¡¾Â©¶´Í¨¸æ¡¿Juniper Networks Junos OSÔ¶³Ì´úÂëÖ´ÐЩ¶´

Ðû²¼Ê±¼ä 2023-08-29

 

Ò»¡¢Â©¶´¸ÅÊö

CVE   ID


·¢ÏÖʱ¼ä

2023-08-26

Àà    ÐÍ

´úÂëÖ´ÐÐ

µÈ    ¼¶

¸ßΣ

¹¥»÷ÏòÁ¿

ÍøÂç

ËùÐèȨÏÞ

ÎÞ

¹¥»÷ÅÓ´ó¶È

µÍ

Óû§½»»¥

ÎÞ

PoC/EXP

ÒѹûÈ»

ÔÚÒ°ÀûÓÃ

δ֪

 

Juniper Networks£¨Õ°²©ÍøÂ磩ÊÇÈ«ÇòÁìÏȵÄÍøÂçºÍÄþ¾²½â¾ö·½°¸ÌṩÉÌ£¬Æä¿Í»§°üÂÞÈ«Çò·¶Î§ÄÚµÄÍøÂçÔËÓªÉÌ¡¢ÆóÒµ¡¢Õþ¸®»ú¹¹ÒÔ¼°Ñо¿ºÍ½ÌÓý»ú¹¹µÈ¡£

8ÔÂ29ÈÕ£¬¶¶È¦Îª¶Ä¶øÉúVSRC¼à²âµ½Juniper NetworksÅû¶ÁËÆäSRX ·À»ðǽϵÁÐºÍ EX ½»»»»úϵÁÐÉϵÄJunos OS µÄ J-Web ×é¼þÖеĶà¸ö©¶´£¬Î´¾­Éí·ÝÑéÖ¤µÄÍþвÕß¿É×éºÏÀûÓÃÕâЩ©ÔÚÊÜÓ°ÏìÉ豸ÉÏÔ¶³ÌÖ´ÐдúÂë¡£

CVE-2023-36844£ºJunos OS J-Web PHPÍⲿ±äÁ¿Ð޸ĩ¶´£¨ÖÐΣ£©

Juniper Networks EXϵÁÐÉϵÄJunos OS µÄ J-Web×é¼þÖдæÔÚPHPÍⲿ±äÁ¿Ð޸ĩ¶´£¬Î´¾­Éí·ÝÑéÖ¤µÄÔ¶³ÌÍþвÕß¿ÉÀûÓöñÒâÇëÇóÐÞ¸ÄijЩ PHP »·¾³±äÁ¿£¬µ¼Ö²¿ÃÅÍêÕûÐÔ¶ªÊ§»ò¿ÉÄܵ¼Ö©¶´ÀûÓÃÁ´¡£

CVE-2023-36845£ºJunos OS J-Web PHPÍⲿ±äÁ¿Ð޸ĩ¶´£¨ÖÐΣ£©

Juniper Networks EX ϵÁÐºÍ SRX ϵÁÐÉϵÄJunos OS µÄ J-Web×é¼þÖдæÔÚPHPÍⲿ±äÁ¿Ð޸ĩ¶´£¬Î´¾­Éí·ÝÑéÖ¤µÄÔ¶³ÌÍþвÕß¿ÉÀûÓöñÒâÇëÇóÐÞ¸Äij¸ö PHP »·¾³±äÁ¿£¬µ¼Ö²¿ÃÅÍêÕûÐÔ¶ªÊ§»ò¿ÉÄܵ¼Ö©¶´ÀûÓÃÁ´¡£

CVE-2023-36846£ºJunos OS SRX ϵÁÐÒªº¦¹¦Ð§Ñé֤ȱʧ©¶´£¨ÖÐΣ£©

Juniper Networks SRX ϵÁÐÉϵÄJunos OSÖдæÔÚÒªº¦¹¦Ð§Ñé֤ȱʧ©¶´£¬Î´¾­Éí·ÝÑéÖ¤µÄÔ¶³ÌÍþвÕ߿ɷ¢ËÍÌØ¶¨ÇëÇóͨ¹ý J-Web ÉÏ´«ÈÎÒâÎļþ£¬´Ó¶øµ¼ÖÂÎļþÏµÍ³ÌØ¶¨²¿ÃŵÄÍêÕûÐÔ¶ªÊ§»ò¿ÉÄܵ¼Ö©¶´ÀûÓÃÁ´¡£

