CVE-2020-2021 | PAN-OS SAMLÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶¹«¸æ

°ä²¼¹¦·ò 2020-06-30

0x00 ·ì϶¸ÅÊö



CVE   ID

CVE-2020-2021

ʱ    ¼ä

2020-06-30

Àà  ÐÍ

AB

µÈ    ¼¶

ÑϳÁ

Ô¶³ÌÀûÓÃ

ÊÇ

Ó°ÏìÁìÓò


0x01 ·ì϶ÏêÇé


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


2020Äê6ÔÂ29ÈÕ £¬Palo Alto Networks¹Ù·½°ä²¼°²È«²¼¸æ £¬½¨¸´ÁËÒ»¸öPAN-OS SAMLÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶£¨CVE-2020-2021£© ¡£¹¥»÷ÕßÎÞÐè¾­¹ýÉí·ÝÑéÖ¤¼´¿ÉÀûÓø÷ì϶½Ó¼ûÉ豸 ¡£

ÔÚÆôÓð²È«ÐÔ¶ÏÑÔÏóÕ÷˵»°£¨SAML£©Éí·ÝÑéÖ¤²¢½ûÓá°ÑéÖ¤Éí·ÝÌṩÉÌÖ¤Ê顱ѡÏîʱ £¬ÓÉÓÚPAN-OS SAMLÉí·ÝÑéÖ¤¹ý³ÌÖÐûÓÐÕýÈ·µØÑéÖ¤ÊðÃû £¬µ¼ÖÂδ¾­Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÄܹ»¸ü¸ÄPAN OSµÄÉèÖúÍÖ°ÄÜ ¡£Ç°ÌáǰÌáÊǹ¥»÷Õß±ØÐëÄܹ»½Ó¼ûÒ×Êܹ¥»÷µÄ·þÎñÆ÷ £¬ÄÜÁ¦ÀûÓô˷ì϶ ¡£


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¸Ã·ì϶ÊÇÔÚCVSSv3ÑϳÁµÈ¼¶ÖлñµÃ10·ÖµÄº±¼û·ì϶֮һ £¬¼È²»±ØÒª¸ß¼¶¼¼Êõ¼¼Êõ £¬ÓÖÄܹ»Í¨¹ýInternet½øÐÐÔ¶³ÌÀûÓà ¡£ÃÀ¹úÍøÂç˾ÁҪÇóËùÓÐÊÜCVE-2020-2021Ó°ÏìµÄÉ豸µ±¼´½¨¸´¸Ã·ì϶ £¬²¢°µÊ¾±í¹úµÄAPT×éÖ¯¿ÉÄܺܿì¾Í»á³¢ÊÔÀûÓø÷ì϶ÌáÒé¹¥»÷ ¡£

Äܹ»Í¨¹ý»ùÓÚSAMLµÄµ¥µãµÇ¼£¨SSO£©Éí·ÝÑéÖ¤±£»¤µÄ×ÊÔ´ÓУº

GlobalProtect Gateway,

GlobalProtect Portal,

GlobalProtect Clientless VPN,

Authentication and Captive Portal,

PAN-OS next-generation firewalls (PA-Series, VM-Series) and Panorama web interfaces

Prisma Access

¶ÔÓÚGlobalProtectÍø¹Ø¡¢GlobalProtectÃÅ»§¡¢ÎÞ¿Í»§¶ËVPN¡¢Captive PortalºÍPrisma Access £¬Î´¾­Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÄܹ»Í¨¹ýÍøÂç½Ó¼û·þÎñÆ÷ÉÏÊܱ£»¤µÄ×ÊÔ´ £¬²»»áÓ°ÏìÍø¹Ø £¬ÃÅ»§»òVPN·þÎñÆ÷µÄÆëÈ«ÐԺͿÉÓÃÐÔ £¬µ«¹¥»÷ÕßÎÞ·¨²é³­»ò´Û¸Äͨ³£Óû§µÄ»á»° ¡£ÕâÊÇÒ»¸öÑϳÁ¼¶´ËÍâ·ì϶ £¬CVSSÆÀ·Ö10.0 ¡£

¶ÔÓÚPAN-OSºÍPanorama Web½çÃæ £¬ÈôÊÇδ¾­Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÓµÓжÔPAN-OS»òPanorama Web½çÃæµÄ½Ó¼ûȨ £¬¼´Äܹ»ÖÎÀíÔ±Éí·ÝµÇ¼²¢Ö´ÐÐÖÎÀí²Ù×÷ ¡£ÕâÊÇÒ»¸öÑϳÁ¼¶´ËÍâ·ì϶ £¬CVSSÆÀ·Ö10.0 £¬ÈôÊǽö¿Éͨ¹ýÊÜÏÞÖÎÀíÍøÂç½Ó¼ûWeb½çÃæ £¬ÔòCVSSÆÀ·Ö9.6 ¡£

