ÆóÒµVPN cookie²»Çå¾²´æ´¢·½·¨Îó²îÇ徲ͨ¸æ
Ðû²¼Ê±¼ä 2019-04-15Îó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-1573£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
Palo Alto Networks GlobalProtect Agent 4.1.0µÄWindows °æ±¾ºÍ GlobalProtect Agent 4.1.10֮ǰµÄ macOS°æ±¾ (CVE-2019-1573)
Pulse Secure Connect Secure ÔçÓÚ8.1R14¡¢8.2¡¢8.3R6 ºÍ9.0R2 µÄ°æ±¾
Palo Alto Networks GlobalProtect Agent 4.1.0µÄWindows °æ±¾ºÍ GlobalProtect Agent 4.1.10֮ǰµÄ macOS °æ±¾ (CVE-2019-1573)
Pulse Secure Connect Secure ÔçÓÚ8.1R14¡¢8.2¡¢8.3R6 ºÍ9.0R2 µÄ°æ±¾
˼¿Æ AnyConnect 4.7.x ºÍ֮ǰ°æ±¾
Îó²î¸ÅÊö
¿¨ÄÚ»ù÷¡´óѧCERT/CCÖ¸³ö£¬£¬£¬£¬£¬ÖÁÉÙËÄ¿îÆóÒµVPN Ó¦ÓÃÖб£´æÇ徲ȱÏÝ£¬£¬£¬£¬£¬°üÀ¨Ë¼¿Æ¡¢F5 Networks¡¢Palo Alto Networks ºÍ Pulse Secure µÄ VPN Ó¦Óᣡ£¡£¡£¡£¡£¡£
ÕâËÄ¿îÓ¦ÓÃÒѱ»Ö¤ÊµÒԷǼÓÃÜÐÎʽ½«ÈÏÖ¤ºÍ»á»°cookie´æ´¢ÔÚÅÌËã»úÄÚ´æ»òÈÕÖ¾ÎļþÖС£¡£¡£¡£¡£¡£¡£¾ßÓÐÅÌËãʱ»ú¼ûȨÏ޵Ĺ¥»÷Õß»òÔÚÅÌËã»úÉÏÔËÐеĶñÒâÈí¼þÄܹ»¼ìË÷¸ÃÐÅÏ¢²¢ÓÃÓÚÁíÍâϵͳÖÐÒÔ»Ö¸´Êܺ¦ÕßµÄ VPN »á»°¶øÎÞÐèÈÏÖ¤¡£¡£¡£¡£¡£¡£¡£Õâ¾Íµ¼Ö¹¥»÷ÕßÖ±½ÓÇÒ²»ÊÜ×谵Ļá¼û¹«Ë¾µÄÄÚ²¿ÍøÂç¡¢ÄÚ²¿ÍøÃÅ»§»òÆäËüÃô¸ÐµÄÓ¦ÓóÌÐò¡£¡£¡£¡£¡£¡£¡£
Îó²îÑéÖ¤
ÔÝÎÞPOC/EXP¡£¡£¡£¡£¡£¡£¡£
ÐÞ¸´½¨Òé
Palo AltoNetworks ÒÑÐû²¼¸üнâ¾öÕâÁ½¸öÎÊÌ⣺
Palo Alto Networks GlobalProtect Agent 4.1.1µÄWindows °æ±¾ºÍ GlobalProtect Agent 4.1.11µÄ macOS0°æ±¾£ºhttps://securityadvisories.paloaltonetworks.com/Home/Detail/146?AspxAutoDetectCookieSupport=1¡£¡£¡£¡£¡£¡£¡£
F5 Networks ÌåÏÖÒÑÔÚ2013Äê×¢ÖØµ½½«ÈÏÖ¤/»á»° cookie ÒÔ²»Çå¾²µÄ·½·¨´æ´¢ÔÚ OSÄÚ´æÖеÄÇéÐΣ¬£¬£¬£¬£¬²»¹ý¾öÒé²»Ðû²¼²¹¶¡£¬£¬£¬£¬£¬¶øÊǽ¨ÒéÏûºÄÕßΪVPN ¿Í»§¶ËÆôÓÃÒ»´ÎÐÔÃÜÂë»òË«ÒòËØÈÏÖ¤»úÖÆ£»£»£»£»£»¶ø´æ´¢ÔÚÍâµØÈÕÖ¾ÎļþÖеÄÎÊÌâÒÑÓÚ2017ÄêÔÚ F5 Networks BIG-IP app Öнâ¾ö¡£¡£¡£¡£¡£¡£¡£
˼¿ÆºÍ Pulse Secure ÉÐδ¹ûÕæÈϿɸÃÕâЩÎÊÌâµÄ±£´æ¡£¡£¡£¡£¡£¡£¡£
²Î¿¼Á´½Ó