FortinetÇå¾²²úÆ·Ó²±àÂë¼ÓÃÜÃÜÔ¿Îó²îÇ徲ͨ¸æ
Ðû²¼Ê±¼ä 2019-11-27Îó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2018-9195£¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÖÐΣ£¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º5.9
Ó°Ïì°æ±¾
Fortinet FortiOS 6.0.6¼°Ö®Ç°°æ±¾
FortiClient 6.0.6¼°Ö®Ç°°æ±¾£¨Windows £©ºÍ6.2.1¼°Ö®Ç°°æ±¾£¨Mac£©
Îó²î¸ÅÊö
Fortinet FortiOSºÍFortinet FortiClient¶¼ÊÇÃÀ¹ú·ÉËþ£¨Fortinet£©¹«Ë¾µÄ²úÆ·¡£¡£¡£¡£¡£¡£Fortinet FortiOSÊÇÒ»Ì×רÓÃÓÚFortiGateÍøÂçÇ徲ƽ̨ÉϵÄÇå¾²²Ù×÷ϵͳ¡£¡£¡£¡£¡£¡£¸ÃϵͳΪÓû§Ìṩ·À»ðǽ¡¢·À²¡¶¾¡¢IPSec/SSLVPN¡¢WebÄÚÈݹýÂ˺ͷ´À¬»øÓʼþµÈ¶àÖÖÇå¾²¹¦Ð§¡£¡£¡£¡£¡£¡£Fortinet FortiClientÊÇÒ»Ì×ÒÆ¶¯ÖÕ¶ËÇå¾²½â¾ö¼Æ»®¡£¡£¡£¡£¡£¡£¸Ã¼Æ»®ÓëFortiGate·À»ðǽװ±¸ÅþÁ¬Ê±¿ÉÌṩIPsecºÍSSL¼ÓÃÜ¡¢¹ãÓòÍøÓÅ»¯¡¢Öն˺ϹæºÍË«Òò×ÓÈÏÖ¤µÈ¹¦Ð§¡£¡£¡£¡£¡£¡£
¸ÃÎó²îÔ´ÓÚFortiGuardЧÀÍͨѶÐÒéʹÓÃÁËÓ²±àÂëµÄ¼ÓÃÜÃÜÔ¿¡£¡£¡£¡£¡£¡£ÊÜÓ°ÏìµÄ²úÆ·°üÀ¨FortiGate·À»ðǽÒÔ¼°MacºÍWindows°æ±¾µÄFortiClientÖն˱£»£»£»£»£»¤Èí¼þ¡£¡£¡£¡£¡£¡£ÕâÈýÖÖ²úƷʹÓÃÈõ¼ÓÃÜ£¨XOR£©²¢ÇÒÊÇÓ²±àÂëµÄ¼ÓÃÜÃÜÔ¿ÓëÖÖÖÖFortiGateÔÆÐ§À;ÙÐÐͨѶ¡£¡£¡£¡£¡£¡£¸ÃÃÜÔ¿ÓÃÓÚ¼ÓÃÜFortiGuard Web¹ýÂ˹¦Ð§¡¢FortiGuard·´À¬»øÓʼþ¹¦Ð§ºÍFortiGuard AntiVirus¹¦Ð§µÄÓû§Á÷Á¿¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉʹÓôËÎó²îÐá̽Óû§µÄÁ÷Á¿£¬£¬£¬£¬£¬£¬£¬¸ú×ÙËûÃǵÄä¯ÀÀ¼Í¼»òµç×ÓÓʼþÊý¾Ý¡£¡£¡£¡£¡£¡£
Îó²îÑéÖ¤
ÔÝÎÞEXP/POC¡£¡£¡£¡£¡£¡£
ÐÞ¸´½¨Òé
ÏÖÔÚ³§ÉÌÒÑÐû²¼Éý¼¶²¹¶¡ÒÔÐÞ¸´Îó²î£¬£¬£¬£¬£¬£¬£¬²¹¶¡»ñÈ¡Á´½Ó£º
https://fortiguard.com/psirt/FG-IR-18-100¡£¡£¡£¡£¡£¡£
²Î¿¼Á´½Ó
https://www.zdnet.com/article/some-fortinet-products-shipped-with-hardcoded-encryption-keys/