¡¾·ì϶¹«¸æ¡¿CVE-2020-10148 SolarWinds Orion RCE·ì϶
°ä²¼¹¦·ò 2020-12-280x00 ·ì϶¸ÅÊö
CVE ID | CVE-2020-10148 | ʱ ¼ä | 2020-12-28 |
Àà ÐÍ | RCE | µÈ ¼¶ | ¸ßΣ |
Ô¶³ÌÀûÓà | ÊÇ | Ó°ÏìÁìÓò |
0x01 ·ì϶ÏêÇé

SolarWinds Orion PlatformÊÇ»ù´¡ÉèÊ©ºÍϵͳÖÎÀí²úÆ·Ì×¼þ¡£SolarWinds Orion API±»Ç¶Èëµ½OrionÄÚºËÖУ¬ÓÃÓÚÓëËùÓÐSolarWinds Orionƽ̨²úÆ·½øÐÐÏνӡ£
½üÈÕ£¬SolarWinds Orion APIÖб»Åû¶´æÔÚÒ»¸öÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2020-10148£©¡£¸Ã·ì϶ÊÇÓÉÓÚSolarWinds Orion APIÉí·ÝÑéÖ¤¿ÉÄܱ»Èƹý£¬¹¥»÷ÕßÄܹ»Í¨¹ýÔÚRequest.PathInfo URIÒªÇóÖÐʹÓÃÌØ¶¨²ÎÊýÀ´ÀûÓô˷ì϶£¬×îÖÕ¹¥»÷ÕßÄܹ»Ô¶³ÌÖ´ÐÐδ¾Éí·ÝÑéÖ¤µÄAPIºÅÁî¡£ÓÈÆäÊǵ±¹¥»÷Õ߸½¼ÓÒ»¸öPathInfoº¯ÊýµÄ²ÎÊýΪWebResource.adx¡¢ScriptResource.adx¡¢i18n.ashx¡¢»òSkipi18nµÄÒªÇó¸øSolarWinds Orion·þÎñÆ÷ʱ£¬SolarWindsÄܹ»ÉèÖÃSkipAuthorization flag£¬ÕâÑùÄܹ»ÔÚ²»±ØÒªÉí·ÝÑéÖ¤µÄÇé¿öÏ´¦ÖÃAPIÒªÇó¡£
0x02 ´ëÖý¨Òé
Ŀǰ£¬SolarWindsÒѾ°ä²¼ÁË´Ë·ì϶µÄ°²È«¸üУ¬½¨Ò齫SolarWinds Orion¸üÐÂÖÁÈçϰ汾£º
2019.4 HF 6£¨2020Äê12ÔÂ14ÈÕ°ä²¼£©
2020.2.1 HF 2£¨2020Äê12ÔÂ15ÈÕ°ä²¼£©
2019.2 SUPERNOVA²¹¶¡£¨2020Äê12ÔÂ23ÈÕ°ä²¼£©
2018.4 SUPERNOVA²¹¶¡£¨2020Äê12ÔÂ23ÈÕ°ä²¼£©
2018.2 SUPERNOVA²¹¶¡£¨2020Äê12ÔÂ23ÈÕ°ä²¼£©
ÏÂÔØÁ´½Ó£º
https://www.solarwinds.com/securityadvisory
0x03 ²Î¿¼Á´½Ó
https://kb.cert.org/vuls/id/843464
https://github.com/solarwinds/OrionSDK/wiki
https://cyber.dhs.gov/ed/21-01/
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-10148
0x04 ¹¦·òÏß
2020-12-26 CERT/CCÅû¶·ì϶
2020-12-27 CERT/CC¸üзì϶
2020-12-28 VSRC°ä²¼°²È«¹«¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/



¾©¹«Íø°²±¸11010802024551ºÅ