Òø·å & ˼¿Æ & Citrix & VMware | SD-WAN°²È«·ì϶¹«¸æ

°ä²¼¹¦·ò 2020-12-02

0x00 ·ì϶¸ÅÊö

½üÈÕ£¬Realmode LabsµÄ×êÑÐÈËÔ±·¢ÏÖÁËÊг¡ÉÏÅÅÃûǰËĵÄSD-WANµÄ²úÆ·ÖдæÔÚ¶à¸ö°²È«·ì϶£¬Æä³§É̱ðÀëÎªÒø·å¡¢Ë¼¿Æ¡¢CitrixºÍVMware¡£ÔÚÕâ´Î·¢Ïֵķì϶ÖУ¬Óжà¸ö¿ÉÔì³ÉÔ¶³Ì´úÂëÖ´ÐУ¬ÇÒÎÞÐèÈκÎÉí·ÝÑéÖ¤¼´¿ÉÀûÓ᣹¥»÷ÕßÄܹ»ÀûÓÃÕâЩ·ì϶À´À¹½Ø»ò¶ñÒâÊèµ¼Á÷Á¿£¬ÉõÖÁ¿Éµ¼ÖÂÍøÂçÖжÏ¡£

 

0x01 ·ì϶ÏêÇé

image.png

                                                        

²úÆ·Ãû³Æ

CVE   ID

Àà   ÐÍ

·ì϶µÈ¼¶

Ô¶³ÌÀûÓÃ

Òø·åSD-WAN

CVE-2020-12145

Éí·ÝÑéÖ¤ÈÆ¹ý

ÑϳÁ

ÊÇ

CVE-2020-12146

õè¾¶±éÀú

¸ßΣ

ÊÇ

CVE-2020-12147

ËÁÒâSQL²éÎÊ

¸ßΣ

ÊÇ

Citrix SD-WAN

CVE-2020-8271

õè¾¶±éÀú¡¢Shell×¢Èë

ÑϳÁ

ÊÇ

CVE-2020-8272

Éí·ÝÑéÖ¤ÈÆ¹ý

¸ßΣ

ÊÇ

CVE-2020-8273

Shell×¢Èë

¸ßΣ

ÊÇ

˼¿ÆViptela vManage

 

 

CVE-2020-27128

SSRF¡¢ËÁÒâÎļþдÈë

ÖÐΣ

ÊÇ

CVE-2020-27129

ºÅÁî×¢Èë

ÖÐΣ

ÊÇ

CVE-2020-26073

Îļþ¶ÁÈ¡¡¢Ä¿Â¼±éÀú

¸ßΣ

ÊÇ

CVE-2020-26074

ȨÏÞÌáÉý

¸ßΣ

·ñ

VMware VeloCloud Orchestrator

CVE-2020-4001

Éí·ÝÑéÖ¤ÈÆ¹ý

ÖÐΣ

ÊÇ

CVE-2020-3984

SQL×¢Èë

¸ßΣ

ÊÇ

CVE-2020-4000

Ŀ¼±éÀú¡¢´úÂëÖ´ÐÐ

ÖÐΣ

ÊÇ

 

Òø·åµÄSD-WANÖдæÔÚÈý¸ö°²È«·ì϶£¬±ðÀëΪCVE-2020-12145¡¢CVE-2020-12146ºÍCVE-2020-12147£¬ÕâЩ·ì϶λÓÚOrchestratorÖ÷ÖÎÀí½çÃæ£¬¿É¼¯ÖнÚÔ칫˾µÄSD-WANÍØÆË¡£¹¥»÷Õ߿ɹ²Í¬ÀûÓÃÕâÈý¸ö·ì϶À´¶ÔSD-PWNÍøÂç½øÐй¥»÷¡£

Citrix SD-WANÒÔCakePHP2Ϊ¿ò¼ÜÔÚApacheÉÏÔËÐС£ÓÉÓÚCakePHP2¿ò¼ÜÔÚ´¦ÖÃURLʱ´æÔÚÎÊÌ⣬Citrix SD-WANÖÐÐÄ´æÔÚÈý¸ö°²È«·ì϶£¬±ðÀëΪCVE-2020-8271¡¢CVE-2020-8272ºÍCVE-2020-8273£¬³É¹¦ÀûÓ÷ì϶µÄ¹¥»÷Õß¿É×¢ÈëshellºÅÁ×îÖÕ½ÚÔìÕû¸öÍøÂç¡£

