Citrix²úÆ·¶à¸öÇå¾²Îó²îͨ¸æ

Ðû²¼Ê±¼ä 2020-07-09

0x00 Îó²î¸ÅÊö


2020Äê7ÔÂ7ÈÕ£¬£¬£¬£¬Citrix¹Ù·½Ðû²¼Ç徲ͨ¸æ£¬£¬£¬£¬ÔÚCitrix ADC¡¢CitrixÍø¹ØºÍCitrix SD-WAN WANOP 4000-WO¡¢4100-WO¡¢5000-WOºÍ5100-WO°æ±¾Öз¢Ã÷Á˶à¸öÎó²î¡£¡£¡£¡£¡£ÏêÇé¼ûÏÂ±í£º

CVE ID

Îó²îÀàÐÍ

Ó°Ïì²úÆ·

¹¥»÷ÕßȨÏÞ

Ìõ¼þÌõ¼þ

CVE-2019-18177

ID

Citrix ADC, Citrix Gateway 

¾­Éí·ÝÈÏÖ¤µÄVPNÓû§

ÐèÒªÒ»¸öÉèÖõÄSSL VPNÖÕ¶Ë

CVE-2020-8187

DOS

Citrix ADC, Citrix Gateway 12.0 and 11.1°æ±¾

δ¾­Éí·ÝÈÏÖ¤µÄÔ¶³ÌÓû§

ÐèÒªÒ»¸öÉèÖõÄSSL VPN»òAAAÖÕ¶Ë

CVE-2020-8190

EOP

Citrix ADC, Citrix Gateway 

λÓÚNSIPÉϾ­Éí·ÝÈÏÖ¤µÄÓû§

¸ÃÎó²îÎÞ·¨Ö±½Ó±»Ê¹Óᣡ£¡£¡£¡£¹¥»÷Õß±ØÐèÊ×ÏÈʹÓÃÁíÒ»¸öÎó²î»ñÈ¡nobodyÕË»§È¨ÏÞ

CVE-2020-8191

XSS

Citrix ADC, Citrix Gateway, Citrix SDWAN WAN-OP 

δ¾­Éí·ÝÈÏÖ¤µÄÔ¶³ÌÓû§

ÐèÒªÊܺ¦ÕßÔÚä¯ÀÀÆ÷Öз­¿ªÓɹ¥»÷Õß¿ØÖƵÄÁ´½Ó£¬£¬£¬£¬Í¬Ê±´¦ÓÚÅþÁ¬NSIPµÄÍøÂçÉÏ

CVE-2020-8193

AB

Citrix ADC, Citrix Gateway, Citrix SDWAN WAN-OP 

¾ßÓÐNSIP»á¼ûȨÏ޵쬣¬£¬£¬Î´¾­Éí·ÝÈÏÖ¤µÄÓû§

¹¥»÷Õß±ØÐèÄܹ»»á¼û¸ÃNSIP

CVE-2020-8194

CI

Citrix ADC, Citrix Gateway, Citrix SDWAN WAN-OP 

δ¾­Éí·ÝÈÏÖ¤µÄÔ¶³ÌÓû§

ÐèÒªÊܺ¦Õß´Ó¸ÃNSIPÏÂÔØ²¢Ö´ÐжñÒâ¶þ½øÖÆÎļþ

CVE-2020-8195

ID

Citrix ADC, Citrix Gateway, Citrix SDWAN WAN-OP 

λÓÚNSIPÉϾ­Éí·ÝÈÏÖ¤µÄÓû§

CVE-2020-8196

ID

Citrix ADC, Citrix Gateway, Citrix SDWAN WAN-OP 

λÓÚNSIPÉϾ­Éí·ÝÈÏÖ¤µÄÓû§

CVE-2020-8197

EOP

Citrix ADC, Citrix Gateway 

λÓÚNSIPÉϾ­Éí·ÝÈÏÖ¤µÄÓû§

CVE-2020-8198

XSS

Citrix ADC, Citrix Gateway,Citrix SDWAN WAN-OP 

δ¾­Éí·ÝÈÏÖ¤µÄÔ¶³Ì¹¥»÷Õß

ÐèÒªÊܺ¦Õß±ØÐèÔÚNSIPÉÏÒÔÖÎÀíÔ±£¨nsroot£©Éí·ÝµÇ¼

CVE-2020-8199

EOP

Citrix Gateway Plug-in for Linux 

λÓÚLinuxÅÌËã»úÉÏÔËÐÐCitrix Gateway  Plug-inµÄÍâµØÓû§

±ØÐèÔËÐÐCitrix Gateway Plug-in for LinuxԤװ°æ±¾

´Ó±íÖпÉÒÔ¿´³ö£¬£¬£¬£¬¹¥»÷»¹ÐèҪijÖÖÐÎʽµÄ»á¼ûȨÏ޲ŻªÊ¹ÓÃÕâЩÎó²î£¬£¬£¬£¬ÕâÒâζ׏¥»÷ÕßÊ×ÏÈÐèÒª»á¼ûÄ¿µÄϵͳ²Å»ª¾ÙÐй¥»÷¡£¡£¡£¡£¡£


