Pulse Connect SecureÈÎÒâ´úÂëÖ´ÐЩ¶´£¨CVE-2021-22908£©

Ðû²¼Ê±¼ä 2021-05-25

0x00 ©¶´¸ÅÊö

CVE  ID

CVE-2021-22908

ʱ   ¼ä

2021-05-25

Àà   ÐÍ

´úÂëÖ´ÐÐ

µÈ   ¼¶

¸ßΣ

Ô¶³ÌÀûÓÃ

ÊÇ

Ó°Ï췶Χ

9.0RX¡¢9.1RX

PoC/EXP

δ¹ûÈ»

ÔÚÒ°ÀûÓÃ

·ñ

 

0x01 ©¶´ÏêÇé

image.png

 

Pulse Connect Secure£¨PCS£©ÊÇÃÀ¹úPulse Secure¹«Ë¾µÄÒ»Ì×SSL VPN½â¾ö·½°¸¡£

2021Äê05ÔÂ24ÈÕ £¬¿¨ÄÚ»ù÷¡´óѧÅû¶ÁËPulse Connect SecureÖеÄÒ»¸ö»º³åÇøÒç³ö©¶´£¨CVE-2021-22908£© £¬¸Ã©¶´µÄCVSSÆÀ·ÖΪ8.5¡£¾­¹ýÉí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓôË©¶´ÔÚÊÜÓ°ÏìµÄPCS·þÎñÆ÷ÉÏÒÔrootȨÏÞÖ´ÐÐÈÎÒâ´úÂë¡£

 

©¶´Ï¸½Ú

ÓÉÓÚPCSÖ§³ÖÁ¬½Óµ½WindowsÎļþ¹²Ïí£¨SMB£©µÄ¹¦Ð§ÓÉ»ùÓÚSamba 4.5.10µÄ¿âºÍ¸¨ÖúÓ¦Ó÷¨Ê½µÄCGI½Å±¾Ìṩ¡£µ±ÎªÄ³Ð©SMB²Ù×÷Ö¸¶¨Ò»¸ö³¤µÄ·þÎñÆ÷Ãû³ÆÊ± £¬smbcltÓ¦Ó÷¨Ê½¿ÉÄÜ»áÓÉÓÚ»º³åÇøÒç³ö¶øÍ߽⠣¬¾ßÌåÈ¡¾öÓÚÖ¸¶¨µÄ·þÎñÆ÷Ãû³Æ³¤¶È¡£

ÒѾ­È·ÈÏPCS 9.1R11.4ϵͳ´æÔÚ´Ë©¶´ £¬Ä¿±êCGI¶ËµãΪ/dana/fb/smb/wnf.cgi £¬ÆäËüCGI¶ËµãÒ²¿ÉÄܻᴥ·¢´Ë©¶´¡£

Èç¹û¹¥»÷ÕßÔÚÀÖ³ÉÀûÓôË©¶´ºóûÓнøÐÐÇåÀí £¬ÔòÖ¸¶¨Ò»¸ö³¤µÄ·þÎñÆ÷Ãû³Æ¿ÉÄܻᵼÖÂÈçÏÂPCSʼþÈÕÖ¾ÌõÄ¿£º

Critical ERR31093 2021-05-24 14:05:37 - ive - [127.0.0.1] Root::System()[] - Program smbclt recently failed.

 

µ«ÒªÀûÓôË©¶´ £¬PCS·þÎñÆ÷±ØÐëÓÐÒ»¸öallows \\*µÄWindowsÎļþ·ÃÎʼÆÄ±»òÔÊÐí¹¥»÷ÕßÁ¬½Óµ½ÈÎÒâ·þÎñÆ÷µÄÆäËüµÄ¼ÆÄ±¡£¿ÉÒÔÔÚPCSµÄ¹ÜÀíÒ³ÃæÖÐ £¬¼ì²ìÓû§->×ÊÔ´¼ÆÄ±->WindowsÎļþ·ÃÎʼÆÄ± £¬À´¼ì²ìµ±Ç°µÄSMB¼ÆÄ±¡£9.1R2¼°Ö®Ç°µÄPCSÉ豸ʹÓÃÔÊÐíÁ¬½Óµ½ÈÎÒâSMBÖ÷»úµÄĬÈϼÆÄ± £¬´Ó9.1R3¿ªÊ¼ £¬Õâ¸ö¼ÆÄ±´ÓĬÈÏÔÊÐí¸ü¸ÄΪĬÈϾܾø¡£

 

Ó°Ï췶Χ

Pulse Connect Secure 9.0RXºÍ9.1RX

 

0x02 ´¦Öý¨Òé

Pulse SecureÔ¤¼ÆÔÚPulse Connect Secure 9.1R11.5»ò¸ü¸ß°æ±¾ÖÐÐÞ¸´¸Ã©¶´ £¬µ«Ä¿Ç°ÉÐδÐû²¼¡£

ÏÂÔØÁ´½Ó£º

https://my.pulsesecure.net/

 

0x03 ²Î¿¼Á´½Ó

https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44800

https://kb.cert.org/vuls/id/667933

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-22908

 

0x04 ʱ¼äÏß

2021-05-24 ¿¨ÄÚ»ù÷¡´óѧÅû¶©¶´

2021-05-25  VSRCÐû²¼Äþ¾²Í¨¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/

image.png