CVE-2020-2050 | PAN-OSÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶¹«¸æ

°ä²¼¹¦·ò 2020-11-12

0x00 ·ì϶¸ÅÊö

CNVD   ID

CVE-2020-2050

ʱ      ¼ä

2020-11-12

Àà    ÐÍ

Éí·ÝÑéÖ¤ÈÆ¹ý

µÈ      ¼¶

¸ßΣ

Ô¶³ÌÀûÓÃ

ÊÇ

Ó°ÏìÁìÓò

<10.0.1

<9.1.5

 <9.0.11

 <8.1.17

 

0x01 ·ì϶ÏêÇé

image.png 

2020Äê11ÔÂ11ÈÕ£¬Palo Alto Networks°ä²¼°²È«¹«¸æ£¬PAN-OSµÄGlobalProtect SSL VPN×é¼þÖдæÔÚÒ»¸öÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶£¨CVE-2020-2050£©£¬ÆäCVSSÆÀ·Ö8.2¡£

µ±Íø¹ØµÄÉí·ÝÑéÖ¤·½Ê½ÅäÖÃΪÆëÈ«»ùÓÚÖ¤Êéʱ£¬¹¥»÷ÕßÄܹ»ÀûÓô˷ìÏ¶ÈÆ¹ýËùÓÐʹÓÃÎÞЧ֤ÊéµÄ¿Í»§¶ËÖ¤Êé²é³­£¬²¢¿ÉÄÜÒÔÈκÎÓû§µÄÉí·Ý½øÐÐÉí·ÝÑéÖ¤£¬×îÖÕ»ñµÃ¶ÔVPNÍøÂç×ÊÔ´µÄ½Ó¼ûȨÏÞ¡£

½«SSL VPNÅäÖÃΪ¿Í»§¶ËÖ¤ÊéÑéÖ¤Ó°ÏìµÄÖ°ÄÜÔ̺¬£º

GlobalProtect Gateway

GlobalProtect Portal

GlobalProtect Clientless VPN

ÔÚ½«¿Í»§¶ËÖ¤ÊéÑéÖ¤ÓëÆäËüÉí·ÝÑéÖ¤²½Öè½áºÏʹÓõÄÇé¿öÏ£¬´Ë·ì϶½«Ê¹µÃÖ¤ÊéÔö³¤µÄ±£»¤±»ºöÂÔ¡£

´Ë·ì϶»áÓ°ÏìʹÓÃGlobalProtect SSL VPN²¢½«Íø¹ØºÍÃÅ»§ÍøÕ¾ÅäÖÃΪÔÊÐíÓû§Ê¹Óÿͻ§¶ËÖ¤ÊéÉí·ÝÑéÖ¤µÄPAN OSÉ豸¡£´Ë±í£¬ÈôÊÇʹÓÃÁ˿ͻ§¶ËÖ¤ÊéÈÏÖ¤£¬Ôò»ùÓÚIPSecµÄVPNÒ²½«Êܵ½Ó°Ïì¡£ÈôÊÇδʹÓÿͻ§¶ËÖ¤Êé½øÐÐÉí·ÝÑéÖ¤£¬ÔòÎÞ·¨ÀûÓô˷ì϶¡£


0x02 ´ëÖý¨Òé

ĿǰPalo Alto NetworksÒѾ­°ä²¼Á˸üа汾¡£½¨Òé²Î¿¼Ï±íʵʱÉý¼¶£º

°æ±¾ºÅ

ÊÜÓ°Ïì°æ±¾

¸üа汾

PAN OS 10.0

<10.0.1

> = 10.0.1

PAN OS 9.1

<9.1.5

> = 9.1.5

PAN OS 9.0

<9.0.11

> = 9.0.11

PAN OS 8.1

<8.1.17

> = 8.1.17

 

һʱ´ëÊ©£º

½«GlobalProtect SSL VPNÅäÖÃΪҪÇóÓû§Ê¹ÓÃÆäÆ¾Ö¤½øÐÐÉí·ÝÑéÖ¤¡£

ÏÂÔØÁ´½Ó£º

https://www.paloaltonetworks.com/search

0x03 ²Î¿¼Á´½Ó

https://security.paloaltonetworks.com/CVE-2020-2050

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-2050

0x04 ¹¦·òÏß

2020-11-11  Palo Alto Networks°ä²¼°²È«²¼¸æ

2020-11-12  VSRC°ä²¼°²È«¹«¸æ

0x05 ¸½Â¼

 

CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/

 

image.png