¡¾·ì϶¹«¸æ¡¿Palo Alto Networks PAN-OSºÅÁî×¢Èë·ì϶ (CVE-2021-3050)

°ä²¼¹¦·ò 2021-08-12

0x00 ·ì϶¸ÅÊö

CVE     ID

CVE-2021-3050

ʱ      ¼ä

2021-08-11

Àà      ÐÍ

ºÅÁî×¢Èë

µÈ      ¼¶

¸ßΣ

Ô¶³ÌÀûÓÃ

ÊÇ

Ó°ÏìÁìÓò


¹¥»÷¸´ÔÓ¶È

µÍ

¿ÉÓÃÐÔ

¸ß

Óû§½»»¥

ÎÞ

ËùÐèȨÏÞ

µÍ

PoC/EXP

Òѹ«¿ª

ÔÚÒ°ÀûÓÃ


 

0x01 ·ì϶ÏêÇé

image.png

PAN-OSÊÇPalo Alto NetworksΪÆä·À»ðǽÉ豸¿ª·¢µÄ²Ù×÷ϵͳ¡£

2021Äê8ÔÂ11ÈÕ£¬Palo Alto Networks°ä²¼°²È«²¼¸æ£¬½¨¸´ÁËPAN-OSÖеÄÒ»¸öºÅÁî×¢Èë·ì϶£¨CVE-2021-3050£©£¬¸Ã·ì϶µÄCVSSv3ÆÀ·ÖΪ8.8¡£

¸Ã·ì϶´æÔÚÓÚPAN-OS Web ½çÃæÖУ¬¾­¹ýÉí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß¿ÉÄÜÖ´ÐÐËÁÒâϵͳºÅÁî²¢ÌáÉýȨÏÞ£¬µ«ÒªÀûÓô˷ì϶£¬¹¥»÷Õß±ØÒª½Ó¼û PAN-OS Web ½çÃæ½øÐÐÉí·ÝÑéÖ¤¡£

Palo Alto Networks°µÊ¾ÔÝδ·¢Ïָ÷ì϶±»ÀûÓ㬵«´Ë·ì϶µÄEXPÒѹ«¿ª¡£

 

0x02 ´ëÖý¨Òé

Ŀǰ´Ë·ì϶ÒѾ­½¨¸´¡£¼øÓÚ´Ë·ì϶Ϊ±í²¿·¢ÏÖ£¬ÇÒ·ì϶ÀûÓù«¿ª¿ÉÓ㬽¨ÒéÊÜÓ°ÏìÓû§²Î¿¼Ï±íʵʱÉý¼¶¸üУº

°æ±¾

ÊÜÓ°Ïì°æ±¾

½¨¸´°æ±¾

PAN-OS 10.1

>= 10.1.0

>= 10.1.2

PAN-OS 10.0

>= 10.0.0

>= 10.0.8

PAN-OS 9.1

>= 9.1.4

>= 9.1.11

PAN-OS 9.0

>= 9.0.10

>= 9.0.15

PAN-OS 8.1

None

8.1.*

×¢£ºPrisma Access ·À»ðǽºÍÔËÐÐ PAN OS 8.1 °æ±¾µÄ·À»ðǽ²»ÊÜ´Ë·ì϶µÄÓ°Ïì¡£

ÏÂÔØÁ´½Ó£º

https://www.paloaltonetworks.cn/

 

0x03 ²Î¿¼Á´½Ó

https://security.paloaltonetworks.com/CVE-2021-3050

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3050

https://nvd.nist.gov/vuln/detail/CVE-2021-3050

 

0x04 ¸üа汾

°æ±¾

ÈÕÆÚ

Åú¸ÄÄÚÈÝ

V1.0

2021-08-12

³õ´Î°ä²¼

 

0x05 Îĵµ¸½Â¼

CNVD£ºwww.cnvd.org.cn

CNNVD£ºwww.cnnvd.org.cn

CVE£ºcve.mitre.org

NVD£ºnvd.nist.gov

CVSS£ºwww.first.org

 

0x06 ¹ØÓÚGA»Æ½ð¼×

¹Ø×¢ÒÔϹ«¼ÒºÅ£¬»ñÈ¡¸ü¶à×ÊѶ£º

image.png