Palo Alto Networks Cortex XSOARδÊÚȨ½Ó¼û·ì϶£¨CVE-2021-3044£©
°ä²¼¹¦·ò 2021-06-230x00 ·ì϶¸ÅÊö
CVE ID | CVE-2021-3044 | ʱ ¼ä | 2021-06-23 |
Àà ÐÍ | δÊÚȨ½Ó¼û | µÈ ¼¶ | ÑϳÁ |
Ô¶³ÌÀûÓà | ÊÇ | Ó°ÏìÁìÓò | |
¹¥»÷¸´ÔÓ¶È | µÍ | ¿ÉÓÃÐÔ | ¸ß |
Óû§½»»¥ | ÎÞ | ËùÐèȨÏÞ | ÎÞ |
PoC/EXP | δ¹«¿ª | ÔÚÒ°ÀûÓà | ·ñ |
0x01 ·ì϶ÏêÇé

Cortex? XSOARÊÇÈ«ÇòÍøÂ簲ȫ¸¨µ¼ÆóÒµPalo Alto NetworksÍÆ³öµÄÒ»¸öÈ«ÐÂÀ©´óµÄ°²È«±àÅÅ¡¢×Ô¶¯»¯ÓëÏìӦƽ̨£¬²¢¼¯³ÉÁËÍþвµý±¨ÖÎÀíÖ°ÄÜ£¬´Ó¶øÎªÆóÒµ°²È«Ìṩ¼´Ê±¡¢È«ÃæµÄÍþв·ÀÓù¡£
2021Äê06ÔÂ22ÈÕ£¬Palo Alto Networks°ä²¼°²È«²¼¸æ£¬½¨¸´ÁËCortex XSOARÖеÄÒ»¸öδÊÚȨ½Ó¼û·ì϶£¨CVE-2021-3044£©£¬¸Ã·ì϶µÄCVSSv3ÆÀ·ÖΪ9.8¡£Î´¾Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß¿ÉÄÜÀûÓô˷ì϶ͨ¹ýREST APIÖ´ÐÐδ¾ÊÚȨµÄ½Ó¼û¡£
¸Ã·ì϶½ö´æÔÚÓÚÅäÖÃÁ˻µÄ¼¯³ÉAPI KeyµÄCortex XSOAR¡£Äܹ»´ÓCortex XSOAR Web ¿Í»§¶ËÑ¡Ôñ¡®Settings > Integration > API Keys¡¯ À´²é¿´ÅäÖÃÊÇ·ñÊܵ½Ó°Ïì¡£
Ó°ÏìÁìÓò
Cortex XSOAR 6.1.0£ºbuilds >= 1016923 and < 1271064
Cortex XSOAR 6.2.0£ºbuilds < 1271065
0x02 ´ëÖý¨Òé
Ŀǰ´Ë·ì϶ÒѾ½¨¸´£¬½¨Òé²Î¿¼Ï±íʵʱÉý¼¶¸üС£´Ë±í£¬ÓÉPalo Alto NetworksÍйܵÄËùÓÐCortex XSOARÊ·ý¶¼ÒÑÉý¼¶£¬²»±ØÒªÔÙÖ´ÐÐÆäËü²Ù×÷¡£
°æ±¾ | ÊÜÓ°Ïì°æ±¾ | ²»ÊÜÓ°Ïì°æ±¾ |
Cortex XSOAR 6.2.0 | < 1271065 | >= 1271065 |
Cortex XSOAR 6.1.0 | >= 1016923 and < 1271064 | < 1016923£¬ >= 1271064 |
Cortex XSOAR 6.0.2 | None | all |
Cortex XSOAR 6.0.1 | None | all |
Cortex XSOAR 6.0.0 | None | all |
Cortex XSOAR 5.5.0 | None | all |
ÏÂÔØÁ´½Ó£º
https://support.paloaltonetworks.com/support
»º½â´ëÊ©
³·ÏúËùÓлµÄ¼¯³É API Key£¬´ÓCortex XSOAR web ¿Í»§¶ËµÄSettings > Integration > API Keys£¬¶øºó³·Ïúÿ¸öAPI Key¡£Äܹ»½«Cortex XSOARÉý¼¶µ½¹Ì¶¨°æ±¾ºó´´½¨ÐµÄAPI Key¡£
Ï޶ȶÔCortex XSOAR·þÎñÆ÷µÄÍøÂç½Ó¼û£¬Ö»ÔÊÐíÊÜÐÅÀµµÄÓû§½Ó¼û¡£
0x03 ²Î¿¼Á´½Ó
https://security.paloaltonetworks.com/CVE-2021-3044
https://security.paloaltonetworks.com/
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3044
0x04 ¹¦·òÏß
2021-06-22 Palo Alto Networks°ä²¼°²È«²¼¸æ
2021-06-23 VSRC°ä²¼°²È«¹«¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/



¾©¹«Íø°²±¸11010802024551ºÅ