Sinisterly
Tutorial CVE-2022-40684 - Printable Version

+- Sinisterly (https://sinister.li)
+-- Forum: Hacking (https://sinister.li/Forum-Hacking)
+--- Forum: Website & Server Hacking (https://sinister.li/Forum-Website-Server-Hacking)
+--- Thread: Tutorial CVE-2022-40684 (/Thread-Tutorial-CVE-2022-40684)

Pages: 1 2


CVE-2022-40684 - zwriner - 10-26-2022

CVSS Score: 9.6

Vulnerable Fortinet product versions:

FortiOS versions between 7.0.0 - 7.0.6 and 7.2.0 - 7.2.1

FortiProxy versions between 7.0.0 - 7.0.6 and version 7.2.0

FortiSwitchManager versions 7.0.0 and 7.2.0

[Image: DMhh5f.jpg]


RE: CVE-2022-40684 - fritz - 10-26-2022

I don't see the link in your post?

I'd recommend using the Metasploit exploit: https://packetstormsecurity.com/files/169431/Fortinet-FortiOS-FortiProxy-FortiSwitchManager-Authentication-Bypass.html


RE: CVE-2022-40684 - mothered - 10-26-2022

(10-26-2022, 09:17 AM)fritz Wrote: I don't see the link in your post?
Obviously forgot to post It.

I've come across countless users over the last decade who did the same.


RE: CVE-2022-40684 - fritz - 10-26-2022

(10-26-2022, 09:42 AM)mothered Wrote:
(10-26-2022, 09:17 AM)fritz Wrote: I don't see the link in your post?
Obviously forgot to post It.

I've come across countless users over the last decade who did the same.
Seems to be a pattern with this user (bot?) though.
https://sinister.ly/Thread-Leak-Google-Cloud-Platform-Instance-Metadata
https://sinister.ly/Thread-Leak-CodeMeter-Webadmin-Dashboard
...
I believe they're originally all supposed to be from blog.criminalip.io, but it looks like his script is broken Wink


About the original subject, I don't know much about Fortinet, but it could be interesting to the community to also have a way to identify potential vulnerable servers (search for open ports or hints in google search for example).
Seeing the exploit code it seems it only checks if random path is 401 protected and that a "fortinet-formatted" request to /system/status does return a 200.


RE: CVE-2022-40684 - mothered - 10-26-2022

(10-26-2022, 11:53 AM)fritz Wrote: Seems to be a pattern with this user (bot?) though.
https://sinister.ly/Thread-Leak-Google-Cloud-Platform-Instance-Metadata
https://sinister.ly/Thread-Leak-CodeMeter-Webadmin-Dashboard
Not sure offhand.

I'll need to assess his/her activity.

(10-26-2022, 11:53 AM)fritz Wrote: About the original subject, I don't know much about Fortinet, but it could be interesting to the community to also have a way to identify potential vulnerable servers (search for open ports or hints in google search for example).
Absolutely.

I couldn't agree more.


RE: CVE-2022-40684 - zwriner - 10-28-2022

(10-26-2022, 09:17 AM)fritz Wrote: I don't see the link in your post?

I'd recommend using the Metasploit exploit: https://packetstormsecurity.com/files/169431/Fortinet-FortiOS-FortiProxy-FortiSwitchManager-Authentication-Bypass.html

Found using criminal ip's asset search - https://www.criminalip.io/


RE: CVE-2022-40684 - mothered - 10-28-2022

(10-28-2022, 01:43 AM)zwriner Wrote: Found using criminal ip's asset search - https://www.criminalip.io/
It's best to add the link to your opening post.


RE: CVE-2022-40684 - zwriner - 11-01-2022

(10-28-2022, 02:47 AM)mothered Wrote:
(10-28-2022, 01:43 AM)zwriner Wrote: Found using criminal ip's asset search - https://www.criminalip.io/
It's best to add the link to your opening post.
My bad I'll keep that in mind next time. Thank you!


RE: CVE-2022-40684 - HackingRealm - 11-01-2022

thanks a lot.... been looking for this


RE: CVE-2022-40684 - Oni - 11-01-2022

Moving this to Website & Server Hacking.