¡¾Â©¶´Í¨¸æ¡¿Fortinet 8Ô¶à¸öÄþ¾²Â©¶´
Ðû²¼Ê±¼ä 2021-08-040x00 ©¶´¸ÅÊö
2021Äê8ÔÂ3ÈÕ£¬Fortinet£¨·ÉËþ£©Ðû²¼Äþ¾²Í¨¸æ£¬ÐÞ¸´ÁËÆä²úÎïÖеÄ22¸öÄþ¾²Â©¶´£¬ÕâЩ©¶´Éæ¼°FortiSandbox ¡¢FortiPortal¡¢ FortiManager¡¢FortiAnalyzer¡¢ FortiOSºÍFortiAuthenticator¡£
0x01 ©¶´ÏêÇé
ÔÚ±¾´Î´ËÐÞ¸´µÄ22¸ö©¶´ÖУ¬×îΪÑÏÖصÄÊÇFortiPortalÖеÄÒ»¸öÔ¶³Ì´úÂëÖ´ÐЩ¶´£¨CVE-2021-32588£©ºÍÒ»¸öSQL×¢È멶´£¨CVE-2021-32590£©£¬¹¥»÷Õß¿ÉÒÔÀûÓÃÕâ2¸ö©¶´ÔÚδÊÚȨµÄÇé¿öÏÂÖ´ÐÐÈÎÒâÃüÁî¡£
FortiPortalÊÇFortinet¹«Ë¾µÄÍйÜÔÆÄþ¾²¼Æı¹ÜÀíºÍÍþв·ÖÎö²úÎרΪÂú×ãÍйܷþÎñÌṩÉÌ (MSP) µÄÍйܷþÎñÐèÇó¶øÉè¼Æ£¬ÆäÔÚ¶à×⻧¡¢¶à²ã¼¶¹ÜÀí¿ò¼ÜÄÚÌṩһÌ×È«ÃæµÄ Wi-Fi ºÍÄþ¾²¹ÜÀí¹¦Ð§£¬Ê¹µÃMSP Äܹ»Í¨¹ýµ¥Ò»¹ÜÀíƽ̨¼ì²ì²¢¹ÜÀíÆä¿Í»§ÍøÂç¡£
©¶´ÏêÇéÈçÏ£º
FortiPortal Ô¶³Ì´úÂëÖ´ÐЩ¶´£¨CVE-2021-32588£©
ÓÉÓÚFortiPortalÖдæÔÚÓ²±àÂëƾ֤£¨CWE-798£©Â©¶´£¬Î´¾ÈÏÖ¤µÄÔ¶³Ì¹¥»÷Õß¿ÉÒÔͨ¹ýʹÓÃĬÈϵÄÓ²±àÂëTomcat¹ÜÀíÆ÷Óû§ÃûºÍÃÜÂëÉÏ´«ºÍ²¿Êð¶ñÒâWebÓ¦Ó÷¨Ê½´æµµÎļþ£¬²¢ÒÔrootÉí·ÝÖ´ÐÐÈÎÒâÃüÁ¸Ã©¶´µÄCVSSv3ÆÀ·ÖΪ9.3¡£
Ó°Ï췶Χ
FortiPortal 5.2.5 ¼°ÒÔÏ°汾
FortiPortal 5.3.5 ¼°ÒÔÏ°汾
FortiPortal 6.0.4 ¼°ÒÔÏ°汾
FortiPortal 5.0.x
FortiPortal 5.1.x
FortiPortal SQL×¢È멶´£¨CVE-2021-32590£©
FortiPortalÖдæÔÚSQL×¢È멶´£¨CWE-89£©£¬¾ßÓÐÆÕͨÓû§È¨Ï޵Ĺ¥»÷Õß¿ÉÒÔͨ¹ý¶ñÒâÖÆ×÷µÄHTTPÇëÇóÔڵײãSQLÊý¾Ý¿âÉÏÖ´ÐÐÈÎÒâÃüÁ¸Ã©¶´µÄCVSSv3ÆÀ·ÖΪ9.4¡£
Ó°Ï췶Χ
FortiPortal 6.0.4 ¼°ÒÔÏ°汾
FortiPortal 5.3.5 ¼°ÒÔÏ°汾
FortiPortal 5.2.5 ¼°ÒÔÏ°汾
FortiPortal 5.1.2 ¼°ÒÔÏ°汾
FortiPortal 5.0.3 ¼°ÒÔÏ°汾
FortiPortal 4.2.4 ¼°ÒÔÏ°汾
FortiPortal 4.1.2 ¼°ÒÔÏ°汾
FortiPortal 4.0.4 ¼°ÒÔÏ°汾
FortiPortal 3.2.2 ¼°ÒÔÏ°汾
³ýÉÏÊö©¶´Í⣬ÐèҪעÒâµÄ£¶¸ö¸ßΣ©¶´°üÂÞ£º
