¡¾·ì϶¹«¸æ¡¿TLStorm 2.0£ºAruba & Avaya»¥»»»úÔ¶³Ì´úÂëÖ´Ðзì϶

°ä²¼¹¦·ò 2022-05-05

0x00 ·ì϶¸ÅÊö

2022Äê5ÔÂ3ÈÕ £¬ArmisµÄ×êÑÐÈËÔ±Åû¶ÁËÔÚ Aruba ºÍ Avaya ¶àÖÖÐͺŵĻ¥»»»úÖз¢ÏÖµÄ5¸ö·ì϶ £¬ÕâЩ·ì϶ͳ³ÆÎª¡°TLStorm 2.0¡± £¬¿ÉÄܵ¼ÖÂÔÚÊÜÓ°ÏìµÄÉ豸ÉÏÔ¶³ÌÖ´ÐдúÂë¡£

 

0x01 ·ì϶ÏêÇé

TLStorm 2.0·ì϶ÓëTLS ¿â NanoSSLÓйأ¨NanoSSL ÊÇDigiCert µÄ×Ó¹«Ë¾MocanaÌṩµÄ×ÛºÏÐÔ¹ØÔ´ SSL Ì×¼þ£© £¬²¢´æÔÚÓÚAruba ºÍ Avaya ¶àÖÖ»¥»»»úÐͺŵÄTLS ͨѶִÐÐÖС£

ÔÚArubaÉ豸ÉÏ £¬NanoSSL±»ÓÃÓÚRadiusÉí·ÝÑéÖ¤ £¬Ò²±»ÓÃÓÚcaptive portalϵͳ£º

l  CVE-2022-23677£¨CVSS ÆÀ·Ö 9.0£©£ºNanoSSL ÔÚ¶à¸ö½Ó¿ÚÉϵÄÀÄÓà (RCE)£º¿ÉÄܵ¼ÖÂÔÚûÓÐЧ»§½»»¥µÄÇé¿öÏÂͨ¹ý»¥»»»úʵÏÖÔ¶³Ì´úÂëÖ´ÐС£

l  CVE-2022-23676£¨CVSS ÆÀ·Ö 9.1£©£ºRADIUS ¿Í»§¶ËÄÚ´æ°Ü»µ·ì϶£º¿ÉÄܵ¼Ö¹¥»÷Õß½ÚÔìµÄÊý¾ÝµÄ¶ÑÒç³ö £¬Õâ¿ÉÄÜÔÊÐí¶ñÒâµÄRADIUS·þÎñÆ÷ £¬»ò¿ÉÄܽӼûRADIUS¹²Ïí°ÂÃØµÄ¹¥»÷Õß £¬ÔÚ»¥»»»úÉÏÔ¶³ÌÖ´ÐдúÂë¡£

ÔÚAvayaÉ豸ÉÏ £¬¸Ã¿âµÄʵÏÖµ¼ÖÂÁË3¸ö°²È«·ì϶ £¬ÕâЩ·ì϶ÎÞÐèÉí·ÝÑéÖ¤»òÓû§½»»¥¼´¿ÉÀûÓãº

l  CVE-2022-29860£¨CVSS ÆÀ·Ö 9.8£©£ºTLS ³Á×é¶ÑÒç¶Âí½Å£ºÔÚ Web ·þÎñÆ÷ÉÏ´¦Öà POST ÒªÇóµÄ¹ý³ÌδÕýÈ·ÑéÖ¤ NanoSSL ·µ»ØÖµ £¬µ¼Ö¶ÑÒç³ö £¬´Ó¶øµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£

l  CVE-2022-29861£¨CVSS ÆÀ·Ö 9.8£©£ºHTTP Í·½âÎö²Ö¿âÒç¶Âí½Å£ºÔÚ´¦ÖöಿÃÅ±íµ¥Êý¾Ýʱ £¬²»ÕýÈ·µÄÌìǵ²é³­Óë·Ç¿ÕÖÕÖ¹µÄ×Ö·û´®Ïà½áºÏ»áµ¼Ö¹¥»÷Õß½ÚÔìµÄ²Ö¿âÒç³ö £¬¿ÉÄܵ¼Ö RCE¡£

l  HTTP POSTÒªÇó´¦ÖöÑÒç¶Âí½Å£ºÓÉÓÚ¶Ìȱ Mocana NanoSSL ¿âµÄÃýÎó²é³­ £¬ÔÚ´¦ÖÃHTTP POSTÒªÇóʱ´æÔÚ·ì϶ £¬µ¼Ö¹¥»÷Õß½ÚÔ쳤¶ÈµÄ¶ÑÒç³ö £¬¿ÉÄܵ¼ÖÂRCE¡£¸Ã·ì϶ÔÝÎÞCVE ID¡£

