Pulse Connect Secureí§Òâ´úÂëÖ´ÐÐÎó²î£¨CVE-2021-22908£©
Ðû²¼Ê±¼ä 2021-05-250x00 Îó²î¸ÅÊö
CVE ID | CVE-2021-22908 | ʱ ¼ä | 2021-05-25 |
Àà ÐÍ | ´úÂëÖ´ÐÐ | µÈ ¼¶ | ¸ßΣ |
Ô¶³ÌʹÓà | ÊÇ | Ó°Ïì¹æÄ£ | 9.0RX¡¢9.1RX |
PoC/EXP | δ¹ûÕæ | ÔÚҰʹÓà | ·ñ |
0x01 Îó²îÏêÇé
Pulse Connect Secure£¨PCS£©ÊÇÃÀ¹úPulse Secure¹«Ë¾µÄÒ»Ì×SSL VPN½â¾ö¼Æ»®¡£¡£¡£¡£¡£¡£¡£
2021Äê05ÔÂ24ÈÕ£¬£¬£¬£¬£¬£¬£¬¿¨ÄÚ»ù÷¡´óѧÅû¶ÁËPulse Connect SecureÖеÄÒ»¸ö»º³åÇøÒç³öÎó²î£¨CVE-2021-22908£©£¬£¬£¬£¬£¬£¬£¬¸ÃÎó²îµÄCVSSÆÀ·ÖΪ8.5¡£¡£¡£¡£¡£¡£¡£¾ÓÉÉí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓôËÎó²îÔÚÊÜÓ°ÏìµÄPCSЧÀÍÆ÷ÉÏÒÔrootȨÏÞÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¡£
Îó²îϸ½Ú
ÓÉÓÚPCSÖ§³ÖÅþÁ¬µ½WindowsÎļþ¹²Ïí£¨SMB£©µÄ¹¦Ð§ÓÉ»ùÓÚSamba 4.5.10µÄ¿âºÍ¸¨ÖúÓ¦ÓóÌÐòµÄCGI¾ç±¾Ìṩ¡£¡£¡£¡£¡£¡£¡£µ±ÎªÄ³Ð©SMB²Ù×÷Ö¸¶¨Ò»¸ö³¤µÄЧÀÍÆ÷Ãû³ÆÊ±£¬£¬£¬£¬£¬£¬£¬smbcltÓ¦ÓóÌÐò¿ÉÄÜ»áÓÉÓÚ»º³åÇøÒç³ö¶øÍ߽⣬£¬£¬£¬£¬£¬£¬Ïêϸȡ¾öÓÚÖ¸¶¨µÄЧÀÍÆ÷Ãû³Æ³¤¶È¡£¡£¡£¡£¡£¡£¡£
ÒѾȷÈÏPCS 9.1R11.4ϵͳ±£´æ´ËÎó²î£¬£¬£¬£¬£¬£¬£¬Ä¿µÄCGI¶ËµãΪ/dana/fb/smb/wnf.cgi£¬£¬£¬£¬£¬£¬£¬ÆäËüCGI¶ËµãÒ²¿ÉÄܻᴥ·¢´ËÎó²î¡£¡£¡£¡£¡£¡£¡£
ÈôÊǹ¥»÷ÕßÔÚÀÖ³ÉʹÓôËÎó²îºóûÓоÙÐÐÕûÀí£¬£¬£¬£¬£¬£¬£¬ÔòÖ¸¶¨Ò»¸ö³¤µÄЧÀÍÆ÷Ãû³Æ¿ÉÄܻᵼÖÂÈçÏÂPCSÊÂÎñÈÕÖ¾ÌõÄ¿£º
Critical ERR31093 2021-05-24 14:05:37 - ive - [127.0.0.1] Root::System()[] - Program smbclt recently failed.
µ«ÒªÊ¹ÓôËÎó²î£¬£¬£¬£¬£¬£¬£¬PCSЧÀÍÆ÷±ØÐèÓÐÒ»¸öallows \\*µÄWindowsÎļþ»á¼ûÕ½ÂÔ»òÔÊÐí¹¥»÷ÕßÅþÁ¬µ½í§ÒâЧÀÍÆ÷µÄÆäËüµÄÕ½ÂÔ¡£¡£¡£¡£¡£¡£¡£¿£¿£¿ÉÒÔÔÚPCSµÄÖÎÀíÒ³ÃæÖУ¬£¬£¬£¬£¬£¬£¬Éó²éÓû§->×ÊÔ´Õ½ÂÔ->WindowsÎļþ»á¼ûÕ½ÂÔ£¬£¬£¬£¬£¬£¬£¬À´Éó²éÄ¿½ñµÄSMBÕ½ÂÔ¡£¡£¡£¡£¡£¡£¡£9.1R2¼°Ö®Ç°µÄPCS×°±¸Ê¹ÓÃÔÊÐíÅþÁ¬µ½í§ÒâSMBÖ÷»úµÄĬÈÏÕ½ÂÔ£¬£¬£¬£¬£¬£¬£¬´Ó9.1R3×îÏÈ£¬£¬£¬£¬£¬£¬£¬Õâ¸öÕ½ÂÔ´ÓĬÈÏÔÊÐí¸ü¸ÄΪĬÈϾܾø¡£¡£¡£¡£¡£¡£¡£
Ó°Ïì¹æÄ£
Pulse Connect Secure 9.0RXºÍ9.1RX
0x02 ´¦Öóͷ£½¨Òé
Pulse SecureÔ¤¼ÆÔÚPulse Connect Secure 9.1R11.5»ò¸ü¸ß°æ±¾ÖÐÐÞ¸´¸ÃÎó²î£¬£¬£¬£¬£¬£¬£¬µ«ÏÖÔÚÉÐδÐû²¼¡£¡£¡£¡£¡£¡£¡£
ÏÂÔØÁ´½Ó£º
https://my.pulsesecure.net/
0x03 ²Î¿¼Á´½Ó
https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44800
https://kb.cert.org/vuls/id/667933
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-22908
0x04 ʱ¼äÏß
2021-05-24 ¿¨ÄÚ»ù÷¡´óѧÅû¶Îó²î
2021-05-25 VSRCÐû²¼Ç徲ͨ¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/