l FortiManager & FortiAnalyzerÖеÄSSRF©¶´£¨CVE-2021-32603£©£º¹¥»÷Õß¿ÉÀûÓôË©¶´Ö´ÐÐδÊÚȨµÄ´úÂë»òÃüÁî¡£
l FortiManager & FortiAnalyzer£¦FortiPortalÖеÄÃüÁî×¢È멶´£¨CVE-2021-26104£©£º¹¥»÷Õß¿ÉÒÔÀûÓôË©¶´ÒÔ root Éí·ÝÖ´ÐÐÈÎÒâ shell ÃüÁî¡£
l FortiSandboxÖеÄÃüÁî×¢È멶´£¨CVE-2021-26097£©£º¹¥»÷Õß¿ÉÒÔͨ¹ý·¢ËͶñÒâ HTTP ÇëÇóÖ´ÐÐδÊÚȨµÄ´úÂë»òÃüÁî¡£
l FortiSandboxÖеÄ·¾¶±éÀú©¶´£¨CVE-2021-24010£©£º¹¥»÷Õß¿ÉÒÔÀûÓôË©¶´ÊµÏÖδÊÚȨ·ÃÎÊÎļþ¡£
l FortiSandboxÖеÄSQL×¢È멶´£¨CVE-2020-29011£©£º¹¥»÷Õß¿ÉÒÔÀûÓôË©¶´ÔڵײãSQL½âÊÍÆ÷ÉÏÖ´ÐÐδÊÚȨµÄ´úÂë»òÃüÁî¡£
l FortiSandbox £¦ FortiAuthenticatorÖеľܾø·þÎñ©¶´£¨CVE-2021-22124£©£ºÎ´¾Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔͨ¹ý·¢ËͶñÒâÇëÇóʹÉ豸½øÈëÎÞÏìӦ״̬¡£
0x02 ´¦Öý¨Òé
Ä¿Ç°ÕâЩ©¶´ÒѾÐÞ¸´¡£
Õë¶ÔCVE-2021-32588£¬½¨Ò鼰ʱÉý¼¶µ½ÒÔÏ°汾£º
FortiPortal 5.2.6 »ò¸ü¸ß°æ±¾
FortiPortal 5.3.6 »ò¸ü¸ß°æ±¾
FortiPortal 6.0.5 »ò¸ü¸ß°æ±¾
Õë¶ÔCVE-2021-32590£¬½¨Ò鼰ʱÉý¼¶µ½ÒÔÏ°汾£º
FortiPortal 6.0.5 »ò¸ü¸ß°æ±¾
FortiPortal 5.3.6 »ò¸ü¸ß°æ±¾
FortiPortal 5.2.6 »ò¸ü¸ß°æ±¾
£¨×¢£º5.1¡¢5.0¡¢4.2¡¢4.1¡¢4.0ºÍ3.2°æ±¾µÄ²¹¶¡ÓдýÈ·ÈÏ¡££©
ÏÂÔØÁ´½Ó£º
https://www.fortinet.com/cn
0x03 ²Î¿¼Á´½Ó
https://www.fortiguard.com/psirt?date=08-2021
https://www.fortiguard.com/psirt/FG-IR-21-077
https://www.fortiguard.com/psirt/FG-IR-21-084
0x04 ¸üа汾
°æ±¾ | ÈÕÆÚ | ÐÞ¸ÄÄÚÈÝ |
V1.0 | 2021-08-04 | Ê×´ÎÐû²¼ |
0x05 Îĵµ¸½Â¼
CNVD£ºwww.cnvd.org.cn
CNNVD£ºwww.cnnvd.org.cn
CVE£ºcve.mitre.org
NVD£ºnvd.nist.gov
CVSS£ºwww.first.org
0x06 ¹ØÓÚ¶¶È¦Îª¶Ä¶øÉú
¹Ø×¢ÒÔϹ«Öںţ¬»ñÈ¡¸ü¶à×ÊѶ£º