Pulse Connect SecureËÁÒâ´úÂëÖ´Ðзì϶£¨CVE-2021-22908£©
°ä²¼¹¦·ò 2021-05-250x00 ·ì϶¸ÅÊö
CVE ID | CVE-2021-22908 | ʱ ¼ä | 2021-05-25 |
Àà ÐÍ | ´úÂëÖ´ÐÐ | µÈ ¼¶ | ¸ßΣ |
Ô¶³ÌÀûÓà | ÊÇ | Ó°ÏìÁìÓò | 9.0RX¡¢9.1RX |
PoC/EXP | δ¹«¿ª | ÔÚÒ°ÀûÓà | ·ñ |
0x01 ·ì϶ÏêÇé

Pulse Connect Secure£¨PCS£©ÊÇÃÀ¹úPulse Secure¹«Ë¾µÄÒ»Ì×SSL VPN½â¾ö¹æ»®¡£
2021Äê05ÔÂ24ÈÕ£¬¿¨ÄÚ»ù÷¡´óѧÅû¶ÁËPulse Connect SecureÖеÄÒ»¸ö»º³åÇøÒç¶Âí½Å£¨CVE-2021-22908£©£¬¸Ã·ì϶µÄCVSSÆÀ·ÖΪ8.5¡£¾¹ýÉí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓô˷ì϶ÔÚÊÜÓ°ÏìµÄPCS·þÎñÆ÷ÉÏÒÔrootȨÏÞÖ´ÐÐËÁÒâ´úÂë¡£
·ì϶ϸ½Ú
ÓÉÓÚPCSÖ§³ÖÏνӵ½WindowsÎļþ¹²Ïí£¨SMB£©µÄÖ°ÄÜÓÉ»ùÓÚSamba 4.5.10µÄ¿âºÍ¸¨ÖúÀûÓ÷¨Ê½µÄCGI¾ç±¾Ìṩ¡£µ±ÎªÄ³Ð©SMB²Ù×÷Ö¸¶¨Ò»¸ö³¤µÄ·þÎñÆ÷Ãû³ÆÊ±£¬smbcltÀûÓ÷¨Ê½¿ÉÄÜ»áÓÉÓÚ»º³åÇøÒç³ö¶ø±ÀÀ££¬¾ßÌåÈ¡¾öÓÚÖ¸¶¨µÄ·þÎñÆ÷Ãû³Æ³¤¶È¡£
ÒѾȷÈÏPCS 9.1R11.4ϵͳ´æÔÚ´Ë·ì϶£¬Ö¸±êCGI¶ËµãΪ/dana/fb/smb/wnf.cgi£¬ÆäËüCGI¶ËµãÒ²¿ÉÄܻᴥ·¢´Ë·ì϶¡£
ÈôÊǹ¥»÷ÕßÔڳɹ¦ÀûÓô˷ì϶ºóûÓнøÐÐËãÕÊ£¬ÔòÖ¸¶¨Ò»¸ö³¤µÄ·þÎñÆ÷Ãû³Æ¿ÉÄܻᵼÖÂÈçÏÂPCSÊÂÎñÈÕÖ¾Ìõ¿î£º
Critical ERR31093 2021-05-24 14:05:37 - ive - [127.0.0.1] Root::System()[] - Program smbclt recently failed.
µ«ÒªÀûÓô˷ì϶£¬PCS·þÎñÆ÷±ØÐëÓÐÒ»¸öallows \\*µÄWindowsÎļþ½Ó¼ûÕ½Êõ»òÔÊÐí¹¥»÷ÕßÏνӵ½ËÁÒâ·þÎñÆ÷µÄÆäËüµÄÕ½Êõ¡£Äܹ»ÔÚPCSµÄÖÎÀíÒ³ÃæÖУ¬²é¿´Óû§->×ÊÔ´Õ½Êõ->WindowsÎļþ½Ó¼ûÕ½Êõ£¬À´²é¿´µ±Ç°µÄSMBÕ½Êõ¡£9.1R2¼°Ö®Ç°µÄPCSÉ豸ʹÓÃÔÊÐíÏνӵ½ËÁÒâSMBÖ÷»úµÄĬÈÏÕ½Êõ£¬´Ó9.1R3ÆðÍ·£¬Õâ¸öÕ½Êõ´ÓĬÈÏÔÊÐí¸ü¸ÄΪĬÈϻؾø¡£
Ó°ÏìÁìÓò
Pulse Connect Secure 9.0RXºÍ9.1RX
0x02 ´ëÖý¨Òé
Pulse SecureÔ¤¼ÆÔÚPulse Connect Secure 9.1R11.5»ò¸ü¸ß°æ±¾Öн¨¸´¸Ã·ì϶£¬µ«Ä¿Ç°ÉÐδ°ä²¼¡£
ÏÂÔØÁ´½Ó£º
https://my.pulsesecure.net/
0x03 ²Î¿¼Á´½Ó
https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44800
https://kb.cert.org/vuls/id/667933
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-22908
0x04 ¹¦·òÏß
2021-05-24 ¿¨ÄÚ»ù÷¡´óѧÅû¶·ì϶
2021-05-25 VSRC°ä²¼°²È«¹«¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/



¾©¹«Íø°²±¸11010802024551ºÅ