 

Ó°ÏìÁìÓò

Avaya ERS3500

Avaya ERS3600

Avaya ERS4900

Avaya ERS5900

Aruba 5400R Series

Aruba 3810 Series

Aruba 2920 Series

Aruba 2930F Series

Aruba 2930M Series

Aruba 2530 Series

Aruba 2540 Series

 

 

0x02 ´ëÖý¨Òé

ĿǰAruba£¨HPÕ¼ÓУ©ºÍ Avaya£¨ExtremeNetworks Õ¼ÓУ©ÒѾ­°ä²¼ÁË´óÎÞÊý·ì϶µÄ²¹¶¡ £¬½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ì¸üС£

Aruba£º

https://asp.arubanetworks.com/

Avaya£º

https://extremeportal.force.com/ExtrSupportHome

 

0x03 ²Î¿¼Á´½Ó

https://www.armis.com/blog/tlstorm-2-nanossl-tls-library-misuse-leads-to-vulnerabilities-in-common-switches/

https://www.bleepingcomputer.com/news/security/aruba-and-avaya-network-switches-are-vulnerable-to-rce-attacks/

https://www.darkreading.com/vulnerabilities-threats/tls-flaws-leave-avaya-aruba-switches-open-to-complete-takeover

 

0x04 ¸üа汾

°æ±¾

ÈÕÆÚ

Åú¸ÄÄÚÈÝ

V1.0

2022-05-05

³õ´Î°ä²¼

 

0x05 ¸½Â¼

GA»Æ½ð¼×¼ò½é

GA»Æ½ð¼×¹«Ë¾³ÉÁ¢ÓÚ1996Äê £¬²¢ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉî½»ËùÖÐÓ×°åÕýʽ¹ÒÅÆÉÏÊÐ £¬ÊǹúÄÚ¼«¾ßʵÁ¦µÄ¡¢Õ¼ÓÐÆëÈ«×ÔÖ÷֪ʶ²úȨµÄÍøÂ簲ȫ²úÆ·¡¢¿ÉÐŰ²È«ÖÎÀíÆ½Ì¨¡¢°²È«·þÎñÓë½â¾ö¹æ»®µÄ×ÛºÏÌṩÉÌ¡£

¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ° £¬ÔÚÈ«¹ú¸÷Ê¡¡¢ÊÓ×¢×ÔÖÎÇøÉèÓзÖÖ§»ú¹¹ £¬Õ¼Óи²¸ÇÈ«¹úµÄÇþ·ϵͳºÍ¼¼ÊõÖ§³ÖÖÐÐÄ £¬²¢ÔÚ±±¾©¡¢ÉϺ£¡¢³É¶¼¡¢¹ãÖÝ¡¢³¤É³¡¢º¼ÖÝµÈ¶àµØÉèÓÐÑз¢ÖÐÐÄ¡£

¶àÄêÀ´ £¬GA»Æ½ð¼×ÖÂÁ¦ÓÚÌṩӵÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷´´Ðµİ²È«²úÆ·ºÍ×î¼Ñʵ¼Ê·þÎñ £¬Ô®ÊÖ¿Í»§È«ÃæÌáÉýÆäIT»ù´¡ÉèÊ©µÄ°²È«ÐԺͳö²úЧÁ¦ £¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢°²È«²úÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸ÖÂÁ¦¡£

 

¹ØÓÚGA»Æ½ð¼×

GA»Æ½ð¼×°²È«Ó¦¼±ÏìÓ¦ÖÐÐÄÖØÒªÕë¶Ô³ÁÒª°²È«·ì϶µÄÔ¤¾¯¡¢¸ú×ٺͷÖÏíÈ«Çò×îеÄÍþвµý±¨ºÍ°²È«»ã±¨¡£

¹Ø×¢ÒÔϹ«¼ÒºÅ £¬»ñȡȫÇò×îа²È«×ÊѶ£º

image.png