¡¾·ì϶¹«¸æ¡¿SonicWall SMA 100ϵÁÐËÁÒâÎļþɾ³ý·ì϶£¨CVE-2021-20034£©

°ä²¼¹¦·ò 2021-09-24


0x00 ·ì϶¸ÅÊö

CVE     ID

CVE-2021-20034

ʱ      ¼ä

2021-09-23

Àà      ÐÍ

Îļþɾ³ý

µÈ      ¼¶

ÑϳÁ

Ô¶³ÌÀûÓÃ

ÊÇ

Ó°ÏìÁìÓò


¹¥»÷¸´ÔÓ¶È

µÍ

¿ÉÓÃÐÔ

¸ß

Óû§½»»¥

ÎÞ

ËùÐèȨÏÞ

ÎÞ

PoC/EXP

δ¹«¿ª

ÔÚÒ°ÀûÓÃ

·ñ

 

0x01 ·ì϶ÏêÇé

image.png

2021Äê9ÔÂ24ÈÕ £¬SonicWall°ä²¼°²È«²¼¸æ £¬½¨¸´ÁËSMA 100 ϵÁÐÉ豸£¨Ô̺¬ SMA 200¡¢210¡¢400¡¢410 ºÍ 500v£©ÖеÄÒ»¸öËÁÒâÎļþɾ³ý·ì϶£¨CVE-2021-20034£© £¬¸Ã·ì϶µÄCVSSv3ÆÀ·ÖΪ9.1¡£

ÓÉÓÚ¶ÔÎļþõè¾¶Ï޶Ȳ»µ± £¬Î´¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÄܹ»Èƹýõè¾¶±éÀú²é³­²¢´ÓSMA 100ϵÁÐÉ豸ÉÑþ³ØýËÁÒâÎļþ £¬×îÖÕ¹¥»÷Õß¿ÉÄÜ»ñµÃ¶Ô¸ÃÉ豸µÄÖÎÀíԱȨÏÞ £¬»òµ¼ÖÂÉ豸³ÁÐÂÆô¶¯µ½³ö³§Ä¬ÈÏÉèÖá£

 

Ó°ÏìÁìÓò

               

²úÆ·

ƽ̨

ÊÜÓ°Ïì°æ±¾

½¨¸´°æ±¾


 

 

 

 

SMA 100 ϵÁÐ

l  SMA 200

l  SMA 210

l  SMA 400

l  SMA 410

l  SMA 500v£¨ESX¡¢KVM¡¢AWS¡¢Azure£©

10.2.1.0-17sv

¼°Ö®Ç°°æ±¾

10.2.1.1-19sv

»ò¸ü¸ß°æ±¾






10.2.0.7-34sv

¼°Ö®Ç°°æ±¾

10.2.0.8-37sv

»ò¸ü¸ß°æ±¾






9.0.0.10-28sv
 
¼°Ö®Ç°°æ±¾

9.0.0.11 -31sv

»ò¸ü¸ß°æ±¾






 

0x02 ´ëÖý¨Òé

Ŀǰ¸Ã·ì϶ÒѾ­½¨¸´ £¬½¨ÒéÊÜÓ°ÏìµÄÓû§ÊµÊ±Éý¼¶¸üе½½¨¸´°æ±¾¡£

ÏÂÔØÁ´½Ó£º

https://mysonicwall.com/

 

0x03 ²Î¿¼Á´½Ó

https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0021

https://www.sonicwall.com/support/product-notification/security-notice-critical-arbitrary-file-delete-vulnerability-in-sonicwall-sma-100-series-appliances/210819124854603/

https://www.bleepingcomputer.com/news/security/sonicwall-fixes-critical-bug-allowing-sma-100-device-takeover/

 

0x04 ¸üа汾

°æ±¾

ÈÕÆÚ

Åú¸ÄÄÚÈÝ

V1.0

2021-09-24

³õ´Î°ä²¼

 

0x05 Îĵµ¸½Â¼

CNVD£ºwww.cnvd.org.cn

CNNVD£ºwww.cnnvd.org.cn

CVE£ºcve.mitre.org

CVSS£ºwww.first.org

NVD£ºnvd.nist.gov

 

0x06 ¹ØÓÚGA»Æ½ð¼×

¹Ø×¢ÒÔϹ«¼ÒºÅ £¬»ñÈ¡¸ü¶à×ÊѶ£º

image.png