Pulse Connect SecureÔ¶³Ì´úÂëÖ´ÐЩ¶´£¨CVE-2021-22893£©

Ðû²¼Ê±¼ä 2021-04-21

0x00 ©¶´¸ÅÊö

CVE  ID

CVE-2021-22893

ʱ   ¼ä

2021-04-21

Àà   ÐÍ

RCE

µÈ   ¼¶

ÑÏÖØ

Ô¶³ÌÀûÓÃ

ÊÇ

Ó°Ï췶Χ

 9.0R3<= PCS <9.1R.11.4

PoC/EXP


ÔÚÒ°ÀûÓÃ

ÊÇ

 

0x01 ©¶´ÏêÇé

image.png

 

2021Äê04ÔÂ20ÈÕ£¬PulseSecureÐû²¼Äþ¾²Í¨¸æ£¬¹ûÈ»ÁËPulse Connect Secure£¨PCS£©ÖеÄÒ»¸öÉí·ÝÑéÖ¤ÈÆ¹ý©¶´£¨CVE-2021-22893£©£¬¸Ã©¶´µÄCVSSv3»ù±¾µÃ·ÖΪ10.0·Ö¡£Ô¶³Ì¹¥»÷¿ÉÒÔͨ¹ýÀûÓôË©¶´ÔÚPulse Connect SecureÍø¹ØÉÏÖ´ÐÐÈÎÒâ´úÂ룬ÇҸé¶´ÎÞÐè¾­¹ýÉí·ÝÑéÖ¤¼´¿ÉÀûÓá£

Ŀǰ¸Ã©¶´ÔÚÕë¶ÔÈ«Çò×éÖ¯µÄ¹¥»÷ÖÐÒѱ»»ý¼«ÀûÓ㬹¥»÷Õßͨ¹ý½«WebShell·ÅÖÃÔÚPulse Connect SecureÉ豸ÉÏ£¬ÒÔʵÏÖ½øÒ»²½µÄ·ÃÎʺͳ־ÃÐÔ¡£ÒÑÖªµÄWebshell¾ßÓаüÂÞÉí·ÝÑéÖ¤ÈÆ¹ý¡¢¶àÒòËØÉí·ÝÑéÖ¤ÈÆ¹ý¡¢ÃÜÂë¼Ç¼ºÍ³Ö¾ÃÐԵȶàÖÖ¹¦Ð§¡£

 

0x02 ´¦Öý¨Òé

ĿǰPulseSecureÔÚPCS 9.1R.11.4°æ±¾ÖÐÐÞ¸´ÁË´Ë©¶´£¬¸Ã©¶´µÄÄþ¾²¸üÐÂÔ¤¼Æ½«ÓÚ5Ô³õÐû²¼£¬½¨Ò鼰ʱÉý¼¶ÖÁ×îа汾¡£´ËÍ⣬Pulse Secure»¹Ðû²¼ÁËPulse ConnectÄþ¾²ÍêÕûÐÔ¹¤¾ß£¬ÒÔ×ÊÖú¿Í»§È·¶¨ÆäϵͳÊÇ·ñÊܵ½Ó°Ïì¡£

»º½â´ëÊ©

ͨ¹ýµ¼ÈëWorkaround-2104.xmlÎļþ¿ÉÒÔ»º½âCVE-2021-22893£¬µ«¸ÃÎļþ»á½ûÓÃWindows File Share BrowserºÍPulse Secure Collaboration¹¦Ð§¡£

 

ÏÂÔØÁ´½Ó£º

https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44784

 

0x03 ²Î¿¼Á´½Ó

https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44784

https://kb.pulsesecure.net/articles/Pulse_Secure_Article/KB44755

https://us-cert.cisa.gov/ncas/alerts/aa21-110a

https://www.bleepingcomputer.com/news/security/pulse-secure-vpn-zero-day-used-to-hack-defense-firms-govt-orgs/

 

0x04 ʱ¼äÏß

2021-04-20  PluseSecureÐû²¼Äþ¾²Í¨¸æ

2021-04-21  VSRCÐû²¼Äþ¾²Í¨¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/

image.png