Citrix²úÆ·¶à¸öÇå¾²Îó²îͨ¸æ
Ðû²¼Ê±¼ä 2020-07-090x00 Îó²î¸ÅÊö
2020Äê7ÔÂ7ÈÕ£¬£¬£¬£¬Citrix¹Ù·½Ðû²¼Ç徲ͨ¸æ£¬£¬£¬£¬ÔÚCitrix ADC¡¢CitrixÍø¹ØºÍCitrix SD-WAN WANOP 4000-WO¡¢4100-WO¡¢5000-WOºÍ5100-WO°æ±¾Öз¢Ã÷Á˶à¸öÎó²î¡£¡£¡£¡£¡£ÏêÇé¼ûÏÂ±í£º
CVE ID |
Îó²îÀàÐÍ |
Ó°Ïì²úÆ· |
¹¥»÷ÕßȨÏÞ |
Ìõ¼þÌõ¼þ |
CVE-2019-18177 |
ID |
Citrix ADC, Citrix Gateway |
¾Éí·ÝÈÏÖ¤µÄVPNÓû§ |
ÐèÒªÒ»¸öÉèÖõÄSSL VPNÖÕ¶Ë |
CVE-2020-8187 |
DOS |
Citrix ADC, Citrix Gateway 12.0 and 11.1°æ±¾ |
δ¾Éí·ÝÈÏÖ¤µÄÔ¶³ÌÓû§ |
ÐèÒªÒ»¸öÉèÖõÄSSL VPN»òAAAÖÕ¶Ë |
CVE-2020-8190 |
EOP |
Citrix ADC, Citrix Gateway |
λÓÚNSIPÉϾÉí·ÝÈÏÖ¤µÄÓû§ |
¸ÃÎó²îÎÞ·¨Ö±½Ó±»Ê¹Óᣡ£¡£¡£¡£¹¥»÷Õß±ØÐèÊ×ÏÈʹÓÃÁíÒ»¸öÎó²î»ñÈ¡nobodyÕË»§È¨ÏÞ |
CVE-2020-8191 |
XSS |
Citrix ADC, Citrix Gateway, Citrix SDWAN WAN-OP |
δ¾Éí·ÝÈÏÖ¤µÄÔ¶³ÌÓû§ |
ÐèÒªÊܺ¦ÕßÔÚä¯ÀÀÆ÷Öз¿ªÓɹ¥»÷Õß¿ØÖƵÄÁ´½Ó£¬£¬£¬£¬Í¬Ê±´¦ÓÚÅþÁ¬NSIPµÄÍøÂçÉÏ |
CVE-2020-8193 |
AB |
Citrix ADC, Citrix Gateway, Citrix SDWAN WAN-OP |
¾ßÓÐNSIP»á¼ûȨÏ޵쬣¬£¬£¬Î´¾Éí·ÝÈÏÖ¤µÄÓû§ |
¹¥»÷Õß±ØÐèÄܹ»»á¼û¸ÃNSIP |
CVE-2020-8194 |
CI |
Citrix ADC, Citrix Gateway, Citrix SDWAN WAN-OP |
δ¾Éí·ÝÈÏÖ¤µÄÔ¶³ÌÓû§ |
ÐèÒªÊܺ¦Õß´Ó¸ÃNSIPÏÂÔØ²¢Ö´ÐжñÒâ¶þ½øÖÆÎļþ |
CVE-2020-8195 |
ID |
Citrix ADC, Citrix Gateway, Citrix SDWAN WAN-OP |
λÓÚNSIPÉϾÉí·ÝÈÏÖ¤µÄÓû§ |
|
CVE-2020-8196 |
ID |
Citrix ADC, Citrix Gateway, Citrix SDWAN WAN-OP |
λÓÚNSIPÉϾÉí·ÝÈÏÖ¤µÄÓû§ |
|
CVE-2020-8197 |
EOP |
Citrix ADC, Citrix Gateway |
λÓÚNSIPÉϾÉí·ÝÈÏÖ¤µÄÓû§ |
|
CVE-2020-8198 |
XSS |
Citrix ADC, Citrix Gateway,Citrix SDWAN WAN-OP |
δ¾Éí·ÝÈÏÖ¤µÄÔ¶³Ì¹¥»÷Õß |
ÐèÒªÊܺ¦Õß±ØÐèÔÚNSIPÉÏÒÔÖÎÀíÔ±£¨nsroot£©Éí·ÝµÇ¼ |
CVE-2020-8199 |
EOP |
Citrix Gateway Plug-in for Linux |
λÓÚLinuxÅÌËã»úÉÏÔËÐÐCitrix Gateway Plug-inµÄÍâµØÓû§ |
±ØÐèÔËÐÐCitrix Gateway Plug-in for LinuxԤװ°æ±¾ |
´Ó±íÖпÉÒÔ¿´³ö£¬£¬£¬£¬¹¥»÷»¹ÐèҪijÖÖÐÎʽµÄ»á¼ûȨÏ޲ŻªÊ¹ÓÃÕâЩÎó²î£¬£¬£¬£¬ÕâÒâζ׏¥»÷ÕßÊ×ÏÈÐèÒª»á¼ûÄ¿µÄϵͳ²Å»ª¾ÙÐй¥»÷¡£¡£¡£¡£¡£
0x01 Îó²îÏêÇé
Citrix²úÆ·Ö÷ÒªÓÃÓÚÓ¦ÓóÌÐòµÄÁ÷Á¿ÖÎÀíºÍʵÏÖÇå¾²µÄÔ¶³Ì»á¼û£¬£¬£¬£¬²¢ÖÁÉÙÒÑÔÚ158¸ö¹ú¼ÒµÄ80000¼Ò¹«Ë¾ÖÐ×°Öᣡ£¡£¡£¡£
