¡¾Îó²îͨ¸æ¡¿Sophos FirewallÉí·ÝÑéÖ¤ÈÆ¹ýÎó²î£¨CVE-2022-1040£©

Ðû²¼Ê±¼ä 2022-03-28

0x00 Îó²î¸ÅÊö

CVE   ID

CVE-2022-1040

ʱ    ¼ä

2022-03-25

Àà    ÐÍ

Éí·ÝÑéÖ¤ÈÆ¹ý

µÈ    ¼¶

ÑÏÖØ

Ô¶³ÌʹÓÃ

ÊÇ

Ó°Ïì¹æÄ£


¹¥»÷ÖØÆ¯ºó

µÍ

Óû§½»»¥

ÎÞ

PoC/EXP


ÔÚҰʹÓÃ


 

0x01 Îó²îÏêÇé

Sophos FirewallÊÇSophos¹«Ë¾µÄ·À»ðǽ²úÆ·¡£¡£¡£¡£¡£

3ÔÂ25ÈÕ£¬£¬£¬£¬£¬£¬£¬SophosÐû²¼Ç徲ͨ¸æ£¬£¬£¬£¬£¬£¬£¬ÐÞ¸´ÁËÆä Sophos Firewall ²úÆ·ÖеÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2022-1040£©£¬£¬£¬£¬£¬£¬£¬¸ÃÎó²îµÄCVSSv3ÆÀ·ÖΪ9.8¡£¡£¡£¡£¡£

¸ÃÎó²îÊÇSophos Firewall µÄÓû§ÃÅ»§ºÍ Webadmin ÖеÄÉí·ÝÑéÖ¤ÈÆ¹ýÎó²î£¬£¬£¬£¬£¬£¬£¬¿ÉʹÓøÃÎó²îÈÆ¹ýÈÏÖ¤²¢Ö´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£

 

Ó°Ïì¹æÄ£

Sophos Firewall °æ±¾ <= 18.5 MR3 (18.5.3)

 

0x02 Çå¾²½¨Òé

ÏÖÔÚSophosÒѾ­Ðû²¼ÁËÏà¹ØÐÞ²¹³ÌÐò£¬£¬£¬£¬£¬£¬£¬ÆôÓÃÁË¡®ÔÊÐí×Ô¶¯×°ÖÃÐÞ²¹³ÌÐò¡¯¹¦Ð§µÄ Sophos Firewall ¿Í»§ÎÞÐèÖ´ÐÐÈκβÙ×÷£¨ÆôÓÃÊÇĬÈÏÉèÖã©¡£¡£¡£¡£¡£ÏÖÔÚÐû²¼µÄÐÞ²¹³ÌÐò°üÀ¨£º

l  2022 Äê 3 Ô 23 ÈÕÐû²¼µÄ v17.0 MR10 EAL4+¡¢v17.5 MR16 ºÍ MR17¡¢v18.0 MR5(-1) ºÍ MR6¡¢v18.5 MR1 ºÍ MR2 ÒÔ¼° v19.0 EAP µÄÐÞ²¹³ÌÐò£» £»£»£»£»£»

l  2022 Äê 3 Ô 23 ÈÕÐû²¼µÄ²»ÊÜÖ§³ÖµÄ EOL °æ±¾ v17.5 MR12 ÖÁ MR15 ÒÔ¼° v18.0 MR3 ºÍ MR4 µÄÐÞ²¹³ÌÐò£» £»£»£»£»£»

l  2022 Äê 3 Ô 24 ÈÕÐû²¼µÄ²»ÊÜÖ§³ÖµÄ EOL °æ±¾ v18.5 GA µÄÐÞ²¹³ÌÐò£» £»£»£»£»£»

l  2022 Äê 3 Ô 24 ÈÕÐû²¼µÄ v18.5 MR3 µÄÐÞ²¹³ÌÐò£» £»£»£»£»£»

l  v19.0 GA ºÍ v18.5 MR4 (18.5.4) ÖаüÀ¨µÄÐÞ¸´³ÌÐò£» £»£»£»£»£»

l  ¾É°æ±¾ Sophos Firewall µÄÓû§ÐèÒªÉý¼¶ÒÔ»ñµÃ×îеı£» £»£»£»£»£»¤ºÍ´ËÐÞ¸´¡£¡£¡£¡£¡£

