¡¾Îó²îͨ¸æ¡¿Fortinet 8Ô¶à¸öÇå¾²Îó²î
Ðû²¼Ê±¼ä 2021-08-040x00 Îó²î¸ÅÊö
2021Äê8ÔÂ3ÈÕ£¬£¬£¬£¬£¬£¬Fortinet£¨·ÉËþ£©Ðû²¼Ç徲ͨ¸æ£¬£¬£¬£¬£¬£¬ÐÞ¸´ÁËÆä²úÆ·ÖеÄ22¸öÇå¾²Îó²î£¬£¬£¬£¬£¬£¬ÕâЩÎó²îÉæ¼°FortiSandbox ¡¢FortiPortal¡¢ FortiManager¡¢FortiAnalyzer¡¢ FortiOSºÍFortiAuthenticator¡£¡£¡£¡£¡£¡£
0x01 Îó²îÏêÇé
ÔÚ±¾´Î´ËÐÞ¸´µÄ22¸öÎó²îÖУ¬£¬£¬£¬£¬£¬×îΪÑÏÖØµÄÊÇFortiPortalÖеÄÒ»¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-32588£©ºÍÒ»¸öSQL×¢ÈëÎó²î£¨CVE-2021-32590£©£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔʹÓÃÕâ2¸öÎó²îÔÚδÊÚȨµÄÇéÐÎÏÂÖ´ÐÐí§ÒâÏÂÁî¡£¡£¡£¡£¡£¡£
FortiPortalÊÇFortinet¹«Ë¾µÄÍйÜÔÆÇå¾²Õ½ÂÔÖÎÀíºÍÍþвÆÊÎö²úÆ·£¬£¬£¬£¬£¬£¬×¨ÎªÖª×ãÍйÜЧÀÍÌṩÉÌ (MSP) µÄÍйÜЧÀÍÐèÇó¶øÉè¼Æ£¬£¬£¬£¬£¬£¬ÆäÔÚ¶à×â»§¡¢¶à²ã¼¶ÖÎÀí¿ò¼ÜÄÚÌṩһÌ×ÖÜÈ«µÄ Wi-Fi ºÍÇå¾²ÖÎÀí¹¦Ð§£¬£¬£¬£¬£¬£¬Ê¹µÃMSP Äܹ»Í¨¹ý¼òµ¥ÖÎÀíÆ½Ì¨Éó²é²¢ÖÎÀíÆä¿Í»§ÍøÂç¡£¡£¡£¡£¡£¡£
Îó²îÏêÇéÈçÏ£º
FortiPortal Ô¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-32588£©
ÓÉÓÚFortiPortalÖб£´æÓ²±àÂëÆ¾Ö¤£¨CWE-798£©Îó²î£¬£¬£¬£¬£¬£¬Î´¾ÈÏÖ¤µÄÔ¶³Ì¹¥»÷Õß¿ÉÒÔͨ¹ýʹÓÃĬÈϵÄÓ²±àÂëTomcatÖÎÀíÆ÷Óû§ÃûºÍÃÜÂëÉÏ´«ºÍ°²ÅŶñÒâWebÓ¦ÓóÌÐò´æµµÎļþ£¬£¬£¬£¬£¬£¬²¢ÒÔrootÉí·ÝÖ´ÐÐí§ÒâÏÂÁ£¬£¬£¬£¬£¬¸ÃÎó²îµÄCVSSv3ÆÀ·ÖΪ9.3¡£¡£¡£¡£¡£¡£
Ó°Ïì¹æÄ£
FortiPortal 5.2.5 ¼°ÒÔϰ汾
FortiPortal 5.3.5 ¼°ÒÔϰ汾
FortiPortal 6.0.4 ¼°ÒÔϰ汾
FortiPortal 5.0.x
FortiPortal 5.1.x
FortiPortal SQL×¢ÈëÎó²î£¨CVE-2021-32590£©
FortiPortalÖб£´æSQL×¢ÈëÎó²î£¨CWE-89£©£¬£¬£¬£¬£¬£¬¾ßÓÐͨË×Óû§È¨Ï޵Ĺ¥»÷Õß¿ÉÒÔͨ¹ý¶ñÒâÖÆ×÷µÄHTTPÇëÇóÔڵײãSQLÊý¾Ý¿âÉÏÖ´ÐÐí§ÒâÏÂÁ£¬£¬£¬£¬£¬¸ÃÎó²îµÄCVSSv3ÆÀ·ÖΪ9.4¡£¡£¡£¡£¡£¡£
Ó°Ïì¹æÄ£
FortiPortal 6.0.4 ¼°ÒÔϰ汾
FortiPortal 5.3.5 ¼°ÒÔϰ汾
FortiPortal 5.2.5 ¼°ÒÔϰ汾
FortiPortal 5.1.2 ¼°ÒÔϰ汾
FortiPortal 5.0.3 ¼°ÒÔϰ汾
FortiPortal 4.2.4 ¼°ÒÔϰ汾
FortiPortal 4.1.2 ¼°ÒÔϰ汾