ÈôÊÇÕâЩÎó²îÔ⵽ʹÓ㬣¬£¬£¬¿ÉÄܻᵼÖÂÐí¶àÇå¾²ÎÊÌ⣬£¬£¬£¬°üÀ¨±»ÓÃÓÚ»ñÊØÐÅÏ¢¡¢·¢¶¯ DoS ¹¥»÷¡¢ÊµÏÖÍâµØÌáȨ¡¢·¢¶¯ XSS ¹¥»÷ºÍÈÆ¹ýÈÏÖ¤²¢×¢Èë¶ñÒâ´úÂë¡£¡£¡£¡£¡£
±ðµÄ£¬£¬£¬£¬ÔÚÓÃÓÚLinuxµÄCitrix Gateway²å¼þÖз¢Ã÷ÁËÒ»¸öÎó²î£¬£¬£¬£¬×°ÖÃÁ˸òå¼þµÄLinuxϵͳµÄÓû§¿ÉÒÔʹÓøÃÎó²î¾ÙÐÐÍâµØÌáȨ¡£¡£¡£¡£¡£
ƾ֤CitrixÐû²¼µÄÐÅÏ¢£¬£¬£¬£¬ÕâЩÎó²îÓë¸Ã¹«Ë¾ÔÚ2020Äê1ÔÂÐÞ¸´µÄCVE-2019-19781Ô¶³Ì´úÂëÖ´ÐÐÎó²îÎ޹أ¬£¬£¬£¬²»Ó°ÏìCitrix×°±¸µÄÔÆ°æ±¾¡£¡£¡£¡£¡£µ½ÏÖÔÚΪֹ»¹Ã»Óз¢Ã÷¶ÔÕâЩÎó²îµÄʹÓ㬣¬£¬£¬½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ìÉý¼¶¡£¡£¡£¡£¡£
0x02 ´¦Öóͷ£½¨Òé
ÏÖÔÚ³§ÉÌÒÑÐû²¼²¹¶¡£¬£¬£¬£¬ÏÂÁа汾µÄCitrix ADC¡¢CitrixÍø¹ØºÍCitrix SD-WAN WANOPÐÞ¸´ÁËÎó²î£º?
Citrix ADC and Citrix Gateway >= 13.0-58.30°æ±¾
Citrix ADC and NetScaler Gateway > 12.1°æ±¾£¬£¬£¬£¬12.1-57.18°æ±¾
Citrix ADC and NetScaler Gateway > ?12.0°æ±¾£¬£¬£¬£¬12.0-63.21°æ±¾
Citrix ADC and NetScaler Gateway > 11.1°æ±¾£¬£¬£¬£¬11.1-64.14°æ±¾
NetScaler ADC and NetScaler Gateway > 10.5°æ±¾£¬£¬£¬£¬10.5-70.18°æ±¾
Citrix SD-WAN WANOP >= 11.1.1a°æ±¾
Citrix SD-WAN WANOP > 11.0°æ±¾£¬£¬£¬£¬11.0.3d°æ±¾
Citrix SD-WAN WANOP > 10.2°æ±¾£¬£¬£¬£¬10.2.7°æ±¾
Citrix Gateway Plug-in for Linux >= ?1.0.0.137°æ±¾
½¨ÒéÊÜÓ°ÏìµÄ¿Í»§ÊµÊ±¸üУ¬£¬£¬£¬ÏÂÔØÁ´½Ó£º
https://www.citrix.com/downloads/citrix-adc/
https://www.citrix.com/downloads/citrix-gateway/
https://www.citrix.com/downloads/citrix-sd-wan/
ÔÝʱ²½·¥£º
µ±Citrix ADC×°±¸°²Åŵ½Éú²úÇéÐÎʱ£¬£¬£¬£¬Citrix ½¨Òé¾ÙÐÐÒÔÏÂÉèÖøü¸Ä£º
? եȡCitrix ADC ÖÎÀíÔ±½Ó¿Ú(NSIP)»á¼ûInternet£»£»£»£»£»£»
? Ìæ»» Citrix ADC ĬÈÏSSLÖ¤Ê飻£»£»£»£»£»
? ʹÓÃHTTPS»á¼û GUI¡£¡£¡£¡£¡£
¸ü¶àÏêϸÐÅÏ¢£¬£¬£¬£¬Çë²Î¿¼ÒÔÏÂÁ´½Ó£ºhttps://docs.citrix.com/zh-cn/citrix-adc/citrix-adc-secure-deployment/secure-deployment-guide.html
0x03 Ïà¹ØÐÂÎÅ
https://threatpost.com/citrix-bugs-allow-unauthenticated-code-injection-data-theft/157214/
0x04 ²Î¿¼Á´½Ó
https://support.citrix.com/article/CTX276688
0x05 ʱ¼äÏß
2020-07-07 Citrix¹Ù·½Ðû²¼Ç徲ͨ¸æ
2020-07-09 VSRCÐû²¼Îó²îͨ¸æ