CVE-2023-36847£ºJunos OS EX ϵÁÐÒªº¦¹¦Ð§Ñé֤ȱʧ©¶´£¨ÖÐΣ£©

Juniper Networks EX ϵÁÐÉϵÄJunos OSÖдæÔÚÒªº¦¹¦Ð§Ñé֤ȱʧ©¶´£¬Î´¾­Éí·ÝÑéÖ¤µÄÔ¶³ÌÍþвÕ߿ɷ¢ËÍÌØ¶¨ÇëÇóͨ¹ý J-Web ÉÏ´«ÈÎÒâÎļþ£¬´Ó¶øµ¼ÖÂÎļþÏµÍ³ÌØ¶¨²¿ÃŵÄÍêÕûÐÔ¶ªÊ§»ò¿ÉÄܵ¼Ö©¶´ÀûÓÃÁ´¡£

Ŀǰ£¬Ñо¿ÈËÔ±ÒѾ­Ðû²¼ÁËÕë¶ÔSRX·À»ðǽ©¶´µÄPoC/EXP£¬Í¨¹ý×éºÏÀûÓÃÒªº¦¹¦Ð§Ñé֤ȱʧ©¶´£¨CVE-2023-36846£©ºÍPHPÍⲿ±äÁ¿Ð޸ĩ¶´£¨CVE-2023-36845£©¡£CVE-2023-36846©¶´¿ÉÔÚδÊÚȨÇé¿öÏÂÉÏ´«PHPÎļþºÍÅäÖÃÎļþ£¬ÔÙÀûÓÃCVE-2023-36845©¶´Ð޸Ļ·¾³±äÁ¿¼ÓÔØÅäÖÃÎļþ£¬´Ó¶ø´¥·¢Ö´ÐÐPHPÎļþ¡£

 

¶þ¡¢Ó°Ï췶Χ

Juniper Networks Junos OS£¨SRX ϵÁУ©£º

20.4R3-S8֮ǰµÄËùÓа汾£»

21.1°æ±¾21.1R1¼°ÒÔÉϰ汾£»

21.2R3-S6֮ǰµÄ21.2°æ±¾£»

21.3R3-S5֮ǰµÄ21.3°æ±¾£»

21.4R3-S5֮ǰµÄ21.4°æ±¾£»

22.1R3-S3֮ǰµÄ22.1°æ±¾£»

22.2R3-S2֮ǰµÄ22.2°æ±¾£»

22.3R2-S2¡¢22.3R3֮ǰµÄ22.3°æ±¾£»

22.4R2-S1¡¢22.4R3֮ǰµÄ22.4°æ±¾£»

Juniper Networks Junos OS£¨EX ϵÁУ©£º

20.4R3-S8֮ǰµÄËùÓа汾£»

21.1°æ±¾21.1R1¼°ÒÔÉϰ汾£»

21.2R3-S6֮ǰµÄ21.2°æ±¾£»

21.3R3-S5֮ǰµÄ21.3°æ±¾£»

21.4R3-S4֮ǰµÄ21.4°æ±¾£»

22.1R3-S3֮ǰµÄ22.1°æ±¾£»

22.2R3-S1֮ǰµÄ22.2°æ±¾£»

22.3R2-S2¡¢22.3R3֮ǰµÄ22.3°æ±¾£»

22.4R2-S1¡¢22.4R3 ֮ǰµÄ 22.4 °æ±¾¡£


Èý¡¢Äþ¾²´ëÊ©

3.1 Éý¼¶°æ±¾

ĿǰJuniper NetworksÒѾ­ÐÞ¸´ÁËÕâЩ©¶´£¬ÊÜÓ°ÏìÓû§¿ÉÔÚ°æ±¾¸üпÉÓÃʱÉý¼¶µ½ÒÔÏÂJunos OS°æ±¾£º

¶ÔÓÚ EX ϵÁУº¿ÉÉý¼¶µ½20.4R3-S8¡¢21.2R3-S6¡¢21.3R3-S5*¡¢21.4R3-S4¡¢22.1R3-S3¡¢22.2R3-S1¡¢22.3R2-S2¡¢22.3R3¡¢22.4R2-S1¡¢22.4R3*¡¢23.2R1 ºÍËùÓкóÐøÐû²¼µÄ¸üа汾¡£

¶ÔÓÚ SRX ϵÁУº¿ÉÉý¼¶µ½ 20.4R3-S8¡¢21.2R3-S6¡¢21.3R3-S5*¡¢21.4R3-S5*¡¢22.1R3-S3¡¢22.2R3-S2*¡¢22.3R2-S2¡¢22.3R3¡¢22.4R2-S1¡¢22.4R3*¡¢23.2R1ºÍËùÓкóÐøÐû²¼µÄ¸üа汾¡£

