CVE-2020-2050 | PAN-OSÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶¹«¸æ
°ä²¼¹¦·ò 2020-11-120x00 ·ì϶¸ÅÊö
CNVD ID | CVE-2020-2050 | ʱ ¼ä | 2020-11-12 |
Àà ÐÍ | Éí·ÝÑéÖ¤ÈÆ¹ý | µÈ ¼¶ | ¸ßΣ |
Ô¶³ÌÀûÓà | ÊÇ | Ó°ÏìÁìÓò | <10.0.1 <9.1.5 <9.0.11 <8.1.17 |
0x01 ·ì϶ÏêÇé
2020Äê11ÔÂ11ÈÕ£¬Palo Alto Networks°ä²¼°²È«¹«¸æ£¬PAN-OSµÄGlobalProtect SSL VPN×é¼þÖдæÔÚÒ»¸öÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶£¨CVE-2020-2050£©£¬ÆäCVSSÆÀ·Ö8.2¡£
µ±Íø¹ØµÄÉí·ÝÑéÖ¤·½Ê½ÅäÖÃΪÆëÈ«»ùÓÚÖ¤Êéʱ£¬¹¥»÷ÕßÄܹ»ÀûÓô˷ìÏ¶ÈÆ¹ýËùÓÐʹÓÃÎÞЧ֤ÊéµÄ¿Í»§¶ËÖ¤Êé²é³£¬²¢¿ÉÄÜÒÔÈκÎÓû§µÄÉí·Ý½øÐÐÉí·ÝÑéÖ¤£¬×îÖÕ»ñµÃ¶ÔVPNÍøÂç×ÊÔ´µÄ½Ó¼ûȨÏÞ¡£
½«SSL VPNÅäÖÃΪ¿Í»§¶ËÖ¤ÊéÑéÖ¤Ó°ÏìµÄÖ°ÄÜÔ̺¬£º
GlobalProtect Gateway
GlobalProtect Portal
GlobalProtect Clientless VPN
ÔÚ½«¿Í»§¶ËÖ¤ÊéÑéÖ¤ÓëÆäËüÉí·ÝÑéÖ¤²½Öè½áºÏʹÓõÄÇé¿öÏ£¬´Ë·ì϶½«Ê¹µÃÖ¤ÊéÔö³¤µÄ±£»¤±»ºöÂÔ¡£
´Ë·ì϶»áÓ°ÏìʹÓÃGlobalProtect SSL VPN²¢½«Íø¹ØºÍÃÅ»§ÍøÕ¾ÅäÖÃΪÔÊÐíÓû§Ê¹Óÿͻ§¶ËÖ¤ÊéÉí·ÝÑéÖ¤µÄPAN OSÉ豸¡£´Ë±í£¬ÈôÊÇʹÓÃÁ˿ͻ§¶ËÖ¤ÊéÈÏÖ¤£¬Ôò»ùÓÚIPSecµÄVPNÒ²½«Êܵ½Ó°Ïì¡£ÈôÊÇδʹÓÿͻ§¶ËÖ¤Êé½øÐÐÉí·ÝÑéÖ¤£¬ÔòÎÞ·¨ÀûÓô˷ì϶¡£
0x02 ´ëÖý¨Òé
ĿǰPalo Alto NetworksÒѾ°ä²¼Á˸üа汾¡£½¨Òé²Î¿¼Ï±íʵʱÉý¼¶£º
°æ±¾ºÅ | ÊÜÓ°Ïì°æ±¾ | ¸üа汾 |
PAN OS 10.0 | <10.0.1 | > = 10.0.1 |
PAN OS 9.1 | <9.1.5 | > = 9.1.5 |
PAN OS 9.0 | <9.0.11 | > = 9.0.11 |
PAN OS 8.1 | <8.1.17 | > = 8.1.17 |
һʱ´ëÊ©£º
½«GlobalProtect SSL VPNÅäÖÃΪҪÇóÓû§Ê¹ÓÃÆäÆ¾Ö¤½øÐÐÉí·ÝÑéÖ¤¡£
ÏÂÔØÁ´½Ó£º
https://www.paloaltonetworks.com/search
0x03 ²Î¿¼Á´½Ó
https://security.paloaltonetworks.com/CVE-2020-2050
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-2050
0x04 ¹¦·òÏß
2020-11-11 Palo Alto Networks°ä²¼°²È«²¼¸æ
2020-11-12 VSRC°ä²¼°²È«¹«¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/


¾©¹«Íø°²±¸11010802024551ºÅ