ÒÔÏÂÊÇCVE-2020-2021·ì϶ӰÏìµÄPalo Alto Networks PAN-OS°æ±¾£º


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾



ÇëÓйØÓû§¾¡¿ì²é¿´ÅäÖà £¬ÊµÊ±È·ÈÏÊÇ·ñÊܵ½¸Ã·ì϶ӰÏì £¬¾ßÌå²½ÖèÈçÏ£º

? ½öµ±ÆôÓÃÁËSAMLÉí·ÝÑéÖ¤²¢ÇÒÔÚ¡°SAMLÉí·ÝÌṩÉÌ·þÎñÆ÷ÅäÖÃÎļþ¡±ÖнûÓá°Éí·ÝÌṩÉÌÖ¤Ê顱ѡÏîʱ £¬ÄÜÁ¦¹»ÀûÓø÷ì϶ ¡£

? ÈôÊDz»Ê¹ÓÃSAML½øÐÐÉí·ÝÑéÖ¤ £¬ÔòÎÞ·¨ÀûÓø÷ì϶ ¡£

? ÈôÊÇÔÚSAMLÉí·ÝÌṩÉÌ·þÎñÆ÷ÅäÖÃÎļþÖÐÆôÓÃÁË¡°ÑéÖ¤Éí·ÝÌṩÉÌÖ¤Ê顱ѡÏî £¬ÔòÎÞ·¨ÀûÓø÷ì϶ ¡£

¹ØÓÚÈôºÎ²é³­·þÎñÆ÷ÅäÖò¢Ö´Ðлº½â´ëÊ©µÄ×¢Ã÷ £¬Çë²Î¿¼£ºhttps://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000008UXK

? Òª²é³­ÊÇ·ñÔÚ·À»ðǽÉÏÆôÓÃÁËSAMLÉí·ÝÑéÖ¤ £¬Çë²Î¿¼Device > Server Profiles > SAML Identity Provider£»

? Òª²é³­ÊÇ·ñΪPanoramaÖÎÀíÔ±Éí·ÝÑéÖ¤ÆôÓÃÁËSAMLÉí·ÝÑéÖ¤ £¬Çë²Î¿¼Panorama >Server Profiles > SAML Identity Provider£»

? Òª²é³­ÊÇ·ñΪPanoramaÖÎÀíµÄ·À»ðǽÆôÓÃÁËSAMLÉí·ÝÑéÖ¤ £¬Çë²Î¿¼Device > [template]> Server Profiles > SAML Identity Provider ¡£

ƾ¾ÝÅäÖà £¬ÈκÎδ¾­ÊÚȨµÄ½Ó¼û³ÇÊмͼÔÚϵͳÈÕÖ¾ÖÐ £¬µ«ÊǺÜÄÑ·Ö±æÓÐЧµÇ¼ÃûºÍ¶ñÒâµÇ¼Ãû ¡£


0x02 ´ëÖý¨Òé


¹Ù·½ÒѰ䲼PAN-OS 8.1.15¡¢PAN-OS 9.0.9¡¢PAN-OS 9.1.3ºÍ¸ü¸ß°æ±¾ £¬ÇëÓйØÓû§ÊµÊ±Éý¼¶ ¡£

°ÑÎÈ£ºÔÚÉý¼¶µ½¹Ì¶¨°æ±¾Ö®Ç° £¬ÇëÈ·±£½«SAMLÉí·ÝÌṩÉ̵ÄÊðÃûÖ¤ÊéÅäÖÃΪ¡°Éí·ÝÌṩÉÌÖ¤Ê顱 £¬ÒÔÈ·±£Óû§Äܹ»³ÖÐø½øÐÐÉí·ÝÑéÖ¤ ¡£Çë²Î¿¼£ºhttps://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/authentication/configure-saml-authentication

? PAN-OSÉý¼¶Ö®Ç°ºÍÖ®ºóËùÐèµÄËùÓвÙ×÷µÄ¾ßÌåÐÅÏ¢ £¬Çë²Î¿¼£ºhttps://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000008UXK

