跳到主要内容

超危

Fortinet FortiClient EMS身份验证绕过漏洞

2026-04-04 00:38:35 公开 ,2026-07-08 14:07:12 更新

  • CISA KEV
  • 关键漏洞
  • 无需认证
  • 远程
  • 公开PoC
CWEs:
CWE-284 (Improper Access Control)
CAPEC:
CAPEC-19 (Embedding Scripts within Scripts) CAPEC-441 (Malicious Logic Insertion) CAPEC-478 (Modification of Windows Service Configuration) CAPEC-479 (Malicious Root Certificate) CAPEC-502 (Intent Spoof) CAPEC-503 (WebView Exposure) CAPEC-536 (Data Injected During Configuration) CAPEC-546 (Incomplete Data Deletion in a Multi-Tenant Environment) CAPEC-550 (Install New Service) CAPEC-551 (Modify Existing Service) CAPEC-552 (Install Rootkit) CAPEC-556 (Replace File Extension Handlers) CAPEC-558 (Replace Trusted Executable) CAPEC-562 (Modify Shared File) CAPEC-563 (Add Malicious File to Shared Webroot) CAPEC-564 (Run Software at Logon) CAPEC-578 (Disable Security Software)
SSVC:
可利用状态:已被积极利用攻击自动化:是技术影响评估:全部 2026-04-03 08:00:00

风险信息

CVSS v3.1 向量
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C
CVSS v3.1 风险值
9.8

详细信息

漏洞类型
其他
漏洞描述
Fortinet FortiClientEMS 7.4.5到7.4.6版本API层在处理特定管理API请求时存在访问控制缺陷,攻击者通过伪造特定的访问头绕过所有API身份验证和授权保护,获取后端访问权限。成功利用后,攻击者可在服务器上以系统权限执行任意代码或命令,导致服务器被完全接管。
修复建议
应用针对7.4.5、7.4.6的热补丁,或升级到FortiClient EMS版本7.4.7及更高版本。参考链接: https://fortiguard.fortinet.com/psirt/FG-IR-26-099 https://docs.fortinet.com/document/forticlient/7.4.5/ems-release-notes/832484 https://docs.fortinet.com/document/forticlient/7.4.6/ems-release-notes/832484

参考链接