CVE-2024-21762 is a critical out-of-bounds write vulnerability in the sslvpnd component of Fortinet FortiOS and FortiProxy SSL-VPN. Improper validation of parameters in specially crafted HTTP requests can cause memory corruption. A remote unauthenticated attacker can exploit the flaw to execute arbitrary code or commands on the affected appliance. Affected releases include FortiOS 7.4.0–7.4.2, 7.2.0–7.2.6, 7.0.0–7.0.13, 6.4.0–6.4.14, 6.2.0–6.2.15, and 6.0.0–6.0.17; and FortiProxy 7.4.0–7.4.2, 7.2.0–7.2.8, 7.0.0–7.0.14, 2.0.0–2.0.13, 1.2.0–1.2.13, 1.1.0–1.1.6, and 1.0.0–1.0.7. The vulnerability has been observed in active exploitation.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
7 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (5 hidden).
This is a 100-file exploit catalog rather than a detection-only repository: the supplied structure contains README.md, .gitignore, and 98 standalone Python clients in exp/. Filenames encode a FortiGate appliance SKU and exact FortiOS build, spanning models such as 30E through 3000D and firmware trains from 6.0 through 7.4. The critical asset is the per-image offset/gadget matrix: every client hardcodes build-specific stack layouts, BSS/GOT/function addresses, ROP gadgets, object sizes, and spray parameters. The code implements two unauthenticated SSL-VPN RCE families identified in the README as CVE-2024-21762 and CVE-2023-27997. CVE-2024-21762-style clients issue malformed chunked POST requests to /aaaa/bbbb while spraying /remote/error or /remote/hostcheck_validate. They corrupt request-processing state, redirect control flow through per-build ROP chains, and invoke FortiGate's internal execute_cmd routine. CVE-2023-27997-style clients first obtain a dynamic salt from /remote/info, reproduce the MD5/XOR enc= encoding, calculate seeds for controlled byte writes, spray SSL-related objects, and overwrite an indirect target/GOT entry to execute attacker-controlled commands. Payload delivery has three observed forms: direct Node.js HTTP retrieval and eval of a configurable /s.js URL; TFTP retrieval of s.js into /tmp/s followed by Node execution; and x86-64/ARM raw-payload stagers. The latter obtain a length-prefixed second stage from a configurable TCP service, allocate executable memory, execute the received bytes, and make a second configurable TCP callback that functions as a reverse shell channel. TLS certificate verification is disabled throughout. Many clients repeatedly attack in parallel, with hardcoded CPU/thread counts and high connection/spray volumes, indicating reliability tuning rather than a minimal PoC. No fixed victim IP, domain, or attacker infrastructure is embedded. Target and callback hosts/ports are command-line supplied, so the fingerprintable observables are primarily the SSL-VPN paths, malformed chunked-transfer patterns, unusually large form/hostcheck requests, the FortiSSLVPN user agent, requests to /remote/info, and outbound target traffic to operator-selected HTTP, TFTP, or raw TCP services. README references additional launcher, listener, shellcode, and JavaScript files, but those are not present in the supplied file listing; conclusions about their contents are therefore limited to the README's description.
Repository contains a single Python exploit script (exploit.py) plus a minimal README with example usage. Key structure/purpose: - README.md: shows how to run the tool against a single target with a callback IP/port. - exploit.py: a network-based exploitation tool that connects via raw TCP sockets to a specified IP:PORT and sends an HTTP POST request to /remote/hostcheck_validate. The request includes Fortinet-like headers (FortiSSLVPNClient/6.4.0 User-Agent and SVPNCOOKIE) and a form-encoded body. Exploit capabilities: - Single-target mode (--target IP:PORT): sends one exploit attempt and prints a monitoring hint. - Batch mode (--input file, --output file): iterates over multiple IP:PORT entries, attempts exploitation, and writes per-target results. - Payload delivery: injects a bash reverse shell command into a form field (host=...) and repeats it to increase likelihood of triggering parsing/overflow conditions (though no actual memory corruption/ROP is implemented in the active code). - Evidence collection: captures and writes the HTTP response to last_response.txt. Notable code notes: - There are commented-out sections suggesting an earlier/alternate approach involving a Node.js one-liner HTTP callback (require('http').get(...)) and a second chunked request intended to overflow a stack return pointer ("ROP_SIMULATION"), but these are not executed in the current version. - The active exploit is best characterized as an RCE command-injection attempt over HTTP with a reverse-shell payload, rather than a complete ROP exploit.
Repository contains a single Python proof-of-concept exploit (poc.py) plus README/license/gitignore. It targets CVE-2024-21762 (Fortinet FortiOS/FortiProxy SSL-VPN) and performs an unauthenticated network attack against the SSL-VPN web service. Key behavior in poc.py: - Establishes a raw TCP socket to TARGET on port 443 and sends handcrafted HTTP requests (no TLS handling in code; it assumes the service accepts the raw bytes as sent). - Stage 1: Sends a large form-encoded POST to /remote/hostcheck_validate. The form value embeds a ROP chain and multiple hardcoded gadget/function pointers (e.g., pivots, call_execl, ssl_do_handshake_ptr, getcwd_ptr). The ROP chain is designed to pivot the stack and invoke execl. - Payload: Uses execl to run /bin/node with -e and a JavaScript snippet that calls child_process.execSync("nslookup xxxxxxxxxxx.oastify.com"). This provides an out-of-band DNS signal indicating code execution. - Stage 2: After a short sleep, sends a second POST / request with Transfer-Encoding: chunked and a malformed chunk body ("0"*4137 + NUL + "A" + CRLFCRLF) intended to trigger the underlying out-of-bounds write in chunk parsing/handling described in the README. Overall purpose: a functional RCE PoC demonstrating exploitation flow (two-request sequence) and a basic verification payload (DNS callback). The exploit is not a scanner/detector; it attempts to achieve code execution. Hardcoded addresses/gadgets imply it is build/version dependent and may require adjustment for specific FortiOS/FortiProxy versions.
