¡¾·ì϶¹«¸æ¡¿Fortinet 8Ô¶à¸ö°²È«·ì϶
°ä²¼¹¦·ò 2021-08-040x00 ·ì϶¸ÅÊö
2021Äê8ÔÂ3ÈÕ£¬Fortinet£¨·ÉËþ£©°ä²¼°²È«²¼¸æ£¬½¨¸´ÁËÆä²úÆ·ÖеÄ22¸ö°²È«·ì϶£¬ÕâЩ·ìÏ¶Éæ¼°FortiSandbox ¡¢FortiPortal¡¢ FortiManager¡¢FortiAnalyzer¡¢ FortiOSºÍFortiAuthenticator¡£
0x01 ·ì϶ÏêÇé

ÔÚ±¾´Î´Ë½¨¸´µÄ22¸ö·ì϶ÖУ¬×îΪÑϳÁµÄÊÇFortiPortalÖеÄÒ»¸öÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2021-32588£©ºÍÒ»¸öSQL×¢Èë·ì϶£¨CVE-2021-32590£©£¬¹¥»÷ÕßÄܹ»ÀûÓÃÕâ2¸ö·ì϶ÔÚδÊÚȨµÄÇé¿öÏÂÖ´ÐÐËÁÒâºÅÁî¡£
FortiPortalÊÇFortinet¹«Ë¾µÄÍйÜÔÆ°²È«Õ½ÊõÖÎÀíºÍÍþв·ÖÎö²úÆ·£¬×¨ÎªÂú×ãÍйܷþÎñÌṩÉÌ (MSP) µÄÍйܷþÎñÐèÒª¶øÉè¼Æ£¬ÆäÔÚ¶à×â»§¡¢¶à²ã¼¶ÖÎÀí¿ò¼ÜÄÚÌṩһÌ×È«ÃæµÄ Wi-Fi ºÍ°²È«ÖÎÀíÖ°ÄÜ£¬Ê¹µÃMSP ¿ÉÄÜͨ¹ýµ¥Ò»ÖÎÀíÆ½Ì¨²é¿´²¢ÖÎÀíÆä¿Í»§ÍøÂç¡£
·ì϶ÏêÇéÈçÏ£º
FortiPortal Ô¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2021-32588£©
ÓÉÓÚFortiPortalÖдæÔÚÓ²±àÂëÆ¾Ö¤£¨CWE-798£©·ì϶£¬Î´¾ÈÏÖ¤µÄÔ¶³Ì¹¥»÷ÕßÄܹ»Í¨¹ýʹÓÃĬÈϵÄÓ²±àÂëTomcatÖÎÀíÆ÷Óû§ÃûºÍÃÜÂëÉÏ´«ºÍ²¿Êð¶ñÒâWebÀûÓ÷¨Ê½´æµµÎļþ£¬²¢ÒÔrootÉí·ÝÖ´ÐÐËÁÒâºÅÁ¸Ã·ì϶µÄCVSSv3ÆÀ·ÖΪ9.3¡£
Ó°ÏìÁìÓò
FortiPortal 5.2.5 ¼°ÒÔϰ汾
FortiPortal 5.3.5 ¼°ÒÔϰ汾
FortiPortal 6.0.4 ¼°ÒÔϰ汾
FortiPortal 5.0.x
FortiPortal 5.1.x
FortiPortal SQL×¢Èë·ì϶£¨CVE-2021-32590£©
FortiPortalÖдæÔÚSQL×¢Èë·ì϶£¨CWE-89£©£¬ÓµÓÐͨ³£Óû§È¨Ï޵Ĺ¥»÷ÕßÄܹ»Í¨¹ý¶ñÒâÔì×÷µÄHTTPÒªÇóÔڵײãSQLÊý¾Ý¿âÉÏÖ´ÐÐËÁÒâºÅÁ¸Ã·ì϶µÄCVSSv3ÆÀ·ÖΪ9.4¡£
Ó°ÏìÁìÓò
FortiPortal 6.0.4 ¼°ÒÔϰ汾
FortiPortal 5.3.5 ¼°ÒÔϰ汾
FortiPortal 5.2.5 ¼°ÒÔϰ汾
FortiPortal 5.1.2 ¼°ÒÔϰ汾
FortiPortal 5.0.3 ¼°ÒÔϰ汾
FortiPortal 4.2.4 ¼°ÒÔϰ汾
FortiPortal 4.1.2 ¼°ÒÔϰ汾
FortiPortal 4.0.4 ¼°ÒÔϰ汾
FortiPortal 3.2.2 ¼°ÒÔϰ汾
