¡¾·ì϶¹«¸æ¡¿Sophos Firewall SQL×¢Èë·ì϶£¨CVE-2024-12727£©

°ä²¼¹¦·ò 2024-12-20

Ò»¡¢·ì϶¸ÅÊö


·ìϼûû³Æ

 Sophos Firewall SQL×¢Èë·ì϶

CVE   ID

CVE-2024-12727

·ì϶ÀàÐÍ

SQL×¢Èë 

·¢ÏÖ¹¦·ò

2024-12-20

·ì϶ÆÀ·Ö

9.8

·ì϶µÈ¼¶

¸ßΣ

¹¥»÷ÏòÁ¿

ÍøÂç

ËùÐèȨÏÞ

ÎÞ

ÀûÓÃÄѶÈ

µÍ

Óû§½»»¥

ÎÞ

PoC/EXP

δ¹«¿ª

ÔÚÒ°ÀûÓÃ

δ·¢ÏÖ

 


Sophos ·À»ðǽÊÇÓÉSophos ¹«Ë¾ÌṩµÄÒ»¿îÖ°ÄÜ׳´ó¡¢Ò×ÓÚÖÎÀíµÄÍøÂ簲ȫ²úÆ·£¬¼¯³ÉÁËNGFW¡¢VPN Ö§³Ö¡¢ATPµÈ¶àÖÖ°²È«Ö°ÄÜ£¬Ö¼ÔÚΪÆóÒµºÍ×éÖ¯Ìá¹©È«ÃæµÄÍøÂç±£»¤¡£


2024Äê12ÔÂ20ÈÕ£¬GA»Æ½ð¼×¼¯ÍÅVSRC¼à²âµ½Sophos ·À»ðǽÖдæÔÚÒ»¸öSQL×¢Èë·ì϶£¨CVE-2024-12727£©£¬¸Ã·ì϶µÄCVSSÆÀ·ÖΪ9.8¡£


Sophos Firewall 21.0 MR1£¨21.0.1£©Ö®Ç°°æ±¾µÄµç×ÓÓʼþ±£»¤Ö°ÄÜÖдæÔÚSQL×¢Èë·ì϶£¬ÓÉÓÚ·À»ðǽδÕýÈ·ÑéÖ¤»ò¹ýÂËÊäÈëÊý¾Ý£¬µ¼Ö¹¥»÷Õß¿Éͨ¹ý»ú¹Ø¶ñÒâ SQL ²éÎÊδÊÚȨ½Ó¼û»ã±¨Êý¾Ý¿â£¬ÈôÊÇ·À»ðǽÔËÐÐÔڸ߿ÉÓÃÐÔ (HA) ģʽ£¬ÇÒÆôÓÃÁË Secure PDF eXchange (SPX) µÄÌØ¶¨ÅäÖ㬹¥»÷Õß¿ÉÄܽøÒ»²½ÀûÓø÷ì϶µ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£


´Ë±í£¬Sophos ·À»ðǽÖл¹´æÔÚÒ»¸öÈõƾ֤·ì϶£¨CVE-2024-12728£¬CVSSÆÀ·Ö9.8£©£¬ÓÉÓڸ߿ÉÓÃÐÔ (HA) ¼¯Èº³õʼ»¯Ê±Ëù½¨ÒéµÄ·ÇËæ»úSSH µÇ¼ÃÜÂëÔÚHA³ÉÁ¢¹ý³ÌʵÏÖºóÒÀÈ»ÓÐЧ£¬ÈôÊÇ·À»ðǽÆôÓÃÁË SSH ·þÎñ£¬¹¥»÷Õß¿ÉÄÜÀûÓÃÕâ¸öÒÑÖªµÄÈõÃÜÂëͨ¹ýSSH µÇ¼£¬´Ó¶ø»ñµÃ¶ÔϵͳµÄÌØÈ¨½Ó¼û£»ÒÔ¼°ÔÚSophos ·À»ðǽÓû§ÃÅ»§£¨User Portal£©ÖдæÔÚÁíÒ»¸ö´úÂë×¢Èë·ì϶£¨CVE-2024-12729£¬CVSSÆÀ·Ö8.8£©£¬¾­¹ýÉí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÀûÓø÷ì϶µ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£


