¡¾·ì϶¹«¸æ¡¿FortiOS TACACS+Éí·ÝÈÏÖ¤ÈÆ¹ý·ì϶(CVE-2025-22252)

°ä²¼¹¦·ò 2025-05-16

Ò»¡¢·ì϶¸ÅÊö


·ìϼûû³Æ

FortiOS TACACS+Éí·ÝÈÏÖ¤ÈÆ¹ý·ì϶

CVE   ID

CVE-2025-22252

·ì϶ÀàÐÍ

Éí·ÝÈÏÖ¤ÈÆ¹ý

·¢ÏÖ¹¦·ò

2025-05-16

·ì϶ÆÀ·Ö

9.0

·ì϶µÈ¼¶

ÑϳÁ

¹¥»÷ÏòÁ¿

ÍøÂç

ËùÐèȨÏÞ

ÎÞ

ÀûÓÃÄѶÈ

µÍ

Óû§½»»¥

²»±ØÒª

PoC/EXP

δ¹«¿ª

ÔÚÒ°ÀûÓÃ

δ·¢ÏÖ


FortiOSÊÇFortinetÌṩµÄ²Ù×÷ϵͳ£¬ÓÃÓÚÆä°²È«É豸£¨Èç·À»ðǽ£©¡£FortiProxyÊÇFortiOSµÄÒ»¸ö×é¼þ£¬ÖØÒªÓÃÓÚ´úÀí·þÎñ£¬Ìṩ·´Ïò´úÀí¡¢WebÀûÓ÷À»ðǽµÈÖ°ÄÜ£¬Ô®ÊÔìóÒµ±£»¤Æä Web ÀûÓÃÃâÊܹ¥»÷²¢ÓÅ»¯ÍøÂçÁ÷Á¿¡£


2025Äê5ÔÂ16ÈÕ£¬GA»Æ½ð¼×¼¯ÍÅVSRC¼à²âµ½fortiguard°ä²¼µÄ°²È«²¼¸æ£¬Ö¸³öFortiOS¡¢FortiProxyºÍFortiSwitchManagerÖеÄTACACS+´æÔÚÉí·ÝÈÏÖ¤ÈÆ¹ý·ì϶¡£µ±TACACS+ÅäÖÃΪʹÓÃÔ¶³ÌTACACS+·þÎñÆ÷½øÐÐÉí·ÝÑéÖ¤£¬ÇҸ÷þÎñÆ÷ʹÓÃASCIIÈÏ֤ʱ£¬¹¥»÷ÕßÄܹ»ÈƹýÕý³£µÄÈÏÖ¤»úÔ죬¼Ù×°³ÉÓÐЧÖÎÀíÔ±£¬»ñµÃÉ豸µÄÖÎÀíԱȨÏÞ¡£¸Ã·ì϶¿ÉÄܵ¼ÖÂδ¾­ÊÚȨµÄ½Ó¼û£¬½ø¶øÈù¥»÷Õ߯ëÈ«½ÚÔìÉ豸¡£


¶þ¡¢Ó°ÏìÁìÓò


FortiOS 7.6°æ±¾Ó°ÏìÁìÓò 7.6.0
FortiOS 7.4°æ±¾Ó°ÏìÁìÓò 7.4.4 ¡Ü FortiOS ¡Ü 7.4.6
FortiProxy 7.6°æ±¾Ó°ÏìÁìÓò 7.6.0 ¡Ü FortiProxy ¡Ü 7.6.1
FortiSwitchManager 7.2°æ±¾Ó°ÏìÁìÓò7.2.5


Èý¡¢°²È«´ëÊ©


3.1 Éý¼¶°æ±¾


¹Ù·½ÒѰ䲼°²È«¸üУ¬½¨ÒéÊÜÓ°ÏìÓû§¾¡¿ìÉý¼¶¡£
FortiOS 7.6°æ±¾Éý¼¶ÖÁ7.6.1»ò¸ü¸ß°æ±¾
FortiOS 7.4°æ±¾Éý¼¶ÖÁ7.4.7»ò¸ü¸ß°æ±¾
FortiProxy 7.6°æ±¾Éý¼¶ÖÁ7.6.2»ò¸ü¸ß°æ±¾
FortiSwitchManager 7.2°æ±¾Éý¼¶ÖÁ7.2.6»ò¸ü¸ß°æ±¾


ÏÂÔØÁ´½Ó£ºhttps://docs.fortinet.com/upgrade-tool/


3.2 һʱ´ëÊ©


ʹÓÃÆäËûÈÏÖ¤·½Ê½
config user tacacs+
   edit "TACACS-SERVER"
       set server
       set key
       set authen-type [pap, mschap, chap]
       set source-ip
   next
End
»òÕß
config user tacacs+
   edit "TACACS-SERVER"
       set server
       set key
       unset authen-type
       set source-ip
   next
end


3.3 ͨÓý¨Òé


? ¶¨ÆÚ¸üÐÂϵͳ²¹¶¡£¬Ï÷¼õϵͳ·ì϶£¬ÌáÉý·þÎñÆ÷µÄ°²È«ÐÔ¡£
¼ÓǿϵͳºÍÍøÂçµÄ½Ó¼û½ÚÔ죬Åú¸Ä·À»ðǽսÊõ£¬¹Ø¹Ø·Ç±ØÒªµÄÀûÓö˿ڻò·þÎñ£¬Ï÷¼õ½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Â¶³öµ½¹«Íø£¬Ï÷¼õ¹¥»÷Ãæ¡£
ʹÓÃÆóÒµ¼¶°²È«²úÆ·£¬ÌáÉýÆóÒµµÄÍøÂ簲ȫ»úÄÜ¡£
¼ÓǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬ÆôÓöà³É·ÖÈÏÖ¤»úÔìºÍ×îÓ×ȨÏÞ×¼Ôò£¬Óû§ºÍÈí¼þȨÏÞӦά³ÖÔÚ×îµÍÏÞ¶È¡£
ÆôÓÃÇ¿ÃÜÂëÕ½Êõ²¢ÉèÖÃΪ¶¨ÆÚÅú¸Ä¡£


3.4 ²Î¿¼Á´½Ó


https://www.fortiguard.com/psirt/FG-IR-24-472