{"id":19829,"date":"2023-03-10T09:51:04","date_gmt":"2023-03-10T01:51:04","guid":{"rendered":"https:\/\/blog.pmail.idv.tw\/?p=19829"},"modified":"2023-03-10T10:23:31","modified_gmt":"2023-03-10T02:23:31","slug":"%e8%b3%87%e5%ae%89%e9%80%9a%e5%a0%b1-fortinet-cve-2023-25610-cvss-v3-9-3","status":"publish","type":"post","link":"https:\/\/blog.pmail.idv.tw\/?p=19829","title":{"rendered":"[\u8cc7\u5b89\u901a\u5831] Fortinet CVE-2023-25610 (CVSS v3 9.3)"},"content":{"rendered":"<p>Fortinet \u53c8\u51fa\u73fe\u6f0f\u6d1e<\/p>\n<p>Fortinet addressed a critical buffer underwrite (\u2018buffer underflow\u2019) vulnerability, tracked as CVE-2023-25610 (CVSS v3 9.3), that resides in the administrative interface in FortiOS and FortiProxy. A remote, unauthenticated attacker can exploit the vulnerability to execute arbitrary code on the vulnerable device and trigger a DoS condition on the GUI, by sending specifically crafted requests.<\/p>\n<p><!--more--><\/p>\n<p>\u6709\u554f\u984c\u7684\u7248\u672c<\/p>\n<ul>\n<li>FortiOS version 7.2.0 through 7.2.3\n<li>FortiOS version 7.0.0 through 7.0.9\n<li>FortiOS version 6.4.0 through 6.4.11\n<li>FortiOS version 6.2.0 through 6.2.12\n<li>FortiOS 6.0, all versions\n<li>FortiProxy version 7.2.0 through 7.2.2\n<li>FortiProxy version 7.0.0 through 7.0.8\n<li>FortiProxy version 2.0.0 through 2.0.11\n<li>FortiProxy 1.2, all versions\n<li>FortiProxy 1.1, all versions<\/li>\n<\/ul>\n<p>\u5efa\u8b70\u66f4\u65b0<\/p>\n<ul>\n<li>FortiOS version 7.4.0 or above\n<li>FortiOS version 7.2.4 or above\n<li>FortiOS version 7.0.10 or above\n<li>FortiOS version 6.4.12 or above\n<li>FortiOS version 6.2.13 or above\n<li>FortiProxy version 7.2.3 or above\n<li>FortiProxy version 7.0.9 or above\n<li>FortiProxy version 2.0.12 or above\n<li>FortiOS-6K7K version 7.0.10 or above\n<li>FortiOS-6K7K version 6.4.12 or above\n<li>FortiOS-6K7K version 6.2.13 or above<\/li>\n<\/ul>\n<p>\u5982\u679c\u66ab\u6642\u9084\u6c92\u5b89\u6392\u66f4\u65b0\u8a08\u756b\uff0c\u53ef\u4ee5\u5148\u628a\u7ba1\u7406\u4ecb\u9762\u9396\u5b9aIP\u6216\u662fWAN\u7aef\u53e3\u7ba1\u7406\u4ecb\u9762\u95dc\u9589https http \u4f86\u7de9\u89e3\u4e00\u4e0b\uff0c\u5efa\u8b70\u9084\u662f\u5b89\u6392\u66f4\u65b0\u3002<\/p>\n<p>PS: \u56e0\u70ba\u6b64\u5806\u758a\u5340\u6f0f\u6d1e\u662f\u5b58\u5728\u65bc httpsd \u7684\u7a0b\u5e8f\uff0c\u6240\u4ee5\u7121\u6cd5\u7d93\u7531 trust-host \u4f86\u907f\u514d\uff0c\u5fc5\u9808\u4f7f\u7528 local-in policy \u4f86\u9650\u5236\u3002<\/p>\n<p>\u53c3\u8003<\/p>\n<h3><font size=\"3\"><a href=\"https:\/\/securityaffairs.com\/143227\/security\/fortinet-fortios-fortiproxy-critical-bug.html?https:\/\/securityaffairs.com\/143227\/security\/fortinet-fortios-fortiproxy-critical-bug.html?fbclid=IwAR0LY1lr1m_Xyv3Mm5CCvt6R7Mf8gVoBNN3QfaflWnOzRTqR4YmOaHR8bDs\" target=\"_blank\" rel=\"noopener\">A critical flaw affects Fortinet FortiOS and FortiProxy, patch it now!<\/a><\/font><\/h3>\n<div class=\"21cd169d3c0f71e95b84db320302cb4a\" data-index=\"1\" style=\"float: right; margin:10px 0 10px 10px;\">\n<script async src=\"https:\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-8711325745898650\"\r\n     crossorigin=\"anonymous\"><\/script>\n<\/div>\n\n<div style=\"font-size: 0px; height: 0px; line-height: 0px; margin: 0; padding: 0; clear: both;\"><\/div>","protected":false},"excerpt":{"rendered":"<p>Fortinet \u53c8\u51fa\u73fe\u6f0f\u6d1e Fortinet addressed a crit &hellip; <a href=\"https:\/\/blog.pmail.idv.tw\/?p=19829\">\u95b1\u8b80\u5168\u6587 <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"ngg_post_thumbnail":0,"footnotes":""},"categories":[194],"tags":[],"class_list":["post-19829","post","type-post","status-publish","format-standard","hentry","category-194"],"_links":{"self":[{"href":"https:\/\/blog.pmail.idv.tw\/index.php?rest_route=\/wp\/v2\/posts\/19829","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.pmail.idv.tw\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.pmail.idv.tw\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.pmail.idv.tw\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.pmail.idv.tw\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=19829"}],"version-history":[{"count":2,"href":"https:\/\/blog.pmail.idv.tw\/index.php?rest_route=\/wp\/v2\/posts\/19829\/revisions"}],"predecessor-version":[{"id":19831,"href":"https:\/\/blog.pmail.idv.tw\/index.php?rest_route=\/wp\/v2\/posts\/19829\/revisions\/19831"}],"wp:attachment":[{"href":"https:\/\/blog.pmail.idv.tw\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=19829"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.pmail.idv.tw\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=19829"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.pmail.idv.tw\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=19829"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}