¶þ¡¢Ó°ÏìÁìÓò


Sophos Firewall <= v21.0 GA (21.0.0)


Èý¡¢°²È«´ëÊ©


3.1 Éý¼¶°æ±¾


ĿǰÕâЩ·ì϶ÒѾ­½¨¸´£¬ÊÜÓ°ÏìÓû§¿ÉÉý¼¶µ½ÒÔϰ汾£º


CVE-2024-12727

Sophos Firewall v21 GA¡¢v20 GA¡¢v20 MR1¡¢v20 MR2¡¢v20 MR3¡¢v19.5 MR3¡¢v19.5 MR4¡¢v19.0 MR2£ºÀûÓò¹¶¡»òÉý¼¶µ½ v21 MR1¼°¸ü¸ß°æ±¾¡£


CVE-2024-12728

Sophos Firewall v21 GA¡¢v20 GA¡¢v20 MR1¡¢v19.5 GA¡¢v19.5 MR1¡¢v19.5 MR2¡¢v19.5 MR3¡¢v19.5 MR4¡¢v19.0 MR2¡¢v20 MR2£ºÀûÓò¹¶¡»òÉý¼¶µ½v20 MR3¡¢v21 MR1 ¼°¸ü¸ß°æ±¾¡£


CVE-2024-12729

Sophos Firewall v21 GA¡¢v20 GA¡¢v20 MR1¡¢v20 MR2¡¢v19.5 GA¡¢v19.5 MR1¡¢v19.5 MR2¡¢v19.5 MR3¡¢v19.5 MR4¡¢v19.0 MR2¡¢v19.0 MR3¡¢v20 MR3£ºÀûÓò¹¶¡»òÉý¼¶µ½v21 MR1 ¼°¸ü¸ß°æ±¾¡£


ÏÂÔØÁ´½Ó£º

https://www.sophos.com/en-us/support/downloads


3.2 һʱ´ëÊ©


Õë¶ÔCVE-2024-12728£º

? È·±£ SSH ½Ó¼û½öÏÞÓÚרÓõġ¢ÎïÀíÉ϶ÀÁ¢µÄ HA Á´½Ó£¬¼´Í¨¹ýÒ»¸öרÃŵÄÍøÂçÏνÓÀ´½øÐÐ HA ÅäÖúÍÖÎÀí£¬¶ø²»ÊÇͨ¹ý¿í·ºµÄ SSH ½Ó¼û¡£

³ÁÐÂÅäÖà HA£¬Ê¹ÓÃÒ»¸ö×ã¹»³¤ÇÒËæ»úµÄ×Ô½ç˵ÃÜÂëÀ´´úÌæÄ¬ÈϵÄÈõÃÜÂ룬´Ó¶ø½µµÍÃÜÂë±»ÆÆ½âµÄ·çÏÕ¡£

½ûÓÃͨ¹ýWAN¶Ë¿ÚµÄ SSH ½Ó¼û£¬²¢¸ÄÓà VPN »ò Sophos Central ½øÐÐÔ¶³Ì½Ó¼ûºÍÖÎÀí¡£


Õë¶ÔCVE-2024-12729£º

½ûÓöÔÓû§ÃÅ»§ºÍ Webadmin µÄ WAN ½Ó¼û£¬²¢¸ÄÓà VPN »ò Sophos Central ½øÐÐÔ¶³Ì½Ó¼ûºÍÖÎÀí¡£


