Citrix²úÆ·¶à¸ö°²È«·ì϶¹«¸æ
°ä²¼¹¦·ò 2020-07-090x00 ·ì϶¸ÅÊö
2020Äê7ÔÂ7ÈÕ£¬Citrix¹Ù·½°ä²¼°²È«²¼¸æ£¬ÔÚCitrix ADC¡¢CitrixÍø¹ØºÍCitrix SD-WAN WANOP 4000-WO¡¢4100-WO¡¢5000-WOºÍ5100-WO°æ±¾Öз¢ÏÖÁ˶à¸ö·ì϶¡£ÏêÇé¼ûÏÂ±í£º
|
CVE ID |
·ì϶ÀàÐÍ |
Ó°Ïì²úÆ· |
¹¥»÷ÕßȨÏÞ |
ǰÌáǰÌá |
|
CVE-2019-18177 |
ID |
Citrix ADC, Citrix Gateway |
¾Éí·ÝÈÏÖ¤µÄVPNÓû§ |
±ØÒªÒ»¸öÅäÖõÄSSL VPNÖÕ¶Ë |
|
CVE-2020-8187 |
DOS |
Citrix ADC, Citrix Gateway 12.0 and 11.1°æ±¾ |
δ¾Éí·ÝÈÏÖ¤µÄÔ¶³ÌÓû§ |
±ØÒªÒ»¸öÅäÖõÄSSL VPN»òAAAÖÕ¶Ë |
|
CVE-2020-8190 |
EOP |
Citrix ADC, Citrix Gateway |
λÓÚNSIPÉϾÉí·ÝÈÏÖ¤µÄÓû§ |
¸Ã·ì϶ÎÞ·¨Ö±½Ó±»ÀûÓ᣹¥»÷Õß±ØÐëÊ×ÏÈÀûÓÃÁíÒ»¸ö·ì϶»ñÈ¡nobodyÕË»§È¨ÏÞ |
|
CVE-2020-8191 |
XSS |
Citrix ADC, Citrix Gateway, Citrix SDWAN WAN-OP |
δ¾Éí·ÝÈÏÖ¤µÄÔ¶³ÌÓû§ |
±ØÒªÊܺ¦ÕßÔÚä¯ÀÀÆ÷Öдò¿ªÓɹ¥»÷Õß½ÚÔìµÄÁ´½Ó£¬Í¬Ê±´¦ÓÚÏνÓNSIPµÄÍøÂçÉÏ |
|
CVE-2020-8193 |
AB |
Citrix ADC, Citrix Gateway, Citrix SDWAN WAN-OP |
ÓµÓÐNSIP½Ó¼ûȨÏ޵ģ¬Î´¾Éí·ÝÈÏÖ¤µÄÓû§ |
¹¥»÷Õß±ØÐë¿ÉÄܽӼû¸ÃNSIP |
|
CVE-2020-8194 |
CI |
Citrix ADC, Citrix Gateway, Citrix SDWAN WAN-OP |
δ¾Éí·ÝÈÏÖ¤µÄÔ¶³ÌÓû§ |
±ØÒªÊܺ¦Õß´Ó¸ÃNSIPÏÂÔØ²¢Ö´ÐжñÒâ¶þ½øÔìÎļþ |
|
CVE-2020-8195 |
ID |
Citrix ADC, Citrix Gateway, Citrix SDWAN WAN-OP |
λÓÚNSIPÉϾÉí·ÝÈÏÖ¤µÄÓû§ |
|
|
CVE-2020-8196 |
ID |
Citrix ADC, Citrix Gateway, Citrix SDWAN WAN-OP |
λÓÚNSIPÉϾÉí·ÝÈÏÖ¤µÄÓû§ |
|
|
CVE-2020-8197 |
EOP |
Citrix ADC, Citrix Gateway |
λÓÚNSIPÉϾÉí·ÝÈÏÖ¤µÄÓû§ |
|
|
CVE-2020-8198 |
XSS |
Citrix ADC, Citrix Gateway,Citrix SDWAN WAN-OP |
δ¾Éí·ÝÈÏÖ¤µÄÔ¶³Ì¹¥»÷Õß |
±ØÒªÊܺ¦Õß±ØÐëÔÚNSIPÉÏÒÔÖÎÀíÔ±£¨nsroot£©Éí·ÝµÇ¼ |
|
CVE-2020-8199 |
EOP |
Citrix Gateway Plug-in for Linux |
λÓÚLinuxÍÆËã»úÉÏÔËÐÐCitrix Gateway Plug-inµÄ±¾µØÓû§ |
±ØÐëÔËÐÐCitrix Gateway Plug-in for LinuxԤװ°æ±¾ |
´Ó±íÖÐÄܹ»¿´³ö£¬¹¥»÷»¹±ØÒªÄ³ÖÖ´ó¾ÖµÄ½Ó¼ûȨÏÞÄÜÁ¦ÀûÓÃÕâЩ·ì϶£¬ÕâÒâζ׏¥»÷ÕßÊ×ÏȱØÒª½Ó¼ûÖ¸±êϵͳÄÜÁ¦½øÐй¥»÷¡£
0x01 ·ì϶ÏêÇé
