Pulse Connect SecureÈÎÒâ´úÂëÖ´ÐЩ¶´£¨CVE-2021-22908£©
Ðû²¼Ê±¼ä 2021-05-250x00 ©¶´¸ÅÊö
CVE ID | CVE-2021-22908 | ʱ ¼ä | 2021-05-25 |
Àà ÐÍ | ´úÂëÖ´ÐÐ | µÈ ¼¶ | ¸ßΣ |
Ô¶³ÌÀûÓà | ÊÇ | Ó°Ï췶Χ | 9.0RX¡¢9.1RX |
PoC/EXP | δ¹ûÈ» | ÔÚÒ°ÀûÓà | ·ñ |
0x01 ©¶´ÏêÇé
Pulse Connect Secure£¨PCS£©ÊÇÃÀ¹úPulse Secure¹«Ë¾µÄÒ»Ì×SSL VPN½â¾ö·½°¸¡£
2021Äê05ÔÂ24ÈÕ£¬¿¨ÄÚ»ù÷¡´óѧÅû¶ÁËPulse Connect SecureÖеÄÒ»¸ö»º³åÇøÒç³ö©¶´£¨CVE-2021-22908£©£¬¸Ã©¶´µÄCVSSÆÀ·ÖΪ8.5¡£¾¹ýÉí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓôË©¶´ÔÚÊÜÓ°ÏìµÄPCS·þÎñÆ÷ÉÏÒÔrootȨÏÞÖ´ÐÐÈÎÒâ´úÂë¡£
©¶´Ï¸½Ú
ÓÉÓÚPCSÖ§³ÖÁ¬½Óµ½WindowsÎļþ¹²Ïí£¨SMB£©µÄ¹¦Ð§ÓÉ»ùÓÚSamba 4.5.10µÄ¿âºÍ¸¨ÖúÓ¦Ó÷¨Ê½µÄCGI½Å±¾Ìṩ¡£µ±ÎªÄ³Ð©SMB²Ù×÷Ö¸¶¨Ò»¸ö³¤µÄ·þÎñÆ÷Ãû³ÆÊ±£¬smbcltÓ¦Ó÷¨Ê½¿ÉÄÜ»áÓÉÓÚ»º³åÇøÒç³ö¶øÍ߽⣬¾ßÌåÈ¡¾öÓÚÖ¸¶¨µÄ·þÎñÆ÷Ãû³Æ³¤¶È¡£
ÒѾȷÈÏPCS 9.1R11.4ϵͳ´æÔÚ´Ë©¶´£¬Ä¿±êCGI¶ËµãΪ/dana/fb/smb/wnf.cgi£¬ÆäËüCGI¶ËµãÒ²¿ÉÄܻᴥ·¢´Ë©¶´¡£
Èç¹û¹¥»÷ÕßÔÚÀÖ³ÉÀûÓôË©¶´ºóûÓнøÐÐÇåÀí£¬ÔòÖ¸¶¨Ò»¸ö³¤µÄ·þÎñÆ÷Ãû³Æ¿ÉÄܻᵼÖÂÈçÏÂPCSʼþÈÕÖ¾ÌõÄ¿£º
Critical ERR31093 2021-05-24 14:05:37 - ive - [127.0.0.1] Root::System()[] - Program smbclt recently failed.
µ«ÒªÀûÓôË©¶´£¬PCS·þÎñÆ÷±ØÐëÓÐÒ»¸öallows \\*µÄWindowsÎļþ·ÃÎʼÆÄ±»òÔÊÐí¹¥»÷ÕßÁ¬½Óµ½ÈÎÒâ·þÎñÆ÷µÄÆäËüµÄ¼ÆÄ±¡£¿ÉÒÔÔÚPCSµÄ¹ÜÀíÒ³ÃæÖУ¬¼ì²ìÓû§->×ÊÔ´¼ÆÄ±->WindowsÎļþ·ÃÎʼÆÄ±£¬À´¼ì²ìµ±Ç°µÄSMB¼ÆÄ±¡£9.1R2¼°Ö®Ç°µÄPCSÉ豸ʹÓÃÔÊÐíÁ¬½Óµ½ÈÎÒâSMBÖ÷»úµÄĬÈϼÆÄ±£¬´Ó9.1R3¿ªÊ¼£¬Õâ¸ö¼ÆÄ±´ÓĬÈÏÔÊÐí¸ü¸ÄΪĬÈϾܾø¡£
Ó°Ï췶Χ
Pulse Connect Secure 9.0RXºÍ9.1RX
0x02 ´¦Öý¨Òé
Pulse SecureÔ¤¼ÆÔÚPulse Connect Secure 9.1R11.5»ò¸ü¸ß°æ±¾ÖÐÐÞ¸´¸Ã©¶´£¬µ«Ä¿Ç°ÉÐδÐû²¼¡£
ÏÂÔØÁ´½Ó£º
https://my.pulsesecure.net/
0x03 ²Î¿¼Á´½Ó
https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44800
https://kb.cert.org/vuls/id/667933
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-22908
0x04 ʱ¼äÏß
2021-05-24 ¿¨ÄÚ»ù÷¡´óѧÅû¶©¶´
2021-05-25 VSRCÐû²¼Äþ¾²Í¨¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/