ҪȷÈÏ´ËÐÞ²¹³ÌÐòÒÑÓ¦ÓÃÓÚÄúµÄ·À»ðǽ£¬£¬£¬£¬£¬£¬£¬Çë²Î¿¼£º

https://support.sophos.com/support/s/article/KB-000043853


»º½â²½·¥

¿Í»§¿ÉÒÔͨ¹ýÈ·±£ÆäÓû§ÃÅ»§ºÍ Webadmin ²»Ì»Â¶ÓÚ WAN À´±£» £»£»£»£»£»¤×Ô¼ºÃâÊÜÍⲿ¹¥»÷¡£¡£¡£¡£¡£

ƾ֤װ±¸»á¼û×î¼Ñʵ¼ù½ûÓöÔÓû§ÃÅ»§ºÍ Webadmin µÄ WAN »á¼û£¬£¬£¬£¬£¬£¬£¬¶øÊÇʹÓà VPN »ò Sophos Central ¾ÙÐÐÔ¶³Ì»á¼ûºÍÖÎÀí£¬£¬£¬£¬£¬£¬£¬Çë²Î¿¼£º

https://docs.sophos.com/nsg/sophos-firewall/18.5/Help/en-us/webhelp/onlinehelp/AdministratorHelp/Administration/DeviceAccess/index.html

 

0x03 ²Î¿¼Á´½Ó

https://www.sophos.com/en-us/security-advisories/sophos-sa-20220325-sfos-rce

https://nvd.nist.gov/vuln/detail/CVE-2022-1040

https://www.bleepingcomputer.com/news/security/critical-sophos-firewall-vulnerability-allows-remote-code-execution/

 

0x04 °æ±¾ÐÅÏ¢

°æ±¾

ÈÕÆÚ

ÐÞ¸ÄÄÚÈÝ

V1.0

2022-03-28

Ê×´ÎÐû²¼

 

0x05 ¸½Â¼

¼øºÚµ£±£Íø¼ò½é

¼øºÚµ£±£Íø¹«Ë¾½¨ÉèÓÚ1996Ä꣬£¬£¬£¬£¬£¬£¬²¢ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉî½»ËùÖÐС°åÕýʽ¹ÒÅÆÉÏÊУ¬£¬£¬£¬£¬£¬£¬ÊǺ£ÄÚ¼«¾ßʵÁ¦µÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÍøÂçÇå¾²²úÆ·¡¢¿ÉÐÅÇå¾²ÖÎÀíÆ½Ì¨¡¢Ç徲ЧÀÍÓë½â¾ö¼Æ»®µÄ×ÛºÏÌṩÉÌ¡£¡£¡£¡£¡£

¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°£¬£¬£¬£¬£¬£¬£¬ÔÚÌìϸ÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÓзÖÖ§»ú¹¹£¬£¬£¬£¬£¬£¬£¬ÓµÓÐÁýÕÖÌìϵÄÇþµÀϵͳºÍÊÖÒÕÖ§³ÖÖÐÐÄ£¬£¬£¬£¬£¬£¬£¬²¢ÔÚ±±¾©¡¢ÉϺ£¡¢³É¶¼¡¢¹ãÖÝ¡¢³¤É³¡¢º¼ÖÝµÈ¶àµØÉèÓÐÑз¢ÖÐÐÄ¡£¡£¡£¡£¡£

¶àÄêÀ´£¬£¬£¬£¬£¬£¬£¬¼øºÚµ£±£ÍøÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷Á¢ÒìµÄÇå¾²²úÆ·ºÍ×î¼Ñʵ¼ùЧÀÍ£¬£¬£¬£¬£¬£¬£¬×ÊÖú¿Í»§ÖÜÈ«ÌáÉýÆäIT»ù´¡ÉèÊ©µÄÇå¾²ÐÔºÍÉú²úЧÄÜ£¬£¬£¬£¬£¬£¬£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Çå¾²¹¤ÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸Æð¾¢¡£¡£¡£¡£¡£


¹ØÓÚ¼øºÚµ£±£Íø

¼øºÚµ£±£ÍøÇå¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÖ÷ÒªÕë¶ÔÖ÷ÒªÇå¾²Îó²îµÄÔ¤¾¯¡¢¸ú×ٺͷÖÏíÈ«Çò×îеÄÍþвÇ鱨ºÍÇå¾²±¨¸æ¡£¡£¡£¡£¡£

¹Ø×¢ÒÔϹ«Öںţ¬£¬£¬£¬£¬£¬£¬»ñȡȫÇò×îÐÂÇå¾²×ÊѶ£º

image.png