Repository contains a single Python tool (EXPLOIT.py) plus README and MIT LICENSE. The script implements both detection and attempted exploitation of CVE-2024-21762 (Fortinet FortiOS/FortiGate SSL-VPN sslvpnd out-of-bounds write) over the network via a raw TLS socket. Core behavior: (1) establishes a TLS connection to the target (default port 443, configurable) with certificate verification disabled; (2) sends a crafted HTTP POST to /remote/logincheck using 'Transfer-Encoding: chunked' with a malformed chunk intended to trigger the vulnerable parser; (3) determines likely vulnerability by observing abnormal server behavior (e.g., empty reply/abrupt close, timeouts, TLS alerts, connection reset). The tool also includes an exploitation path that embeds a bash reverse-shell command into the chunked body and supports an '--auto' mode that runs detection then exploitation if the target appears vulnerable, prompting for LHOST/LPORT if not provided. README documents affected FortiOS version ranges, usage flags, and listener commands (nc/ncat).
This repository provides a proof-of-concept (PoC) exploit and scanner for CVE-2024-21762, a critical vulnerability in Fortinet FortiOS SSL VPN's /remote/hostcheck_validate endpoint. The repository contains three main Python scripts: 1. poc_rce.py: The primary exploit script, which sends a crafted POST request to the vulnerable endpoint with a bash reverse shell payload injected into the 'host' parameter. It supports both single-target and batch modes, allowing for automated exploitation attempts against multiple FortiGate SSL VPN instances. The script saves the HTTP response from the target to 'last_response.txt' for analysis. 2. poc_check.py: A vulnerability checker that scans multiple IPs and ports to determine if they are likely vulnerable to CVE-2024-21762. It uses custom POST requests to the /remote/VULNCHECK endpoint and analyzes the responses to distinguish between vulnerable and patched systems. 3. http_c2_server.py: A simple HTTP-based command-and-control (C2) server that can be used to receive reverse shell connections or command output from exploited targets. It listens for incoming connections and can send commands to compromised systems. The exploit is operational, delivering a functional reverse shell payload if the target is vulnerable. The repository is well-structured, with clear separation between exploitation, detection, and C2 components. The README provides detailed usage instructions, requirements, and legal disclaimers. The main attack vector is network-based, targeting exposed FortiGate SSL VPN interfaces over HTTPS.
This repository contains a Python proof-of-concept exploit for CVE-2024-21762, a remote code execution vulnerability in Fortinet FortiGate firewalls. The main file, PoC.py, crafts and sends two custom HTTP POST requests to the target device, specifically targeting the /remote/hostcheck_validate endpoint. The exploit constructs a complex payload using a custom ROP chain and form values designed to trigger code execution on the target. The script uses raw sockets to connect to the target on port 80 and sends the malicious requests. The README.md provides context about the vulnerability, usage instructions, and a disclaimer. No hardcoded credentials or external network addresses are present, but the script requires the user to specify the target IP address. The exploit demonstrates remote code execution capabilities but does not include a weaponized or easily customizable payload beyond the provided ROP chain and placeholders.
This repository contains a working exploit for CVE-2024-21762, a critical out-of-bounds write vulnerability in Fortinet FortiOS (FortiGate) SSL VPN. The exploit is implemented in a single Python script (poc.py) and is accompanied by a detailed README.md that explains the vulnerability, exploitation process, and technical background. The exploit works by sending two specially crafted HTTP POST requests to the target FortiGate device's SSL VPN endpoints. The first request targets '/remote/hostcheck_validate' with a large, precisely constructed payload that leverages ROP chains and memory manipulation to achieve code execution. The second request abuses chunked transfer encoding to trigger the vulnerability. The payload executed on the target can be a system command (e.g., nslookup to an attacker-controlled domain for OOB verification) or a reverse shell using Node.js, demonstrating the exploit's flexibility. The repository is structured as follows: - README.md: Provides a comprehensive technical write-up, including vulnerability analysis, binary diffing, and exploitation details. - poc.py: The main exploit script, which is self-contained and requires the user to specify the target IP and (optionally) the attacker-controlled domain or reverse shell parameters. The exploit targets FortiOS versions prior to the patch for CVE-2024-21762 and requires the SSL VPN service to be accessible. The attack vector is network-based, and the exploit demonstrates both command execution and reverse shell capabilities. Several fingerprintable endpoints and example IPs/domains are present in the code and documentation.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
94 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A critical out-of-bounds write vulnerability in the FortiOS and FortiProxy SSL VPN component that permits unauthenticated remote code execution through specially crafted HTTP requests. The content states it continues to be abused in intrusions against exposed FortiGate systems.
A Fortinet FortiGate vulnerability exploited by the threat actor for remote code execution on 3BB's FortiGate SSL-VPN endpoint, providing initial access.
An unauthenticated remote code-execution vulnerability in Fortinet FortiGate SSL-VPN appliances. It was present in the attacker's toolkit and the 3BB FortiGate target was running affected firmware, but this report does not establish exploitation.
A critical (CVSS 9.8) unauthenticated remote code-execution vulnerability caused by an out-of-bounds write in FortiOS and FortiProxy SSL-VPN. The attackers reportedly used a heap-spray and ROP-chain exploit to gain a reverse shell on a targeted FortiGate 60F appliance.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.