¡¾·ì϶¹«¸æ¡¿Fortinet 8Ô¶à¸ö°²È«·ì϶

°ä²¼¹¦·ò 2021-08-04


0x00 ·ì϶¸ÅÊö

2021Äê8ÔÂ3ÈÕ£¬Fortinet£¨·ÉËþ£©°ä²¼°²È«²¼¸æ£¬½¨¸´ÁËÆä²úÆ·ÖеÄ22¸ö°²È«·ì϶£¬ÕâЩ·ìÏ¶Éæ¼°FortiSandbox ¡¢FortiPortal¡¢ FortiManager¡¢FortiAnalyzer¡¢ FortiOSºÍFortiAuthenticator ¡£

 

0x01 ·ì϶ÏêÇé

image.png

ÔÚ±¾´Î´Ë½¨¸´µÄ22¸ö·ì϶ÖУ¬×îΪÑϳÁµÄÊÇFortiPortalÖеÄÒ»¸öÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2021-32588£©ºÍÒ»¸öSQL×¢Èë·ì϶£¨CVE-2021-32590£©£¬¹¥»÷ÕßÄܹ»ÀûÓÃÕâ2¸ö·ì϶ÔÚδÊÚȨµÄÇé¿öÏÂÖ´ÐÐËÁÒâºÅÁî ¡£

FortiPortalÊÇFortinet¹«Ë¾µÄÍйÜÔÆ°²È«Õ½ÊõÖÎÀíºÍÍþв·ÖÎö²úÆ·£¬×¨ÎªÂú×ãÍйܷþÎñÌṩÉÌ (MSP) µÄÍйܷþÎñÐèÒª¶øÉè¼Æ£¬ÆäÔÚ¶à×â»§¡¢¶à²ã¼¶ÖÎÀí¿ò¼ÜÄÚÌṩһÌ×È«ÃæµÄ Wi-Fi ºÍ°²È«ÖÎÀíÖ°ÄÜ£¬Ê¹µÃMSP ¿ÉÄÜͨ¹ýµ¥Ò»ÖÎÀíÆ½Ì¨²é¿´²¢ÖÎÀíÆä¿Í»§ÍøÂç ¡£


·ì϶ÏêÇéÈçÏ£º

FortiPortal Ô¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2021-32588£©

ÓÉÓÚFortiPortalÖдæÔÚÓ²±àÂëÆ¾Ö¤£¨CWE-798£©·ì϶£¬Î´¾­ÈÏÖ¤µÄÔ¶³Ì¹¥»÷ÕßÄܹ»Í¨¹ýʹÓÃĬÈϵÄÓ²±àÂëTomcatÖÎÀíÆ÷Óû§ÃûºÍÃÜÂëÉÏ´«ºÍ²¿Êð¶ñÒâWebÀûÓ÷¨Ê½´æµµÎļþ£¬²¢ÒÔrootÉí·ÝÖ´ÐÐËÁÒâºÅÁ¸Ã·ì϶µÄCVSSv3ÆÀ·ÖΪ9.3 ¡£

Ó°ÏìÁìÓò

FortiPortal 5.2.5 ¼°ÒÔϰ汾

FortiPortal 5.3.5 ¼°ÒÔϰ汾

FortiPortal 6.0.4 ¼°ÒÔϰ汾

FortiPortal 5.0.x

FortiPortal 5.1.x

 

FortiPortal SQL×¢Èë·ì϶£¨CVE-2021-32590£©

FortiPortalÖдæÔÚSQL×¢Èë·ì϶£¨CWE-89£©£¬ÓµÓÐͨ³£Óû§È¨Ï޵Ĺ¥»÷ÕßÄܹ»Í¨¹ý¶ñÒâÔì×÷µÄHTTPÒªÇóÔڵײãSQLÊý¾Ý¿âÉÏÖ´ÐÐËÁÒâºÅÁ¸Ã·ì϶µÄCVSSv3ÆÀ·ÖΪ9.4 ¡£

Ó°ÏìÁìÓò

FortiPortal 6.0.4 ¼°ÒÔϰ汾

FortiPortal 5.3.5 ¼°ÒÔϰ汾

FortiPortal 5.2.5 ¼°ÒÔϰ汾

FortiPortal 5.1.2 ¼°ÒÔϰ汾

FortiPortal 5.0.3 ¼°ÒÔϰ汾

FortiPortal 4.2.4 ¼°ÒÔϰ汾

FortiPortal 4.1.2 ¼°ÒÔϰ汾

FortiPortal 4.0.4 ¼°ÒÔϰ汾

FortiPortal 3.2.2 ¼°ÒÔϰ汾

 