0x01 Îó²îÏêÇé



¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Citrix²úÆ·Ö÷ÒªÓÃÓÚÓ¦ÓóÌÐòµÄÁ÷Á¿ÖÎÀíºÍʵÏÖÇå¾²µÄÔ¶³Ì»á¼û£¬£¬£¬£¬²¢ÖÁÉÙÒÑÔÚ158¸ö¹ú¼ÒµÄ80000¼Ò¹«Ë¾ÖÐ×°Öᣡ£¡£¡£¡£

ÈôÊÇÕâЩÎó²îÔ⵽ʹÓ㬣¬£¬£¬¿ÉÄܻᵼÖÂÐí¶àÇå¾²ÎÊÌ⣬£¬£¬£¬°üÀ¨±»ÓÃÓÚ»ñÊØÐÅÏ¢¡¢·¢¶¯ DoS ¹¥»÷¡¢ÊµÏÖÍâµØÌáȨ¡¢·¢¶¯ XSS ¹¥»÷ºÍÈÆ¹ýÈÏÖ¤²¢×¢Èë¶ñÒâ´úÂë¡£¡£¡£¡£¡£

±ðµÄ£¬£¬£¬£¬ÔÚÓÃÓÚLinuxµÄCitrix Gateway²å¼þÖз¢Ã÷ÁËÒ»¸öÎó²î£¬£¬£¬£¬×°ÖÃÁ˸òå¼þµÄLinuxϵͳµÄÓû§¿ÉÒÔʹÓøÃÎó²î¾ÙÐÐÍâµØÌáȨ¡£¡£¡£¡£¡£

ƾ֤CitrixÐû²¼µÄÐÅÏ¢£¬£¬£¬£¬ÕâЩÎó²îÓë¸Ã¹«Ë¾ÔÚ2020Äê1ÔÂÐÞ¸´µÄCVE-2019-19781Ô¶³Ì´úÂëÖ´ÐÐÎó²îÎ޹أ¬£¬£¬£¬²»Ó°ÏìCitrix×°±¸µÄÔÆ°æ±¾¡£¡£¡£¡£¡£µ½ÏÖÔÚΪֹ»¹Ã»Óз¢Ã÷¶ÔÕâЩÎó²îµÄʹÓ㬣¬£¬£¬½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ìÉý¼¶¡£¡£¡£¡£¡£


0x02 ´¦Öóͷ£½¨Òé


ÏÖÔÚ³§ÉÌÒÑÐû²¼²¹¶¡£¬£¬£¬£¬ÏÂÁа汾µÄCitrix ADC¡¢CitrixÍø¹ØºÍCitrix SD-WAN WANOPÐÞ¸´ÁËÎó²î£º?

Citrix ADC and Citrix Gateway >= 13.0-58.30°æ±¾

Citrix ADC and NetScaler Gateway > 12.1°æ±¾£¬£¬£¬£¬12.1-57.18°æ±¾

Citrix ADC and NetScaler Gateway > ?12.0°æ±¾£¬£¬£¬£¬12.0-63.21°æ±¾

Citrix ADC and NetScaler Gateway > 11.1°æ±¾£¬£¬£¬£¬11.1-64.14°æ±¾

NetScaler ADC and NetScaler Gateway > 10.5°æ±¾£¬£¬£¬£¬10.5-70.18°æ±¾

Citrix SD-WAN WANOP >= 11.1.1a°æ±¾

Citrix SD-WAN WANOP > 11.0°æ±¾£¬£¬£¬£¬11.0.3d°æ±¾

Citrix SD-WAN WANOP > 10.2°æ±¾£¬£¬£¬£¬10.2.7°æ±¾

Citrix Gateway Plug-in for Linux >= ?1.0.0.137°æ±¾

½¨ÒéÊÜÓ°ÏìµÄ¿Í»§ÊµÊ±¸üУ¬£¬£¬£¬ÏÂÔØÁ´½Ó£º

https://www.citrix.com/downloads/citrix-adc/

https://www.citrix.com/downloads/citrix-gateway/

https://www.citrix.com/downloads/citrix-sd-wan/

ÔÝʱ²½·¥£º

µ±Citrix ADC×°±¸°²Åŵ½Éú²úÇéÐÎʱ£¬£¬£¬£¬Citrix ½¨Òé¾ÙÐÐÒÔÏÂÉèÖøü¸Ä£º

? եȡCitrix ADC ÖÎÀíÔ±½Ó¿Ú(NSIP)»á¼ûInternet£»£»£»£»£»£»

? Ìæ»» Citrix ADC ĬÈÏSSLÖ¤Ê飻£»£»£»£»£»

? ʹÓÃHTTPS»á¼û GUI¡£¡£¡£¡£¡£

¸ü¶àÏêϸÐÅÏ¢£¬£¬£¬£¬Çë²Î¿¼ÒÔÏÂÁ´½Ó£ºhttps://docs.citrix.com/zh-cn/citrix-adc/citrix-adc-secure-deployment/secure-deployment-guide.html


0x03 Ïà¹ØÐÂÎÅ


https://threatpost.com/citrix-bugs-allow-unauthenticated-code-injection-data-theft/157214/


0x04 ²Î¿¼Á´½Ó


https://support.citrix.com/article/CTX276688


0x05 ʱ¼äÏß


2020-07-07 Citrix¹Ù·½Ðû²¼Ç徲ͨ¸æ

2020-07-09 VSRCÐû²¼Îó²îͨ¸æ


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