Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add module for CVE-2024-21762 FortiOS out-of-bounds write to RCE #18824

Open
jheysel-r7 opened this issue Feb 12, 2024 · 2 comments
Open

Add module for CVE-2024-21762 FortiOS out-of-bounds write to RCE #18824

jheysel-r7 opened this issue Feb 12, 2024 · 2 comments
Labels
suggestion-module New module suggestions

Comments

@jheysel-r7
Copy link
Contributor

jheysel-r7 commented Feb 12, 2024

Summary

A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, 6.0.0 through 6.0.17, FortiProxy versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0.14, 2.0.0 through 2.0.13, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6, 1.0.0 through 1.0.7 allows attacker to execute unauthorized code or commands via specifically crafted requests

Basic example

PoC

Motivation

The application is widely used and is currently being exploited

@jheysel-r7 jheysel-r7 added the suggestion-module New module suggestions label Feb 12, 2024
@jheysel-r7 jheysel-r7 changed the title Add module for CVE-2024-21762 FortiOS SSLVPN out-of-bounds write to RCE Add module for CVE-2024-21762 FortiOS out-of-bounds write to RCE Feb 12, 2024
@sempervictus
Copy link
Contributor

Seconded, this may be a poor fix to a prior cve in the same stack and may be ripe terrain to find more. Infra for the sslvpn interfaces would be great and probably useful again down the line (as well as to backfill prior exploits).
Small note of caution: the automatic updates for the fixed versions seem to be broken for a lot of users so this ones very much still out in the wild and may be for some time if the broken versions preclude auto-update (as opposed to some server side issue).

@iNoSec2
Copy link

iNoSec2 commented Feb 27, 2024

Second it too. It will be a nice module to add since we see some of them in pentest

@jheysel-r7 jheysel-r7 moved this to In Progress in Metasploit Kanban Jun 26, 2024
@jheysel-r7 jheysel-r7 moved this from In Progress to Todo in Metasploit Kanban Jul 10, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
suggestion-module New module suggestions
Projects
None yet
Development

No branches or pull requests

3 participants