸ß°æ±¾¡£ |
CVE-2020-29016 | FortiWeb 6.3.6»ò¸ü¸ß°æ±¾¡£ FortiWeb 6.2.4»ò¸ü¸ß°æ±¾¡£ |
CVE-2020-29017 | FortiDeceptor 3.2.0»ò¸ü¸ß°æ±¾¡£ FortiDeceptor 3.1.1»ò¸ü¸ß°æ±¾¡£ FortiDeceptor 3.0.2»ò¸ü¸ß°æ±¾¡£ |
CVE-2020-29018 | FortiWeb 6.3.6»ò¸ü¸ß°æ±¾¡£ |
CVE-2020-29019 | FortiWeb 6.3.8»ò¸ü¸ß°æ±¾¡£ FortiWeb 6.2.4»ò¸ü¸ß°æ±¾¡£ |
0x03 ²Î¿¼Á´½Ó
https://www.fortiguard.com/psirt
https://www.fortiguard.com/psirt/%20FG-IR-20-124
https://www.fortinet.com/resources?
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-29015
0x04 ¹¦·òÏß
2021-01-04 FortiGuard°ä²¼°²È«²¼¸æ
2021-01-07 VSRC°ä²¼°²È«¹«¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/



¾©¹«Íø°²±¸11010802024551ºÅ