³ýÉÏÊö·ì϶±í£¬±ØÒª°ÑÎȵ춏ö¸ßΣ·ì϶Ô̺¬£º
l FortiManager & FortiAnalyzerÖеÄSSRF·ì϶£¨CVE-2021-32603£©£º¹¥»÷Õß¿ÉÀûÓô˷ì϶ִÐÐδÊÚȨµÄ´úÂë»òºÅÁî¡£
l FortiManager & FortiAnalyzer£¦FortiPortalÖеĺÅÁî×¢Èë·ì϶£¨CVE-2021-26104£©£º¹¥»÷ÕßÄܹ»ÀûÓô˷ì϶ÒÔ root Éí·ÝÖ´ÐÐËÁÒâ shell ºÅÁî¡£
l FortiSandboxÖеĺÅÁî×¢Èë·ì϶£¨CVE-2021-26097£©£º¹¥»÷ÕßÄܹ»Í¨¹ý·¢ËͶñÒâ HTTP ÒªÇóÖ´ÐÐδÊÚȨµÄ´úÂë»òºÅÁî¡£
l FortiSandboxÖеÄõè¾¶±éÀú·ì϶£¨CVE-2021-24010£©£º¹¥»÷ÕßÄܹ»ÀûÓô˷ì϶ʵÏÖδÊÚȨ½Ó¼ûÎļþ¡£
l FortiSandboxÖеÄSQL×¢Èë·ì϶£¨CVE-2020-29011£©£º¹¥»÷ÕßÄܹ»ÀûÓô˷ì϶ÔڵײãSQLÚ¹ÊÍÆ÷ÉÏÖ´ÐÐδÊÚȨµÄ´úÂë»òºÅÁî¡£
l FortiSandbox £¦ FortiAuthenticatorÖеĻؾø·þÎñ·ì϶£¨CVE-2021-22124£©£ºÎ´¾Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÄܹ»Í¨¹ý·¢ËͶñÒâÒªÇóʹÉ豸½øÈëÎÞÏìӦ״̬¡£
0x02 ´ëÖý¨Òé
ĿǰÕâЩ·ì϶ÒѾ½¨¸´¡£
Õë¶ÔCVE-2021-32588£¬½¨ÒéʵʱÉý¼¶µ½ÒÔϰ汾£º
FortiPortal 5.2.6 »ò¸ü¸ß°æ±¾
FortiPortal 5.3.6 »ò¸ü¸ß°æ±¾
FortiPortal 6.0.5 »ò¸ü¸ß°æ±¾
Õë¶ÔCVE-2021-32590£¬½¨ÒéʵʱÉý¼¶µ½ÒÔϰ汾£º
FortiPortal 6.0.5 »ò¸ü¸ß°æ±¾
FortiPortal 5.3.6 »ò¸ü¸ß°æ±¾
FortiPortal 5.2.6 »ò¸ü¸ß°æ±¾
£¨×¢£º5.1¡¢5.0¡¢4.2¡¢4.1¡¢4.0ºÍ3.2°æ±¾µÄ²¹¶¡ÓдýÈ·ÈÏ¡££©
ÏÂÔØÁ´½Ó£º
https://www.fortinet.com/cn
0x03 ²Î¿¼Á´½Ó
https://www.fortiguard.com/psirt?date=08-2021
https://www.fortiguard.com/psirt/FG-IR-21-077
https://www.fortiguard.com/psirt/FG-IR-21-084
0x04 ¸üа汾
°æ±¾ | ÈÕÆÚ | Åú¸ÄÄÚÈÝ |
V1.0 | 2021-08-04 | ³õ´Î°ä²¼ |
0x05 Îĵµ¸½Â¼
CNVD£ºwww.cnvd.org.cn
CNNVD£ºwww.cnnvd.org.cn
CVE£ºcve.mitre.org
NVD£ºnvd.nist.gov
CVSS£ºwww.first.org
0x06 ¹ØÓÚGA»Æ½ð¼×
¹Ø×¢ÒÔϹ«¼ÒºÅ£¬»ñÈ¡¸ü¶à×ÊѶ£º



¾©¹«Íø°²±¸11010802024551ºÅ