Fortinet FortiOS ÊÚȨÎÊÌâ·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2019-05-30

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2018-13382£¬Î£ÏÕ¼¶±ð£º¸ß¼¶£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨

ÊÜÓ°ÏìµÄ°æ±¾


FortiOS 6.0.0 to 6.0.4 
FortiOS 5.6.0 to 5.6.8 
FortiOS 5.4.1 to 5.4.10

½öÔÚÆôÓÃSSL VPN WebÃÅ»§Ê±¡£


·ì϶¸ÅÊö


Fortinet FortiOSÊÇÃÀ¹ú·ÉËþ£¨Fortinet£©¹«Ë¾µÄÒ»Ì×רÓÃÓÚFortiGateÍøÂ簲ȫƽ̨Éϵݲȫ²Ù×÷ϵͳ¡£¸ÃϵͳΪÓû§Ìṩ·À»ðǽ¡¢·À²¡¶¾¡¢IPSec/SSLVPN¡¢WebÄÚÈݹýÂ˺ͷ´À¬»øÓʼþµÈ¶àÖÖ°²È«Ö°ÄÜ¡£


Fortinet FortiOSµÄSSL VPN WebÃÅ»§´æÔÚÊÚȨÎÊÌâ·ì϶¡£¸Ã·ì϶ԴÓÚÍøÂçϵͳ»ò²úÆ·ÖжÌȱÉí·ÝÑéÖ¤´ëÊ©»òÉí·ÝÑé֤ǿ¶È²»¼°¡£


·ì϶ÑéÖ¤


ÔÝÎÞPOC/EXP¡£


½¨¸´½¨Òé


Ŀǰ³§ÉÌÒѰ䲼Éý¼¶²¹¶¡ÒÔ½¨¸´·ì϶£¬ÇëÉý¼¶µ½FortiOS 5.4.11,5.6.9,6.0.5,6.2.0»òÒÔÉϰ汾£¬²¹¶¡»ñÈ¡Á´½Ó£ºhttps://fortiguard.com/psirt/FG-IR-18-389 ¡£


»òÕßͨ¹ýÀûÓÃÒÔÏÂCLIºÅÁî½ûÓÃSSL-VPN WebÃÅ»§·þÎñ£º
config vpn ssl settings
unset source-interface

end


²Î¿¼Á´½Ó


https://fortiguard.com/psirt/FG-IR-18-389
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-201905-1025