³ýÉÏÊö·ì϶±í£¬±ØÒª°ÑÎȵ춏ö¸ßΣ·ì϶Ô̺¬£º

l  FortiManager & FortiAnalyzerÖеÄSSRF·ì϶£¨CVE-2021-32603£©£º¹¥»÷Õß¿ÉÀûÓô˷ì϶ִÐÐδÊÚȨµÄ´úÂë»òºÅÁî ¡£

l  FortiManager & FortiAnalyzer£¦FortiPortalÖеĺÅÁî×¢Èë·ì϶£¨CVE-2021-26104£©£º¹¥»÷ÕßÄܹ»ÀûÓô˷ì϶ÒÔ root Éí·ÝÖ´ÐÐËÁÒâ shell ºÅÁî ¡£

l  FortiSandboxÖеĺÅÁî×¢Èë·ì϶£¨CVE-2021-26097£©£º¹¥»÷ÕßÄܹ»Í¨¹ý·¢ËͶñÒâ HTTP ÒªÇóÖ´ÐÐδÊÚȨµÄ´úÂë»òºÅÁî ¡£

l  FortiSandboxÖеÄõè¾¶±éÀú·ì϶£¨CVE-2021-24010£©£º¹¥»÷ÕßÄܹ»ÀûÓô˷ì϶ʵÏÖδÊÚȨ½Ó¼ûÎļþ ¡£

l  FortiSandboxÖеÄSQL×¢Èë·ì϶£¨CVE-2020-29011£©£º¹¥»÷ÕßÄܹ»ÀûÓô˷ì϶ÔڵײãSQLÚ¹ÊÍÆ÷ÉÏÖ´ÐÐδÊÚȨµÄ´úÂë»òºÅÁî ¡£

l  FortiSandbox £¦ FortiAuthenticatorÖеĻؾø·þÎñ·ì϶£¨CVE-2021-22124£©£ºÎ´¾­Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÄܹ»Í¨¹ý·¢ËͶñÒâÒªÇóʹÉ豸½øÈëÎÞÏìӦ״̬ ¡£

 

0x02 ´ëÖý¨Òé

ĿǰÕâЩ·ì϶ÒѾ­½¨¸´ ¡£

Õë¶ÔCVE-2021-32588£¬½¨ÒéʵʱÉý¼¶µ½ÒÔϰ汾£º

FortiPortal 5.2.6 »ò¸ü¸ß°æ±¾

FortiPortal 5.3.6 »ò¸ü¸ß°æ±¾

FortiPortal 6.0.5 »ò¸ü¸ß°æ±¾

 

Õë¶ÔCVE-2021-32590£¬½¨ÒéʵʱÉý¼¶µ½ÒÔϰ汾£º

FortiPortal 6.0.5 »ò¸ü¸ß°æ±¾

FortiPortal 5.3.6 »ò¸ü¸ß°æ±¾

FortiPortal 5.2.6 »ò¸ü¸ß°æ±¾

£¨×¢£º5.1¡¢5.0¡¢4.2¡¢4.1¡¢4.0ºÍ3.2°æ±¾µÄ²¹¶¡ÓдýÈ·ÈÏ ¡££©

ÏÂÔØÁ´½Ó£º

https://www.fortinet.com/cn

 

0x03 ²Î¿¼Á´½Ó

https://www.fortiguard.com/psirt?date=08-2021

https://www.fortiguard.com/psirt/FG-IR-21-077

https://www.fortiguard.com/psirt/FG-IR-21-084

 

0x04 ¸üа汾

°æ±¾

ÈÕÆÚ

Åú¸ÄÄÚÈÝ

V1.0

2021-08-04

³õ´Î°ä²¼

 

0x05 Îĵµ¸½Â¼

CNVD£ºwww.cnvd.org.cn

CNNVD£ºwww.cnnvd.org.cn

CVE£ºcve.mitre.org

NVD£ºnvd.nist.gov

CVSS£ºwww.first.org

 

0x06 ¹ØÓÚGA»Æ½ð¼×

¹Ø×¢ÒÔϹ«¼ÒºÅ£¬»ñÈ¡¸ü¶à×ÊѶ£º

image.png      image.png