CVE-2020-2050 | PAN-OSÉí·ÝÑéÖ¤ÈÆ¹ýÎó²îͨ¸æ
Ðû²¼Ê±¼ä 2020-11-120x00 Îó²î¸ÅÊö
CNVD ID | CVE-2020-2050 | ʱ ¼ä | 2020-11-12 |
Àà ÐÍ | Éí·ÝÑéÖ¤ÈÆ¹ý | µÈ ¼¶ | ¸ßΣ |
Ô¶³ÌʹÓà | ÊÇ | Ó°Ïì¹æÄ£ | <10.0.1 <9.1.5 <9.0.11 <8.1.17 |
0x01 Îó²îÏêÇé
2020Äê11ÔÂ11ÈÕ£¬£¬£¬£¬Palo Alto NetworksÐû²¼Ç徲ͨ¸æ£¬£¬£¬£¬PAN-OSµÄGlobalProtect SSL VPN×é¼þÖб£´æÒ»¸öÉí·ÝÑéÖ¤ÈÆ¹ýÎó²î£¨CVE-2020-2050£©£¬£¬£¬£¬ÆäCVSSÆÀ·Ö8.2¡£¡£¡£¡£
µ±Íø¹ØµÄÉí·ÝÑéÖ¤·½·¨ÉèÖÃΪÍêÈ«»ùÓÚÖ¤Êéʱ£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔʹÓôËÎó²îÈÆ¹ýËùÓÐʹÓÃÎÞЧ֤ÊéµÄ¿Í»§¶ËÖ¤Êé¼ì²é£¬£¬£¬£¬²¢Äܹ»ÒÔÈκÎÓû§µÄÉí·Ý¾ÙÐÐÉí·ÝÑéÖ¤£¬£¬£¬£¬×îÖÕ»ñµÃ¶ÔVPNÍøÂç×ÊÔ´µÄ»á¼ûȨÏÞ¡£¡£¡£¡£
½«SSL VPNÉèÖÃΪ¿Í»§¶ËÖ¤ÊéÑéÖ¤Ó°ÏìµÄ¹¦Ð§°üÀ¨£º
GlobalProtect Gateway
GlobalProtect Portal
GlobalProtect Clientless VPN
ÔÚ½«¿Í»§¶ËÖ¤ÊéÑéÖ¤ÓëÆäËüÉí·ÝÑéÖ¤ÒªÁìÁ¬ÏµÊ¹ÓõÄÇéÐÎÏ£¬£¬£¬£¬´ËÎó²î½«Ê¹µÃÖ¤ÊéÌí¼ÓµÄ±£»£»£»£»¤±»ºöÂÔ¡£¡£¡£¡£
´ËÎó²î»áÓ°ÏìʹÓÃGlobalProtect SSL VPN²¢½«Íø¹ØºÍÃÅ»§ÍøÕ¾ÉèÖÃΪÔÊÐíÓû§Ê¹Óÿͻ§¶ËÖ¤ÊéÉí·ÝÑéÖ¤µÄPAN OS×°±¸¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬ÈôÊÇʹÓÃÁ˿ͻ§¶ËÖ¤ÊéÈÏÖ¤£¬£¬£¬£¬Ôò»ùÓÚIPSecµÄVPNÒ²½«Êܵ½Ó°Ïì¡£¡£¡£¡£ÈôÊÇδʹÓÿͻ§¶ËÖ¤Êé¾ÙÐÐÉí·ÝÑéÖ¤£¬£¬£¬£¬ÔòÎÞ·¨Ê¹ÓôËÎó²î¡£¡£¡£¡£
0x02 ´¦Öóͷ£½¨Òé
ÏÖÔÚPalo Alto NetworksÒѾÐû²¼Á˸üа汾¡£¡£¡£¡£½¨Òé²Î¿¼Ï±íʵʱÉý¼¶£º
°æ±¾ºÅ | ÊÜÓ°Ïì°æ±¾ | ¸üа汾 |
PAN OS 10.0 | <10.0.1 | > = 10.0.1 |
PAN OS 9.1 | <9.1.5 | > = 9.1.5 |
PAN OS 9.0 | <9.0.11 | > = 9.0.11 |
PAN OS 8.1 | <8.1.17 | > = 8.1.17 |
ÔÝʱ²½·¥£º
½«GlobalProtect SSL VPNÉèÖÃΪҪÇóÓû§Ê¹ÓÃÆäÆ¾Ö¤¾ÙÐÐÉí·ÝÑéÖ¤¡£¡£¡£¡£
ÏÂÔØÁ´½Ó£º
https://www.paloaltonetworks.com/search
0x03 ²Î¿¼Á´½Ó
https://security.paloaltonetworks.com/CVE-2020-2050
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-2050
0x04 ʱ¼äÏß
2020-11-11 Palo Alto NetworksÐû²¼Ç徲ͨ¸æ
2020-11-12 VSRCÐû²¼Ç徲ͨ¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/