Pulse Connect Secureí§Òâ´úÂëÖ´ÐÐÎó²î£¨CVE-2021-22908£©

Ðû²¼Ê±¼ä 2021-05-25

0x00 Îó²î¸ÅÊö

CVE  ID

CVE-2021-22908

ʱ   ¼ä

2021-05-25

Àà   ÐÍ

´úÂëÖ´ÐÐ

µÈ   ¼¶

¸ßΣ

Ô¶³ÌʹÓÃ

ÊÇ

Ó°Ïì¹æÄ£

9.0RX¡¢9.1RX

PoC/EXP

δ¹ûÕæ

ÔÚҰʹÓÃ

·ñ

 

0x01 Îó²îÏêÇé

image.png

 

Pulse Connect Secure£¨PCS£©ÊÇÃÀ¹úPulse Secure¹«Ë¾µÄÒ»Ì×SSL VPN½â¾ö¼Æ»®¡£¡£¡£¡£¡£¡£¡£

2021Äê05ÔÂ24ÈÕ£¬£¬£¬£¬£¬£¬£¬¿¨ÄÚ»ù÷¡´óѧÅû¶ÁËPulse Connect SecureÖеÄÒ»¸ö»º³åÇøÒç³öÎó²î£¨CVE-2021-22908£©£¬£¬£¬£¬£¬£¬£¬¸ÃÎó²îµÄCVSSÆÀ·ÖΪ8.5¡£¡£¡£¡£¡£¡£¡£¾­ÓÉÉí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓôËÎó²îÔÚÊÜÓ°ÏìµÄPCSЧÀÍÆ÷ÉÏÒÔrootȨÏÞÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¡£

 

Îó²îϸ½Ú

ÓÉÓÚPCSÖ§³ÖÅþÁ¬µ½WindowsÎļþ¹²Ïí£¨SMB£©µÄ¹¦Ð§ÓÉ»ùÓÚSamba 4.5.10µÄ¿âºÍ¸¨ÖúÓ¦ÓóÌÐòµÄCGI¾ç±¾Ìṩ¡£¡£¡£¡£¡£¡£¡£µ±ÎªÄ³Ð©SMB²Ù×÷Ö¸¶¨Ò»¸ö³¤µÄЧÀÍÆ÷Ãû³ÆÊ±£¬£¬£¬£¬£¬£¬£¬smbcltÓ¦ÓóÌÐò¿ÉÄÜ»áÓÉÓÚ»º³åÇøÒç³ö¶øÍ߽⣬£¬£¬£¬£¬£¬£¬Ïêϸȡ¾öÓÚÖ¸¶¨µÄЧÀÍÆ÷Ãû³Æ³¤¶È¡£¡£¡£¡£¡£¡£¡£

ÒѾ­È·ÈÏPCS 9.1R11.4ϵͳ±£´æ´ËÎó²î£¬£¬£¬£¬£¬£¬£¬Ä¿µÄCGI¶ËµãΪ/dana/fb/smb/wnf.cgi£¬£¬£¬£¬£¬£¬£¬ÆäËüCGI¶ËµãÒ²¿ÉÄܻᴥ·¢´ËÎó²î¡£¡£¡£¡£¡£¡£¡£

ÈôÊǹ¥»÷ÕßÔÚÀÖ³ÉʹÓôËÎó²îºóûÓоÙÐÐÕûÀí£¬£¬£¬£¬£¬£¬£¬ÔòÖ¸¶¨Ò»¸ö³¤µÄЧÀÍÆ÷Ãû³Æ¿ÉÄܻᵼÖÂÈçÏÂPCSÊÂÎñÈÕÖ¾ÌõÄ¿£º

Critical ERR31093 2021-05-24 14:05:37 - ive - [127.0.0.1] Root::System()[] - Program smbclt recently failed.

 

µ«ÒªÊ¹ÓôËÎó²î£¬£¬£¬£¬£¬£¬£¬PCSЧÀÍÆ÷±ØÐèÓÐÒ»¸öallows \\*µÄWindowsÎļþ»á¼ûÕ½ÂÔ»òÔÊÐí¹¥»÷ÕßÅþÁ¬µ½í§ÒâЧÀÍÆ÷µÄÆäËüµÄÕ½ÂÔ¡£¡£¡£¡£¡£¡£¡ £¿£¿£¿ÉÒÔÔÚPCSµÄÖÎÀíÒ³ÃæÖУ¬£¬£¬£¬£¬£¬£¬Éó²éÓû§->×ÊÔ´Õ½ÂÔ->WindowsÎļþ»á¼ûÕ½ÂÔ£¬£¬£¬£¬£¬£¬£¬À´Éó²éÄ¿½ñµÄSMBÕ½ÂÔ¡£¡£¡£¡£¡£¡£¡£9.1R2¼°Ö®Ç°µÄPCS×°±¸Ê¹ÓÃÔÊÐíÅþÁ¬µ½í§ÒâSMBÖ÷»úµÄĬÈÏÕ½ÂÔ£¬£¬£¬£¬£¬£¬£¬´Ó9.1R3×îÏÈ£¬£¬£¬£¬£¬£¬£¬Õâ¸öÕ½ÂÔ´ÓĬÈÏÔÊÐí¸ü¸ÄΪĬÈϾܾø¡£¡£¡£¡£¡£¡£¡£

 

Ó°Ïì¹æÄ£

Pulse Connect Secure 9.0RXºÍ9.1RX

 

0x02 ´¦Öóͷ£½¨Òé

Pulse SecureÔ¤¼ÆÔÚPulse Connect Secure 9.1R11.5»ò¸ü¸ß°æ±¾ÖÐÐÞ¸´¸ÃÎó²î£¬£¬£¬£¬£¬£¬£¬µ«ÏÖÔÚÉÐδÐû²¼¡£¡£¡£¡£¡£¡£¡£

ÏÂÔØÁ´½Ó£º

https://my.pulsesecure.net/

 

0x03 ²Î¿¼Á´½Ó

https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44800

https://kb.cert.org/vuls/id/667933

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-22908

 

0x04 ʱ¼äÏß

2021-05-24 ¿¨ÄÚ»ù÷¡´óѧÅû¶Îó²î

2021-05-25  VSRCÐû²¼Ç徲ͨ¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/

image.png