¡¾·ì϶¹«¸æ¡¿Fortinet FortiOSÓëFortiProxyÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶(CVE-2024-55591)
°ä²¼¹¦·ò 2025-01-16Ò»¡¢·ì϶¸ÅÊö
·ìϼûû³Æ | Fortinet FortiOSÓëFortiProxyÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶ | ||
CVE ID | CVE-2024-55591 | ||
·ì϶ÀàÐÍ | Éí·ÝÑéÖ¤ÈÆ¹ý | ·¢ÏÖ¹¦·ò | 2025-01-16 |
·ì϶ÆÀ·Ö | 9.8 | ·ì϶µÈ¼¶ | ÑϳÁ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | µÍ |
ÀûÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ÎÞ |
PoC/EXP | δ¹«¿ª | ÔÚÒ°ÀûÓà | ÒÑ·¢ÏÖ |
FortiOS ÊÇ Fortinet ÌṩµÄ²Ù×÷ϵͳ£¬ÓÃÓÚÆä°²È«É豸£¨Èç·À»ðǽ£©¡£FortiProxy ÊÇ FortiOS µÄÒ»¸ö×é¼þ£¬ÖØÒªÓÃÓÚ´úÀí·þÎñ£¬Ìṩ·´Ïò´úÀí¡¢Web ÀûÓ÷À»ðǽµÈÖ°ÄÜ£¬Ô®ÊÔìóÒµ±£»¤Æä Web ÀûÓÃÃâÊܹ¥»÷²¢ÓÅ»¯ÍøÂçÁ÷Á¿¡£
2025Äê1ÔÂ16ÈÕ£¬GA»Æ½ð¼×¼¯ÍÅVSRC¼à²âµ½Fortinet ¹Ù·½°ä²¼°²È«²¼¸æ£¬Ö¸³ö FortiOS ºÍ FortiProxy ´æÔÚÒ»¸öÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶£¨CVE-2024-55591£©£¬¹¥»÷Õß¿Éͨ¹ý¾«ÐÄ»ú¹ØµÄÒªÇó£¬ÀûÓà Node.js WebSocket Ä£¿é£¬ÈƹýÉí·ÝÑéÖ¤²¢»ñÈ¡³¬µÈÖÎÀíԱȨÏÞ¡£¸Ã·ì϶µÄ CVSS ·ì϶ÆÀ·ÖΪ 9.8 ·Ö£¬·ì϶¼¶±ðΪÑϳÁ£¬¿ÉÄܵ¼ÖÂÔ¶³Ì¹¥»÷Õß¶ÔÊÜÓ°ÏìϵͳµÄÆëÈ«½ÚÔì¡£
¶þ¡¢Ó°ÏìÁìÓò
7.0.0 <= FortiOS 7.0 <= 7.0.16
Èý¡¢°²È«´ëÊ©
3.1 Éý¼¶°æ±¾
ÏÂÔØÁ´½Ó£º


¾©¹«Íø°²±¸11010802024551ºÅ