3.3 ͨÓý¨Òé


¶¨ÆÚ¸üÐÂϵͳ²¹¶¡£¬Ï÷¼õϵͳ·ì϶£¬ÌáÉý·þÎñÆ÷µÄ°²È«ÐÔ¡£

¼ÓǿϵͳºÍÍøÂçµÄ½Ó¼û½ÚÔ죬Åú¸Ä·À»ðǽսÊõ£¬¹Ø¹Ø·Ç±ØÒªµÄÀûÓö˿ڻò·þÎñ£¬Ï÷¼õ½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Â¶³öµ½¹«Íø£¬Ï÷¼õ¹¥»÷Ãæ¡£

ʹÓÃÆóÒµ¼¶°²È«²úÆ·£¬ÌáÉýÆóÒµµÄÍøÂ簲ȫ»úÄÜ¡£

¼ÓǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬ÆôÓöà³É·ÖÈÏÖ¤»úÔìºÍ×îÓ×ȨÏÞ×¼Ôò£¬Óû§ºÍÈí¼þȨÏÞӦά³ÖÔÚ×îµÍÏÞ¶È¡£

ÆôÓÃÇ¿ÃÜÂëÕ½Êõ²¢ÉèÖÃΪ¶¨ÆÚÅú¸Ä¡£


3.4 ²Î¿¼Á´½Ó


https://www.sophos.com/en-us/security-advisories/sophos-sa-20241219-sfos-rce

https://nvd.nist.gov/vuln/detail/CVE-2024-12727


ËÄ¡¢°æ±¾ÐÅÏ¢


°æ±¾

ÈÕÆÚ

±¸×¢

V1.0

2024-12-20

³õ´Î°ä²¼

 

Îå¡¢¸½Â¼


5.1 GA»Æ½ð¼×¼ò½é


GA»Æ½ð¼×³ÉÁ¢ÓÚ1996Ä꣬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ´´½¨µÄ¡¢Õ¼ÓÐÆëÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢°²È«¸ß¿Æ¼¼ÆóÒµ¡£ÊǹúÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢°²È«²úÆ·¡¢°²È«·þÎñ½â¾ö¹æ»®µÄÁ캽ÆóÒµÖ®Ò»¡£


¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°GA»Æ½ð¼×´óÏ㬹«Ë¾Ô±¹¤6000ÓàÈË£¬Ñз¢ÍŶÓ1200ÓàÈË, ¼¼Êõ·þÎñÍŶÓ1300ÓàÈË¡£ÔÚÈ«¹ú¸÷Ê¡¡¢ÊÓ×¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬Õ¼Óи²¸ÇÈ«¹úµÄÏúÊÛϵͳ¡¢Çþ·ϵͳºÍ¼¼ÊõÖ§³Öϵͳ¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐÓ×°å¹ÒÅÆÉÏÊС££¨¹ÉƱ´úÂ룺002439£©


¶àÄêÀ´£¬GA»Æ½ð¼×ÖÂÁ¦ÓÚÌṩӵÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷´´Ðµİ²È«²úÆ·ºÍ×î¼Ñʵ¼Ê·þÎñ£¬Ô®ÊÖ¿Í»§È«ÃæÌáÉýÆäIT»ù´¡ÉèÊ©µÄ°²È«ÐԺͳö²úЧÁ¦£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢°²È«²úÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸ÖÂÁ¦¡£


5.2 ¹ØÓÚGA»Æ½ð¼×


GA»Æ½ð¼×°²È«Ó¦¼±ÏìÓ¦ÖÐÐÄÒѰ䲼1000¶à¸ö·ì϶¹«¸æÎ¢·çÏÕÔ¤¾¯£¬ÎÒÃǽ«³ÖÐø¸ú×ÙÈ«Çò×îеÄÍøÂ簲ȫÊÂÎñºÍ·ì϶£¬ÎªÆóÒµµÄÐÅÏ¢°²È«±£¼Ý»¤º½¡£


¹Ø×¢ÎÒÃÇ£º


°²È«¼òѶ.jpg