CVE-2020-2050 | PAN-OSÉí·ÝÑéÖ¤ÈÆ¹ýÎó²îͨ¸æ

Ðû²¼Ê±¼ä 2020-11-12

0x00 Îó²î¸ÅÊö

CNVD   ID

CVE-2020-2050

ʱ      ¼ä

2020-11-12

Àà    ÐÍ

Éí·ÝÑéÖ¤ÈÆ¹ý

µÈ      ¼¶

¸ßΣ

Ô¶³ÌʹÓÃ

ÊÇ

Ó°Ïì¹æÄ£

<10.0.1

<9.1.5

 <9.0.11

 <8.1.17

 

0x01 Îó²îÏêÇé

image.png 

2020Äê11ÔÂ11ÈÕ£¬£¬£¬£¬Palo Alto NetworksÐû²¼Ç徲ͨ¸æ£¬£¬£¬£¬PAN-OSµÄGlobalProtect SSL VPN×é¼þÖб£´æÒ»¸öÉí·ÝÑéÖ¤ÈÆ¹ýÎó²î£¨CVE-2020-2050£©£¬£¬£¬£¬ÆäCVSSÆÀ·Ö8.2¡£¡£¡£¡£

µ±Íø¹ØµÄÉí·ÝÑéÖ¤·½·¨ÉèÖÃΪÍêÈ«»ùÓÚÖ¤Êéʱ£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔʹÓôËÎó²îÈÆ¹ýËùÓÐʹÓÃÎÞЧ֤ÊéµÄ¿Í»§¶ËÖ¤Êé¼ì²é£¬£¬£¬£¬²¢Äܹ»ÒÔÈκÎÓû§µÄÉí·Ý¾ÙÐÐÉí·ÝÑéÖ¤£¬£¬£¬£¬×îÖÕ»ñµÃ¶ÔVPNÍøÂç×ÊÔ´µÄ»á¼ûȨÏÞ¡£¡£¡£¡£

½«SSL VPNÉèÖÃΪ¿Í»§¶ËÖ¤ÊéÑéÖ¤Ó°ÏìµÄ¹¦Ð§°üÀ¨£º

GlobalProtect Gateway

GlobalProtect Portal

GlobalProtect Clientless VPN

ÔÚ½«¿Í»§¶ËÖ¤ÊéÑéÖ¤ÓëÆäËüÉí·ÝÑéÖ¤ÒªÁìÁ¬ÏµÊ¹ÓõÄÇéÐÎÏ£¬£¬£¬£¬´ËÎó²î½«Ê¹µÃÖ¤ÊéÌí¼ÓµÄ±£»£»£» £»¤±»ºöÂÔ¡£¡£¡£¡£

´ËÎó²î»áÓ°ÏìʹÓÃGlobalProtect SSL VPN²¢½«Íø¹ØºÍÃÅ»§ÍøÕ¾ÉèÖÃΪÔÊÐíÓû§Ê¹Óÿͻ§¶ËÖ¤ÊéÉí·ÝÑéÖ¤µÄPAN OS×°±¸¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬ÈôÊÇʹÓÃÁ˿ͻ§¶ËÖ¤ÊéÈÏÖ¤£¬£¬£¬£¬Ôò»ùÓÚIPSecµÄVPNÒ²½«Êܵ½Ó°Ïì¡£¡£¡£¡£ÈôÊÇδʹÓÿͻ§¶ËÖ¤Êé¾ÙÐÐÉí·ÝÑéÖ¤£¬£¬£¬£¬ÔòÎÞ·¨Ê¹ÓôËÎó²î¡£¡£¡£¡£


0x02 ´¦Öóͷ£½¨Òé

ÏÖÔÚPalo Alto NetworksÒѾ­Ðû²¼Á˸üа汾¡£¡£¡£¡£½¨Òé²Î¿¼Ï±íʵʱÉý¼¶£º

°æ±¾ºÅ

ÊÜÓ°Ïì°æ±¾

¸üа汾

PAN OS 10.0

<10.0.1

> = 10.0.1

PAN OS 9.1

<9.1.5

> = 9.1.5

PAN OS 9.0

<9.0.11

> = 9.0.11

PAN OS 8.1

<8.1.17

> = 8.1.17

 

ÔÝʱ²½·¥£º

½«GlobalProtect SSL VPNÉèÖÃΪҪÇóÓû§Ê¹ÓÃÆäÆ¾Ö¤¾ÙÐÐÉí·ÝÑéÖ¤¡£¡£¡£¡£

ÏÂÔØÁ´½Ó£º

https://www.paloaltonetworks.com/search

0x03 ²Î¿¼Á´½Ó

https://security.paloaltonetworks.com/CVE-2020-2050

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-2050

0x04 ʱ¼äÏß

2020-11-11  Palo Alto NetworksÐû²¼Ç徲ͨ¸æ

2020-11-12  VSRCÐû²¼Ç徲ͨ¸æ

0x05 ¸½Â¼

 

CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/

 

image.png