SolarWinds NPMÔ¶³Ì´úÂëÖ´ÐЩ¶´£¨CVE-2021-31474£©

Ðû²¼Ê±¼ä 2021-05-26

0x00 ©¶´¸ÅÊö

CVE  ID

CVE-2021-31474

ʱ    ¼ä

2021-05-26

Àà   ÐÍ

RCE

µÈ    ¼¶

ÑÏÖØ

Ô¶³ÌÀûÓÃ

ÊÇ

Ó°Ï췶Χ

2020.2.1

PoC/EXP

δ¹ûÈ»

ÔÚÒ°ÀûÓÃ

·ñ

 

0x01 ©¶´ÏêÇé

image.png

 

SolarWinds Network Performance Monitor£¨NPM£©ÊǼ¯ÍøÂç¼à²â¡¢É豸ÐÔÄÜά»¤¹ÜÀí¡¢¹ÊÕÏ¼à¿Ø¡¢ÍøÂçʵʱÁ÷Á¿¼à¿ØºÍÀúÊ·Êý¾Ýͳ¼Æ¡¢»ã×ܺÍÀúÊ·Êý¾Ý·ÖÎöµÈ¹¦Ð§ÓÚÒ»ÌåµÄÍøÂç¹ÜÀíϵͳ¡£

2021Äê05ÔÂ20ÈÕ£¬Zero Day Initiative¹ûÈ»Åû¶ÁËSolarWinds Network Performance MonitorÖеÄÒ»¸öÔ¶³Ì´úÂëÖ´ÐЩ¶´£¨CVE-2021-31474£©£¬ÆäCVSSÆÀ·ÖΪ9.8¡£

¸Ã©¶´´æÔÚÓÚSolarWinds.Serialization¿âÖУ¬ÓÉÓÚ¶ÔÓû§ÌṩµÄÊý¾Ýȱ·¦ÕýÈ·ÑéÖ¤£¬µ¼Ö²»ÐÅÈÎÊý¾ÝµÄ·´ÐòÁл¯¡£ÀÖ³ÉÀûÓôË©¶´µÄ¹¥»÷Õß¿ÉÒÔÔÚϵͳÉÏÏÂÎÄÖÐÖ´ÐÐÈÎÒâ´úÂ룬¶øÎÞÐè¾­¹ýÉí·ÝÑéÖ¤¡£

 

Ó°Ï췶Χ

SolarWinds Network Performance Monitor 2020.2.1

 

0x02 ´¦Öý¨Òé

ĿǰSolarWindsÒѾ­ÐÞ¸´Á˸é¶´£¬½¨Ò龡¿ì½øÐÐÉý¼¶¸üС£

ÏÂÔØÁ´½Ó£º

https://documentation.solarwinds.com/en/success_center/sam/content/release_notes/sam_2020-2-5_release_notes.htm

 

0x03 ²Î¿¼Á´½Ó

https://www.zerodayinitiative.com/advisories/ZDI-21-602/

https://nvd.nist.gov/vuln/detail/CVE-2021-31474

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-31474

 

0x04 ʱ¼äÏß

2021-05-20  ZDI¹ûÈ»Åû¶©¶´

2021-05-26  VSRCÐû²¼Äþ¾²Í¨¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/

image.png