ÏÂÔØÁ´½Ó£º

https://supportportal.juniper.net

3.2 ÁÙʱ´ëÊ©

½ûÓÃÊÜÓ°ÏìÉè±¹ØÁ¬ÄJ-Web£¬»òÏÞÖÆ½öÔÊÐíÊÜÐÅÈεÄÖ÷»ú½øÐзÃÎÊ¡£

3.3 ͨÓý¨Òé

l  ¶¨ÆÚ¸üÐÂϵͳ²¹¶¡£¬¼õÉÙϵͳ©¶´£¬ÌáÉý·þÎñÆ÷µÄÄþ¾²ÐÔ¡£

l  ¼ÓǿϵͳºÍÍøÂçµÄ·ÃÎÊ¿ØÖÆ£¬Ð޸ķÀ»ðǽ¼ÆÄ±£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻò·þÎñ£¬¼õÉÙ½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬¼õÉÙ¹¥»÷Ãæ¡£

l  ʹÓÃÆóÒµ¼¶Äþ¾²²úÎÌáÉýÆóÒµµÄÍøÂçÄþ¾²ÐÔÄÜ¡£

l  ¼ÓǿϵͳÓû§ºÍȨÏÞ¹ÜÀí£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔ­Ôò£¬Óû§ºÍÈí¼þȨÏÞÓ¦±£³ÖÔÚ×îµÍÏÞ¶È¡£

l  ÆôÓÃÇ¿ÃÜÂë¼ÆÄ±²¢ÉèÖÃΪ¶¨ÆÚÐ޸ġ£

3.4 ²Î¿¼Á´½Ó

https://supportportal.juniper.net/s/article/2023-08-Out-of-Cycle-Security-Bulletin-Junos-OS-SRX-Series-and-EX-Series-Multiple-vulnerabilities-in-J-Web-can-be-combined-to-allow-a-preAuth-Remote-Code-Execution

https://labs.watchtowr.com/cve-2023-36844-and-friends-rce-in-juniper-firewalls/

https://www.bleepingcomputer.com/news/security/exploit-released-for-juniper-firewall-bugs-allowing-rce-attacks/

  

ËÄ¡¢°æ±¾ÐÅÏ¢

°æ±¾

ÈÕÆÚ

±¸×¢

V1.0

2023-08-29

Ê×´ÎÐû²¼

 

Îå¡¢¸½Â¼

5.1 ¶¶È¦Îª¶Ä¶øÉú¼ò½é

¶¶È¦Îª¶Ä¶øÉú½¨Á¢ÓÚ1996Ä꣬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ´´½¨µÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢Äþ¾²¸ß¿Æ¼¼ÆóÒµ¡£ÊǹúÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Äþ¾²²úÎï¡¢Äþ¾²·þÎñ½â¾ö·½°¸µÄÁ캽ÆóÒµÖ®Ò»¡£

¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°¶¶È¦Îª¶Ä¶øÉú´óÏ㬹«Ë¾Ô±¹¤6000ÓàÈË£¬Ñз¢ÍŶÓ1200ÓàÈË, ¼¼Êõ·þÎñÍŶÓ1300ÓàÈË¡£ÔÚÈ«¹ú¸÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬ÓµÓÐÁýÕÖÈ«¹úµÄÏúÊÛÌåϵ¡¢ÇþµÀÌåϵºÍ¼¼ÊõÖ§³ÖÌåϵ¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐС°å¹ÒÅÆÉÏÊС££¨¹ÉƱ´úÂ룺002439£©

¶àÄêÀ´£¬¶¶È¦Îª¶Ä¶øÉúÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷´´ÐµÄÄþ¾²²úÎïºÍ×î¼Ñʵ¼ù·þÎñ£¬×ÊÖú¿Í»§È«ÃæÌáÉýÆäIT»ù´¡ÉèÊ©µÄÄþ¾²ÐÔºÍÉú²úЧÄÜ£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Äþ¾²¹¤ÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸Å¬Á¦¡£

5.2 ¹ØÓÚ¶¶È¦Îª¶Ä¶øÉú

¶¶È¦Îª¶Ä¶øÉúÄþ¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÒÑÐû²¼1000¶à¸ö©¶´Í¨¸æºÍ·çÏÕÔ¤¾¯£¬ÎÒÃǽ«Á¬Ðø¸ú×ÙÈ«Çò×îеÄÍøÂçÄþ¾²Ê¼þºÍ©¶´£¬ÎªÆóÒµµÄÐÅÏ¢Äþ¾²±£¼Ý»¤º½¡£

¹Ø×¢ÎÒÃÇ£º

image.png