? ΪÁ˶ϸùGlobalProtectÃÅ»§ºÍÍø¹ØÉϵÄδÊÚȨ»á»° £¬Prisma Accessͨ¹ýPanoramaÖÎÀí £¬ÇëʹÓÃPanorama¸ü¸ÄAuthentication Override cookieµÄÅäÖà ¡£Çë²Î¿¼£ºhttps://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000008UXy

³ÁÐÂÆô¶¯·À»ðǽºÍPanoramaÄܹ»¶Ï¸ùWeb½çÃæÉϵÄÈκÎδ¾­ÊÚȨµÄ»á»° ¡£

? Òª¶Ï¸ùCaptive PortalÖеÄÈκÎδÊÚȨÓû§»á»° £¬ÇëÖ´ÐÐÒÔϲ½Ö裺

ÔËÐÐÒÔϺÅÁî

show user ip-user-mapping all type SSO

¶ÔÓÚ·µ»ØµÄËùÓÐIP £¬ÇëÔËÐÐÒÔÏÂÁ½¸öºÅÁîÒԶϸùÓû§£º

clear user-cache-mp

clear user-cache

? PAN-OS 8.0ÒÑÖÕÖ¹Ö§³Ö£¨½ØÖÁ2019Äê10ÔÂ31ÈÕ£© £¬²»ÔÙÊØ»¤ ¡£

ËùÓÐPrisma Access·þÎñ¾ùÒÑÉý¼¶ÒÔ½â¾ö´ËÎÊÌâ £¬²¢ÇÒ²»ÔÙÒ×Êܹ¥»÷ ¡£Prisma Access¿Í»§²»±ØÒª¶ÔSAML»òIdPÅäÖýøÐÐÈκθü¸Ä ¡£

һʱ´ëÊ©£º

? ʹÓÃÆäËûÉí·ÝÑéÖ¤²½Öè²¢½ûÓÃSAMLÉí·ÝÑéÖ¤£»

? ÔÚÖ´ÐÐÉý¼¶Ö®Ç° £¬Í¬Ê±ÀûÓã¨a£©ºÍ£¨b£©Á½Ï½â´ëÊ© ¡£

£¨a£©È·±£ÒÑÅäÖá°Éí·ÝÌṩÉÌÖ¤Ê顱 ¡£ÅäÖá°Éí·ÝÌṩÉÌÖ¤Ê顱Êǰ²È«SAMLÉí·ÝÑéÖ¤ÅäÖõijÁÒª×é³É²¿ÃÅ ¡£

£¨b£©ÈôÊÇÉí·ÝÌṩÉÌ£¨IDP£©Ö¤ÊéÊÇÖ¤ÊéÐû¸æ»ú¹¹£¨CA£©ÊðÃûµÄÖ¤Êé £¬ÔòÈ·±£ÔÚSAMLÉí·ÝÌṩÉÌ·þÎñÆ÷ÅäÖÃÎļþÖÐÆôÓÃÁË¡°Éí·ÝÌṩÉÌÖ¤Ê顱ѡÏî ¡£Ä¬ÈÏÇé¿öÏ £¬ºÜ¶àÊ¢ÐеÄIDP³ÇÊÐÌìÉú×ÔÊðÃûIDPÖ¤Êé £¬²¢ÇÒÎÞ·¨ÆôÓá°ÑéÖ¤Éí·ÝÌṩÉÌÖ¤Ê顱ѡÏî ¡£ÒªÊ¹ÓÃÓÉCAÊðÃûµÄÖ¤Êé £¬¿ÉÄܱØÒªÖ´ÐÐÆäËû²½Öè ¡£¸ÃÖ¤ÊéÄܹ»ÓÉÄÚ²¿ÆóÒµCA £¬PAN OSÉϵÄCA»ò¹«¹²CAÊðÃû ¡ £¿ÉÔÚhttps://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000008UXPÉÏ»ñÈ¡ÓйØÔÚIDPÉÏÅäÖÃCAÐû¸æµÄÖ¤ÊéµÄ×¢Ã÷ ¡£


0x03 ÓйØÐÂÎÅ


https://www.zdnet.com/article/us-cyber-command-says-foreign-hackers-will-most-likely-exploit-new-pan-os-security-bug/


0x04 ²Î¿¼Á´½Ó


https://security.paloaltonetworks.com/CVE-2020-2021?from=timeline&isappinstalled=0


0x05 ¹¦·òÏß


2020-06-29 Palo Alto Networks°ä²¼°²È«²¼¸æ

2020-06-30 VSRC°ä²¼·ì϶¹«¸æ


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