• XSS.stack #1 – первый литературный журнал от юзеров форума

Remote Decrypt FortiManager configuration secrets (CVE-2020-9289)

Zodiac

RAM
Пользователь
Регистрация
04.11.2022
Сообщения
108
Реакции
40
CVE-2020-9289 and CVE-2019-6693 are related to the same default and hardcoded key.

The only differences on the decryption routine implemented in FortiManager/FortiAnalyzer are:
  • The IV handling (all the 16 bytes are provided before the encrypted data from digits).
  • The last encrypted block is stripped from the output so it needs junk to be appended then removed from the cleartext
See https://www.fortiguard.com/psirt/FG-IR-19-007 for more details.

URL - https://github.com/synacktiv/CVE-2020-9289
 


Напишите ответ...
  • Вставить:
Прикрепить файлы
Верх