Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Decrypt FortiGate configuration secrets | https://github.com/gquere/CVE-2019-6693 | POC Details |
| 2 | Decrypt reversible secrets encrypted using the default hardcoded key related to CVE-2020-9289 on FortiAnalyzer/FortiManager (the only difference with CVE-2019-6693 is the encryption routine). | https://github.com/synacktiv/CVE-2020-9289 | POC Details |
| 3 | An authorized remote user with access or knowledge of the standard encryption key can gain access and decrypt the FortiOS backup files and all non-administator passwords, private keys and High Availability passwords. | https://github.com/saladandonionrings/cve-2019-6693 | POC Details |
| 4 | None | https://github.com/Real4XoR/CVE-2019-6693 | POC Details |
No public POC found.
Login to generate AI POC| CVE-2019-17650 | Fortinet FortiClient 操作系统命令注入漏洞 | |
| CVE-2018-9195 | Fortinet FortiOS和Fortinet FortiClient 信任管理问题漏洞 | |
| CVE-2019-15704 | Fortinet FortiClient 信息泄露漏洞 |
No comments yet