¡¾Îó²îͨ¸æ¡¿SonicWall Analytics Ô¶³Ì´úÂëÖ´ÐÐÎó²î (CVE-2021-20032)
Ðû²¼Ê±¼ä 2021-08-170x00 Îó²î¸ÅÊö
CVE ID | CVE-2021-20032 | ʱ ¼ä | 2021-08-10 |
Àà ÐÍ | RCE | µÈ ¼¶ | ÑÏÖØ |
Ô¶³ÌʹÓà | ÊÇ | Ó°Ïì¹æÄ£ | |
¹¥»÷ÖØÆ¯ºó | ¿ÉÓÃÐÔ | ||
Óû§½»»¥ | ËùÐèȨÏÞ | ||
PoC/EXP | δ¹ûÕæ | ÔÚҰʹÓà | ·ñ |
0x01 Îó²îÏêÇé
SonicWALL Analyzer ÊÇSonicWALLÍÆ³öµÄÓ¦ÓÃÁ÷Á¿ÆÊÎö½â¾ö¼Æ»®Ö®Ò»£¬£¬£¬£¬Ö§³ÖSonicWALL·À»ðǽµÈ²úÆ·¡£¡£¡£¡£AnalyzerÖ÷ҪΪITÖÎÀíÖ°Ô±ÌṩʵʱºÍÀúÊ·Ó¦ÓÃÁ÷Á¿ÆÊÎöÓëÇå¾²ÊÂÎñ±¨¸æ£¬£¬£¬£¬´Ó¶øÊ¹Æä¾ß±¸ÉîÈëÆÊÎöÍøÂçÐÔÄÜÓëÇå¾²µÄÄÜÁ¦¡£¡£¡£¡£
2021Äê8ÔÂ17ÈÕ£¬£¬£¬£¬SonicWALLÐû²¼Ç徲ͨ¸æ£¬£¬£¬£¬ÐÞ¸´ÁËSonicWall AnalyticsÖеÄÒ»¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-20032£©£¬£¬£¬£¬ÆäCVSSv3ÆÀ·ÖΪ9.8¡£¡£¡£¡£
ÓÉÓÚSonicWall Analytics On-Prem£¨ÍâµØ£©µÄijЩ°æ±¾ÖÐJava Debug Wire Protocol£¨JWDP£©½Ó¿ÚÇå¾²ÉèÖùýʧ£¬£¬£¬£¬Î´¾Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓôËÎó²îÔÚϵͳÉÏÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£
Ó°Ïì¹æÄ£
Analytics On-Prem <= 2.5.2518
0x02 ´¦Öóͷ£½¨Òé
ÏÖÔÚ´ËÎó²îÒѾÐÞ¸´¡£¡£¡£¡£½¨ÒéÊÜÓ°ÏìÓû§ÊµÊ±Éý¼¶¸üе½Analytics On-Prem 2.5.2519 »ò¸ü¸ß°æ±¾¡£¡£¡£¡£
ÔÝʱ»º½â²½·¥
×èÖ¹¶ÔÊÜÓ°Ïì°æ±¾ÉϵÄ9000/TCP¶Ë¿ÚµÄ»á¼û¡£¡£¡£¡£
×¢£ºSonicWall Analytics 2.5 ¼°¸üÔç°æ±¾µÄ°²ÅÅÊÇÍâµØ°²ÅÅ£¬£¬£¬£¬Ó¦Î»ÓÚÄÚ²¿Çå¾²ÍøÂç·Ö¶ÎÖС£¡£¡£¡£
ÏÂÔØÁ´½Ó£º
https://mysonicwall.com/
0x03 ²Î¿¼Á´½Ó
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0018
https://www.sonicwall.com/support/product-notification/?sol_id=210809113238240
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-20032
0x04 ¸üа汾
°æ±¾ | ÈÕÆÚ | ÐÞ¸ÄÄÚÈÝ |
V1.0 | 2021-08-17 | Ê×´ÎÐû²¼ |
0x05 Îĵµ¸½Â¼
CNVD£ºwww.cnvd.org.cn
CNNVD£ºwww.cnnvd.org.cn
CVE£ºcve.mitre.org
NVD£ºnvd.nist.gov
CVSS£ºwww.first.org
0x06 ¹ØÓÚ¼øºÚµ£±£Íø
¹Ø×¢ÒÔϹ«Öںţ¬£¬£¬£¬»ñÈ¡¸ü¶à×ÊѶ£º