¡¾·ì϶¹«¸æ¡¿SolarWinds Serv-U Ô¶³Ì´úÂëÖ´ÐÐ0 day·ì϶£¨CVE-2021-35211£©
°ä²¼¹¦·ò 2021-07-130x00 ·ì϶¸ÅÊö
CVE ID | CVE-2021-35211 | ʱ ¼ä | 2021-07-13 |
Àà ÐÍ | RCE | µÈ ¼¶ | ¸ßΣ |
Ô¶³ÌÀûÓà | ÊÇ | Ó°ÏìÁìÓò | < 15.2.3 HF2 |
¹¥»÷¸´ÔÓ¶È | ¿ÉÓÃÐÔ | ||
Óû§½»»¥ | ËùÐèȨÏÞ | ||
PoC/EXP | ÔÚÒ°ÀûÓÃ | ÊÇ |
0x01 ·ì϶ÏêÇé

2021Äê7ÔÂ9ÈÕ£¬SolarWinds°ä²¼°²È«²¼¸æ£¬MicrosoftÔÚÆäServ-U²úÆ·Öз¢ÏÖÁËÒ»¸öÔ¶³Ì´úÂëÖ´ÐÐ0 day·ì϶£¨CVE-2021-35211£©£¬³É¹¦ÀûÓô˷ì϶µÄÔ¶³Ì¹¥»÷Õß¿ÉÄÜÒÔÌØÊâȨÏÞÖ´ÐÐËÁÒâ´úÂ룬¶øºóÔÚÊÜÓ°ÏìµÄϵͳÉÏ×°Öò¢ÔËÐз¨Ê½¡¢²é¿´¡¢¸ü¸Ä»òɾ³ýÊý¾ÝµÈ¡£Ä¿Ç°¸Ã·ì϶ÒѾ³Ê´Ë¿ÌÒ°ÀûÓá£
¸Ã·ì϶½ö´æÔÚÓÚSolarWinds Serv-U Managed File TransferºÍServ-U Secure FTPÖУ¬ÆäËü SolarWinds ²úÆ·²»ÊÜÓ°Ï죬²»Ê¹Óà Serv-U µÄ N-able ¿Í»§Ò²²»ÊÜ´Ë·ì϶µÄÓ°Ïì¡£µ«±ØÒª°ÑÎȵÄÊÇ£¬Serv-U GatewayÊÇÕâÁ½¸ö²úÆ·µÄÒ»¸ö×é¼þ£¬¶ø²»ÊÇÒ»¸öµ¥¶ÀµÄ²úÆ·¡£
´Ë±í£¬¾ÝSolarWinds°µÊ¾£¬ÈôÊÇServ-U »·¾³ÖÐδÆôÓà SSH£¬Ôò¸Ã·ì϶²»´æÔÚ¡£
Ó°ÏìÁìÓò
Serv-U °æ±¾ < 15.2.3 HF2
0x02 ´ëÖý¨Òé
Ŀǰ´Ë·ì϶ÒÑÔÚ2021 Äê 7 Ô 9 ÈÕ°ä²¼µÄServ-U 15.2.3 HF2Öн¨¸´£¬½¨ÒéËùÓÐÊÜÓ°ÏìµÄServ-U ¿Í»§²Î¿¼ÒÔÏ·½Ê½ÊµÊ±Éý¼¶¸üУº
Serv-U 15.2.3 HF1°æ±¾£ºÖ±½ÓÉý¼¶¸üÐÂÖÁServ-U 15.2.3 HF2 £»
Serv-U 15.2.3°æ±¾£ºÏÈÉý¼¶¸üÐÂÖÁServ-U 15.2.3 HF1 £¬¶øºóÔÙÉý¼¶¸üÐÂÖÁServ-U 15.2.3 HF2 £»
15.2.3 ֮ǰµÄËùÓÐServ-U °æ±¾£ºÏÈÉý¼¶¸üÐÂÖÁServ-U 15.2.3 £¬ÔÙÉý¼¶¸üÐÂÖÁServ-U 15.2.3 HF1 £¬¶øºóÔÙÉý¼¶¸üÐÂÖÁ Serv-U 15.2.3 HF2 ¡£
ÏÂÔØÁ´½Ó£º
https://www.serv-u.com/
0x03 ²Î¿¼Á´½Ó
https://www.solarwinds.com/trust-center/security-advisories/cve-2021-35211
https://www.bleepingcomputer.com/news/security/solarwinds-patches-critical-serv-u-vulnerability-exploited-in-the-wild/
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-35211
0x04 ¸üа汾
°æ±¾ | ÈÕÆÚ | Åú¸ÄÄÚÈÝ |
V1.0 | 2021-07-13 | ³õ´Î°ä²¼ |
0x05 Îĵµ¸½Â¼
CNVD¹ÙÍø£ºwww.cnvd.org.cn
CNNVD¹ÙÍø£ºwww.cnnvd.org.cn
CVE¹ÙÍø£ºcve.mitre.org
NVD¹ÙÍø£ºnvd.nist.gov
CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºwww.first.org
0x06 ¹ØÓÚGA»Æ½ð¼×
¹Ø×¢ÒÔϹ«¼ÒºÅ£¬»ñÈ¡¸ü¶à×ÊѶ£º



¾©¹«Íø°²±¸11010802024551ºÅ