CVE-2020- 5135 | SonicOS»º³åÇøÒç¶Âí½Å¹«¸æ

°ä²¼¹¦·ò 2020-10-15

0x00 ·ì϶¸ÅÊö

CVE   ID

CVE-2020- 5135

ʱ   ¼ä

2020-10-15

Àà   ÐÍ

»º³åÇøÒç³ö

µÈ   ¼¶

¸ßΣ

Ô¶³ÌÀûÓÃ

ÊÇ

Ó°ÏìÁìÓò


 

SonicWallµÄSSL VPNÄܹ»Ê¹Ô¶³ÌÓû§°²È«µØÏνӺÍÔËÐй«Ë¾WindowsºÍLinuxϵͳ¼°ÍøÂçÉϵÄÈκÎÀûÓ÷¨Ê½ £¬Óû§Äܹ»ÇáËÉÉÏ´«ºÍÏÂÔØÎļþ¡¢×°ÖÃÍøÂçÇý¶¯Æ÷ÒÔ¼°½Ó¼û×ÊÔ´µÈ¡£SonicWallÍøÂ簲ȫÉ豸NSAÓµÓÐSSL VPN²¦ºÅÖ°ÄÜ £¬Äܹ»Í¨¹ýSSL VPN¿Í»§¶ËNextenderÔ¶³Ì½Ó¼û¹«Ë¾»òÄÚ²¿ÍøÂç¡£

 

0x01 ·ì϶ÏêÇé

image.png

 

2020Äê10ÔÂ12ÈÕ £¬SonicWall°ä²¼°²È«¹«¸æ £¬SonicWall NSAÓÃÓÚ²úÆ·ÖÎÀíºÍSSL VPNÔ¶³Ì½Ó¼ûµÄHTTP/HTTPS·þÎñÖдæÔÚÒ»¸ö»ùÓÚ²Ö¿âµÄ»º³åÇøÒç¶Âí½Å £¬·ì϶¸ú×ÙΪCVE-2020-5135¡£¹¥»÷ÕßÄܹ»Í¨¹ýÀûÓô˷ì϶Ïò·À»ðǽ·¢ËͶñÒâÒªÇóµ¼Ö»ؾø·þÎñ£¨DoS£©²¢Ö´ÐÐËÁÒâ´úÂë¡£

³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷Õß¿É×èÖ¹Óû§Ïνӵ½¹«Ë¾×ÊÔ´ £¬²¢µ¼ÖÂÉ豸±ÀÀ£µÈ¡£½ØÖÁĿǰ £¬ShodanËÑË÷µ½ÊÜÓ°ÏìµÄHTTP·þÎñÆ÷Ö÷»úΪ818 £¬694̨¡£

image.png

·ì϶ӰÏìÁìÓò£º

SonicOS 6.5.4.7-79n¼°¸üÔç°æ±¾

SonicOS 6.5.1.11-4n¼°¸üÔç°æ±¾

SonicOS 6.0.5.3-93o¼°¸üÔç°æ±¾

SonicOSv 6.5.4.4-44v-21-794¼°¸üÔç°æ±¾

SonicOS 7.0.0.0-1

 

0x02 ´ëÖý¨Òé

ĿǰSonicWallÒѰ䲼½¨¸´°æ±¾ £¬½¨ÒéʵʱÉý¼¶£º

SonicOS 6.5.4.7-83n

SonicOS 6.5.1.12-1n

SonicOS 6.0.5.3-94o

SonicOS 6.5.4.v-21s-987

µÚ7´ú7.0.0.0-2¼°¸ü¸ß°æ±¾

Á´½ÓµØÖ·£º

https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2020-0010

һʱ´ëÊ©£º

ÔÚÀûÓý¨²¹·¨Ê½Ö®Ç° £¬Äܹ»ÁÙʱ½«SSL VPNÓëInternet¶Ï¿ªÏνÓ¡£

 

0x03 ²Î¿¼Á´½Ó

https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2020-0010

https://www.tripwire.com/state-of-security/vert/sonicwall-vpn-portal-critical-flaw-cve-2020-5135/

https://threatpost.com/critical-sonicwall-vpn-bug/160108/

0x04 ¹¦·òÏß

2020-10-12  SonicWall³õ´Î°ä²¼°²È«²¼¸æ

2020-10-15  SonicWall°ä²¼¸üж©Õý

2020-10-15  VSRC°ä²¼°²È«¹«¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/

 

 

 

image.png