漏洞描述 近日,Fortinet 发布安全公告,披露 CVE-2022-42475 Fortinet FortiOS sslvpnd 远程代码执行漏洞。攻击者可构造恶意请求出发溢出等,造成远程代码执行。目前外界尚未流传POC。
相关漏洞推荐 POC CVE-2015-1880: Fortinet FortiOS <=5.2.3 - Cross-Site Scripting POC CVE-2016-3978: Fortinet FortiOS - Open Redirect/Cross-Site Scripting POC CVE-2017-3132: Fortinet FortiOS < 5.6.0 - Cross-Site Scripting POC CVE-2017-3133: Fortinet FortiOS < 5.6.0 - Cross-Site Scripting POC CVE-2018-13379: Fortinet FortiOS - Credentials Disclosure POC CVE-2018-13380: Fortinet FortiOS - Cross-Site Scripting POC CVE-2018-13379: Fortinet FortiOS - Credentials Disclosure POC CVE-2022-40684: Fortinet FortiOS admin 远程命令执行漏洞 Fortinet FortiOS/FortiProxy 认证绕过漏洞 Fortinet FortiOS SSLVPN CVE-2024-21762 越界写漏洞 Fortinet FortiOS CVE-2022-40684 认证绕过漏洞 Fortinet FortiOS HA 不正确的权限管理漏洞 Fortinet FortiOS 远程代码执行漏洞