¡¾Îó²îͨ¸æ¡¿Palo Alto Networks PAN-OSÏÂÁî×¢ÈëÎó²î (CVE-2021-3050)
Ðû²¼Ê±¼ä 2021-08-120x00 Îó²î¸ÅÊö
CVE ID | CVE-2021-3050 | ʱ ¼ä | 2021-08-11 |
Àà ÐÍ | ÏÂÁî×¢Èë | µÈ ¼¶ | ¸ßΣ |
Ô¶³ÌʹÓà | ÊÇ | Ó°Ïì¹æÄ£ | |
¹¥»÷ÖØÆ¯ºó | µÍ | ¿ÉÓÃÐÔ | ¸ß |
Óû§½»»¥ | ÎÞ | ËùÐèȨÏÞ | µÍ |
PoC/EXP | ÒѹûÕæ | ÔÚҰʹÓà |
0x01 Îó²îÏêÇé
PAN-OSÊÇPalo Alto NetworksΪÆä·À»ðǽװ±¸¿ª·¢µÄ²Ù×÷ϵͳ¡£¡£¡£¡£¡£
2021Äê8ÔÂ11ÈÕ£¬£¬£¬£¬£¬Palo Alto NetworksÐû²¼Ç徲ͨ¸æ£¬£¬£¬£¬£¬ÐÞ¸´ÁËPAN-OSÖеÄÒ»¸öÏÂÁî×¢ÈëÎó²î£¨CVE-2021-3050£©£¬£¬£¬£¬£¬¸ÃÎó²îµÄCVSSv3ÆÀ·ÖΪ8.8¡£¡£¡£¡£¡£
¸ÃÎó²î±£´æÓÚPAN-OS Web ½çÃæÖУ¬£¬£¬£¬£¬¾ÓÉÉí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÄܹ»Ö´ÐÐí§ÒâϵͳÏÂÁî²¢ÌáÉýȨÏÞ£¬£¬£¬£¬£¬µ«ÒªÊ¹ÓôËÎó²î£¬£¬£¬£¬£¬¹¥»÷ÕßÐèÒª»á¼û PAN-OS Web ½çÃæ¾ÙÐÐÉí·ÝÑéÖ¤¡£¡£¡£¡£¡£
Palo Alto NetworksÌåÏÖÔÝδ·¢Ã÷¸ÃÎó²î±»Ê¹Ó㬣¬£¬£¬£¬µ«´ËÎó²îµÄEXPÒѹûÕæ¡£¡£¡£¡£¡£
0x02 ´¦Öóͷ£½¨Òé
ÏÖÔÚ´ËÎó²îÒѾÐÞ¸´¡£¡£¡£¡£¡£¼øÓÚ´ËÎó²îΪÍⲿ·¢Ã÷£¬£¬£¬£¬£¬ÇÒÎó²îʹÓùûÕæ¿ÉÓ㬣¬£¬£¬£¬½¨ÒéÊÜÓ°ÏìÓû§²Î¿¼Ï±íʵʱÉý¼¶¸üУº
°æ±¾ | ÊÜÓ°Ïì°æ±¾ | ÐÞ¸´°æ±¾ |
PAN-OS 10.1 | >= 10.1.0 | >= 10.1.2 |
PAN-OS 10.0 | >= 10.0.0 | >= 10.0.8 |
PAN-OS 9.1 | >= 9.1.4 | >= 9.1.11 |
PAN-OS 9.0 | >= 9.0.10 | >= 9.0.15 |
PAN-OS 8.1 | None | 8.1.* |
×¢£ºPrisma Access ·À»ðǽºÍÔËÐÐ PAN OS 8.1 °æ±¾µÄ·À»ðǽ²»ÊÜ´ËÎó²îµÄÓ°Ïì¡£¡£¡£¡£¡£
ÏÂÔØÁ´½Ó£º
https://www.paloaltonetworks.cn/
0x03 ²Î¿¼Á´½Ó
https://security.paloaltonetworks.com/CVE-2021-3050
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3050
https://nvd.nist.gov/vuln/detail/CVE-2021-3050
0x04 ¸üа汾
°æ±¾ | ÈÕÆÚ | ÐÞ¸ÄÄÚÈÝ |
V1.0 | 2021-08-12 | Ê×´ÎÐû²¼ |
0x05 Îĵµ¸½Â¼
CNVD£ºwww.cnvd.org.cn
CNNVD£ºwww.cnnvd.org.cn
CVE£ºcve.mitre.org
NVD£ºnvd.nist.gov
CVSS£ºwww.first.org
0x06 ¹ØÓÚ¼øºÚµ£±£Íø
¹Ø×¢ÒÔϹ«Öںţ¬£¬£¬£¬£¬»ñÈ¡¸ü¶à×ÊѶ£º