Citrix²úÆ·ÖØÒªÓÃÓÚÀûÓ÷¨Ê½µÄÁ÷Á¿ÖÎÀíºÍʵÏÖ°²È«µÄÔ¶³Ì½Ó¼û£¬²¢ÖÁÉÙÒÑÔÚ158¸ö¹ú¶ÈµÄ80000¼Ò¹«Ë¾ÖÐ×°Öá£
ÈôÊÇÕâЩ·ì϶Ôâµ½ÀûÓ㬿ÉÄܻᵼÖºܶలȫÎÊÌ⣬Ô̺¬±»ÓÃÓÚ»ñÊØÐÅÏ¢¡¢·¢Æð DoS ¹¥»÷¡¢ÊµÏÖ±¾µØÌáȨ¡¢·¢Æð XSS ¹¥»÷ºÍÈÆ¹ýÈÏÖ¤²¢×¢Èë¶ñÒâ´úÂë¡£
´Ë±í£¬ÔÚÓÃÓÚLinuxµÄCitrix Gateway²å¼þÖз¢ÏÖÁËÒ»¸ö·ì϶£¬×°ÖÃÁ˸òå¼þµÄLinuxϵͳµÄÓû§Äܹ»ÀûÓø÷ì϶½øÐб¾µØÌáȨ¡£
ƾ¾ÝCitrix°ä²¼µÄÐÅÏ¢£¬ÕâЩ·ì϶Óë¸Ã¹«Ë¾ÔÚ2020Äê1Ô½¨¸´µÄCVE-2019-19781Ô¶³Ì´úÂëÖ´Ðзì϶Î޹أ¬²»Ó°ÏìCitrixÉ豸µÄÔÆ°æ±¾¡£µ½Ä¿Ç°ÎªÖ¹»¹Ã»Óз¢ÏÖ¶ÔÕâЩ·ì϶µÄÀûÓ㬽¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ìÉý¼¶¡£
0x02 ´ëÖý¨Òé
Ŀǰ³§ÉÌÒѰ䲼²¹¶¡£¬ÏÂÁа汾µÄCitrix ADC¡¢CitrixÍø¹ØºÍCitrix SD-WAN WANOP½¨¸´ÁË·ì϶£º?
Citrix ADC and Citrix Gateway >= 13.0-58.30°æ±¾
Citrix ADC and NetScaler Gateway > 12.1°æ±¾£¬12.1-57.18°æ±¾
Citrix ADC and NetScaler Gateway > ?12.0°æ±¾£¬12.0-63.21°æ±¾
Citrix ADC and NetScaler Gateway > 11.1°æ±¾£¬11.1-64.14°æ±¾
NetScaler ADC and NetScaler Gateway > 10.5°æ±¾£¬10.5-70.18°æ±¾
Citrix SD-WAN WANOP >= 11.1.1a°æ±¾
Citrix SD-WAN WANOP > 11.0°æ±¾£¬11.0.3d°æ±¾
Citrix SD-WAN WANOP > 10.2°æ±¾£¬10.2.7°æ±¾
Citrix Gateway Plug-in for Linux >= ?1.0.0.137°æ±¾
½¨ÒéÊÜÓ°ÏìµÄ¿Í»§ÊµÊ±¸üУ¬ÏÂÔØÁ´½Ó£º
https://www.citrix.com/downloads/citrix-adc/
https://www.citrix.com/downloads/citrix-gateway/
https://www.citrix.com/downloads/citrix-sd-wan/
һʱ´ëÊ©£º
µ±Citrix ADCÉ豸²¿Êðµ½³ö²ú»·¾³Ê±£¬Citrix ½¨Òé½øÐÐÒÔÏÂÅäÖøü¸Ä£º
? ²»ÈÝCitrix ADC ÖÎÀíÔ±½Ó¿Ú(NSIP)½Ó¼ûInternet£»
? ´úÌæ Citrix ADC ĬÈÏSSLÖ¤Ê飻
? ʹÓÃHTTPS½Ó¼û GUI¡£
¸ü¶à¾ßÌåÐÅÏ¢£¬Çë²Î¿¼ÒÔÏÂÁ´½Ó£ºhttps://docs.citrix.com/zh-cn/citrix-adc/citrix-adc-secure-deployment/secure-deployment-guide.html
0x03 ÓйØÐÂÎÅ
https://threatpost.com/citrix-bugs-allow-unauthenticated-code-injection-data-theft/157214/
0x04 ²Î¿¼Á´½Ó
https://support.citrix.com/article/CTX276688
0x05 ¹¦·òÏß
2020-07-07 Citrix¹Ù·½°ä²¼°²È«²¼¸æ
2020-07-09 VSRC°ä²¼·ì϶¹«¸æ


¾©¹«Íø°²±¸11010802024551ºÅ