FortiPortal 4.0.4 ¼°ÒÔϰ汾
FortiPortal 3.2.2 ¼°ÒÔϰ汾
³ýÉÏÊöÎó²îÍ⣬£¬£¬£¬£¬£¬ÐèÒª×¢ÖØµÄ£¶¸ö¸ßΣÎó²î°üÀ¨£º
l FortiManager & FortiAnalyzerÖеÄSSRFÎó²î£¨CVE-2021-32603£©£º¹¥»÷Õß¿ÉʹÓôËÎó²îÖ´ÐÐδÊÚȨµÄ´úÂë»òÏÂÁî¡£¡£¡£¡£¡£¡£
l FortiManager & FortiAnalyzer£¦FortiPortalÖеÄÏÂÁî×¢ÈëÎó²î£¨CVE-2021-26104£©£º¹¥»÷Õß¿ÉÒÔʹÓôËÎó²îÒÔ root Éí·ÝÖ´ÐÐí§Òâ shell ÏÂÁî¡£¡£¡£¡£¡£¡£
l FortiSandboxÖеÄÏÂÁî×¢ÈëÎó²î£¨CVE-2021-26097£©£º¹¥»÷Õß¿ÉÒÔͨ¹ý·¢ËͶñÒâ HTTP ÇëÇóÖ´ÐÐδÊÚȨµÄ´úÂë»òÏÂÁî¡£¡£¡£¡£¡£¡£
l FortiSandboxÖеÄ·¾¶±éÀúÎó²î£¨CVE-2021-24010£©£º¹¥»÷Õß¿ÉÒÔʹÓôËÎó²îʵÏÖδÊÚȨ»á¼ûÎļþ¡£¡£¡£¡£¡£¡£
l FortiSandboxÖеÄSQL×¢ÈëÎó²î£¨CVE-2020-29011£©£º¹¥»÷Õß¿ÉÒÔʹÓôËÎó²îÔڵײãSQLÚ¹ÊÍÆ÷ÉÏÖ´ÐÐδÊÚȨµÄ´úÂë»òÏÂÁî¡£¡£¡£¡£¡£¡£
l FortiSandbox £¦ FortiAuthenticatorÖеľܾøÐ§ÀÍÎó²î£¨CVE-2021-22124£©£ºÎ´¾Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔͨ¹ý·¢ËͶñÒâÇëÇóʹװ±¸½øÈëÎÞÏìӦ״̬¡£¡£¡£¡£¡£¡£
0x02 ´¦Öóͷ£½¨Òé
ÏÖÔÚÕâЩÎó²îÒѾÐÞ¸´¡£¡£¡£¡£¡£¡£
Õë¶ÔCVE-2021-32588£¬£¬£¬£¬£¬£¬½¨ÒéʵʱÉý¼¶µ½ÒÔϰ汾£º
FortiPortal 5.2.6 »ò¸ü¸ß°æ±¾
FortiPortal 5.3.6 »ò¸ü¸ß°æ±¾
FortiPortal 6.0.5 »ò¸ü¸ß°æ±¾
Õë¶ÔCVE-2021-32590£¬£¬£¬£¬£¬£¬½¨ÒéʵʱÉý¼¶µ½ÒÔϰ汾£º
FortiPortal 6.0.5 »ò¸ü¸ß°æ±¾
FortiPortal 5.3.6 »ò¸ü¸ß°æ±¾
FortiPortal 5.2.6 »ò¸ü¸ß°æ±¾
£¨×¢£º5.1¡¢5.0¡¢4.2¡¢4.1¡¢4.0ºÍ3.2°æ±¾µÄ²¹¶¡ÓдýÈ·ÈÏ¡£¡£¡£¡£¡£¡££©
ÏÂÔØÁ´½Ó£º
https://www.fortinet.com/cn
0x03 ²Î¿¼Á´½Ó
https://www.fortiguard.com/psirt?date=08-2021
https://www.fortiguard.com/psirt/FG-IR-21-077
https://www.fortiguard.com/psirt/FG-IR-21-084
0x04 ¸üа汾
°æ±¾ | ÈÕÆÚ | ÐÞ¸ÄÄÚÈÝ |
V1.0 | 2021-08-04 | Ê×´ÎÐû²¼ |
0x05 Îĵµ¸½Â¼
CNVD£ºwww.cnvd.org.cn
CNNVD£ºwww.cnnvd.org.cn
CVE£ºcve.mitre.org
NVD£ºnvd.nist.gov
CVSS£ºwww.first.org
0x06 ¹ØÓÚ¼øºÚµ£±£Íø
¹Ø×¢ÒÔϹ«Öںţ¬£¬£¬£¬£¬£¬»ñÈ¡¸ü¶à×ÊѶ£º