˼¿ÆViptela vManageÊÇ˼¿ÆSD-WAN»ù´¡¼Ü¹¹µÄÖÐÐÄ£¬¿ÉÖÎÀíÍøÂçÖÐËùÓÐÖÕ¶Ë¡£ÓÉÓÚSD-WANÉè¼ÆµÄ¼¯ÖÐÐÔ£¬´Ó°²È«½Ç¶ÈÀ´¿´£¬vManageÉϵĶà¸ö·ì϶ÊôÓÚµ¥µã¹ÊÕÏ¡£

ͨ¹ýÀûÓÃCVE-2020-27128¡¢CVE-2020-27129¡¢CVE-2020-26073ºÍCVE-2020-26074£¬¹¥»÷Õß¿ÉÄÜÔ¶³ÌÖ´ÐдúÂëÀ´»ñµÃvManageµÄ½ÚÔìȨ£¬¶ø¸ÃÖÕ¶Ëͨ³£ÍйÜÔÚÔÆ»·¾³ÖС£¹¥»÷Õß²»±ØÒªÈκÎÅäÖü´¿ÉÀûÓÃÕâЩ·ì϶¡£

VMware VeloCloud OrchestratorÊÇÏνӵ½±ßԵ·ÓÉÆ÷²¢¼¯ÖнÚÔìµÄÍøÂçÍØÆË¡£VMware VeloCloud»ù´¡¼Ü¹¹ÓÉnginx×é³É£¬ÆäÖØÒªÓÃ×÷node.js·þÎñÆ÷µÄ·´Ïò´úÀí£¬ÓÉÓÚÆä½Ó¿Ú´æÔÚ°²È«·ì϶£¬±ðÀëΪCVE-2020-4001¡¢CVE-2020-3984ºÍCVE-2020-4000¡£¹¥»÷ÕßÄܹ»ÀûÓÃÕâЩ·ì϶Åú¸ÄVelocloudµÇ¼Ãû»ò³ÁÖÃÃÜÂë¡£

 

²¿ÃÅ·ì϶ÏêÇéÈçÏ£º

Òø·åSD-WANÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶£¨CVE-2020-12145£©

ÓÉÓÚ¶ÔδִÐÐÉí·ÝÑéÖ¤µÄ±¾µØÖ÷»úµÄAPIŲÓõÄÌØÊâ´¦ÖôæÔÚ°²È«ÎÊÌ⣬ÈκÎÒÔ¡°localhost¡±×÷ΪÆäHTTP Host±êÍ·µÄÒªÇó¶¼Âú×ã²é³­ÒªÇó£¬ÕâÈÝÒ×µ¼ÖÂÉí·ÝÑéÖ¤ÈÆ¹ý¡£¿ÉʹÓÃrequest.getBaseUri().getHost().equals(¡°localhost¡±)ºÅÁî½øÐÐlocalhost²é³­¡£


Citrix SD-WANõè¾¶±éÀúºÍshell×¢Èë·ì϶£¨CVE-2020-8271£©

ÓÉÓÚ/collector/diagnostics/stop_ping¶Ëµã¶ÁÈ¡"/tmp/pid_" . $req_idÎļþ£¬²¢ÔÚshell_execŲÓÃÖÐʹÓÃÆäÄÚÈÝ£¬¶øÃ»ÓжÔÔÊÐíõè¾¶±éÀúµÄ$req_id½øÐÐËãÕÊ¡£¹¥»÷ÕßÄܹ»½«¶ñÒâÎļþÉÏ´«µ½Èκδ¦Ëù²¢Ö´ÐÐËÁÒâshellºÅÁî¡£

 

0x02 ´ëÖý¨Òé

ĿǰÓйس§ÉÌÒѾ­°ä²¼¸üУ¬½¨Òé²Î¿¼¹Ù·½µÄ½¨Òéʵʱ¸üС£

 

0x03 ²Î¿¼Á´½Ó

https://www.securityweek.com/sd-wan-product-vulnerabilities-allow-hackers-steer-traffic-shut-down-networks

https://medium.com/realmodelabs/sd-pwn-part-4-vmware-velocloud-the-last-takeover-a7016f9a9175

https://tools.cisco.com/security/center/publicationListing.x?product=Cisco&sort=-day_sir&offset=20#~Vulnerabilities

https://www.vmware.com/security/advisories/VMSA-2020-0025.html

 

0x04 ¹¦·òÏß

2020-12-01  VSRC°ä²¼°²È«¹«¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/



image.png