Palo Alto Networks Cortex XSOARδÊÚȨ½Ó¼û·ì϶£¨CVE-2021-3044£©

°ä²¼¹¦·ò 2021-06-23

0x00 ·ì϶¸ÅÊö

CVE   ID

CVE-2021-3044

ʱ    ¼ä

2021-06-23

Àà    ÐÍ

δÊÚȨ½Ó¼û

µÈ    ¼¶

ÑϳÁ

Ô¶³ÌÀûÓÃ

ÊÇ

Ó°ÏìÁìÓò


¹¥»÷¸´ÔÓ¶È

µÍ

¿ÉÓÃÐÔ

¸ß

Óû§½»»¥

ÎÞ

ËùÐèȨÏÞ

ÎÞ

PoC/EXP

δ¹«¿ª

ÔÚÒ°ÀûÓÃ

·ñ

 

0x01 ·ì϶ÏêÇé

image.png

Cortex? XSOARÊÇÈ«ÇòÍøÂ簲ȫ¸¨µ¼ÆóÒµPalo Alto NetworksÍÆ³öµÄÒ»¸öÈ«ÐÂÀ©´óµÄ°²È«±àÅÅ¡¢×Ô¶¯»¯ÓëÏìӦƽ̨£¬²¢¼¯³ÉÁËÍþвµý±¨ÖÎÀíÖ°ÄÜ£¬´Ó¶øÎªÆóÒµ°²È«Ìṩ¼´Ê±¡¢È«ÃæµÄÍþв·ÀÓù¡£

2021Äê06ÔÂ22ÈÕ£¬Palo Alto Networks°ä²¼°²È«²¼¸æ£¬½¨¸´ÁËCortex XSOARÖеÄÒ»¸öδÊÚȨ½Ó¼û·ì϶£¨CVE-2021-3044£©£¬¸Ã·ì϶µÄCVSSv3ÆÀ·ÖΪ9.8¡£Î´¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß¿ÉÄÜÀûÓô˷ì϶ͨ¹ýREST APIÖ´ÐÐδ¾­ÊÚȨµÄ½Ó¼û¡£

¸Ã·ì϶½ö´æÔÚÓÚÅäÖÃÁ˻µÄ¼¯³ÉAPI KeyµÄCortex XSOAR¡£Äܹ»´ÓCortex XSOAR Web ¿Í»§¶ËÑ¡Ôñ¡®Settings > Integration > API Keys¡¯ À´²é¿´ÅäÖÃÊÇ·ñÊܵ½Ó°Ïì¡£


Ó°ÏìÁìÓò

Cortex XSOAR 6.1.0£ºbuilds >= 1016923 and < 1271064

Cortex XSOAR 6.2.0£ºbuilds < 1271065

 

0x02 ´ëÖý¨Òé

Ŀǰ´Ë·ì϶ÒѾ­½¨¸´£¬½¨Òé²Î¿¼Ï±íʵʱÉý¼¶¸üС£´Ë±í£¬ÓÉPalo Alto NetworksÍйܵÄËùÓÐCortex XSOARÊ·ý¶¼ÒÑÉý¼¶£¬²»±ØÒªÔÙÖ´ÐÐÆäËü²Ù×÷¡£

°æ±¾

ÊÜÓ°Ïì°æ±¾

²»ÊÜÓ°Ïì°æ±¾

Cortex XSOAR 6.2.0

< 1271065

>= 1271065

Cortex XSOAR 6.1.0

>= 1016923 and < 1271064

< 1016923£¬ >= 1271064

Cortex XSOAR 6.0.2

None

all

Cortex XSOAR 6.0.1

None

all

Cortex XSOAR 6.0.0

None

all

Cortex XSOAR 5.5.0

None

all

 

ÏÂÔØÁ´½Ó£º

https://support.paloaltonetworks.com/support

 

»º½â´ëÊ©

³·ÏúËùÓлµÄ¼¯³É API Key£¬´ÓCortex XSOAR web ¿Í»§¶ËµÄSettings > Integration > API Keys£¬¶øºó³·Ïúÿ¸öAPI Key¡£Äܹ»½«Cortex XSOARÉý¼¶µ½¹Ì¶¨°æ±¾ºó´´½¨ÐµÄAPI Key¡£

Ï޶ȶÔCortex XSOAR·þÎñÆ÷µÄÍøÂç½Ó¼û£¬Ö»ÔÊÐíÊÜÐÅÀµµÄÓû§½Ó¼û¡£

 

0x03 ²Î¿¼Á´½Ó

https://security.paloaltonetworks.com/CVE-2021-3044

https://security.paloaltonetworks.com/

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3044

 

0x04 ¹¦·òÏß

2021-06-22  Palo Alto Networks°ä²¼°²È«²¼¸æ

2021-06-23  VSRC°ä²¼°²È«¹«¸æ

 

0x05 ¸½Â¼

CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/

image.png