Palo Alto Networks PAN-OSÔ¶³Ì´úÂëÖ´Ðзì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2019-07-24

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-1579£¬ £¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬ £¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º8.1


Ó°Ïì°æ±¾


ÊÜÓ°ÏìµÄ°æ±¾


Palo Alto Networks PAN-OS 7.1.18¼°Ö®Ç°°æ±¾
Palo Alto Networks PAN-OS 8.0.11¼°Ö®Ç°°æ±¾
Palo Alto Networks PAN-OS 8.1.2¼°Ö®Ç°°æ±¾


²»ÊÜÓ°ÏìµÄ°æ±¾


Palo Alto Networks PAN-OS 9.0


·ì϶¸ÅÊö


Palo Alto Networks PAN-OSÊÇÃÀ¹úPalo Alto Networks¹«Ë¾µÄÒ»Ì×ΪÆä·À»ðǽÉ豸¿ª·¢µÄ²Ù×÷ϵͳ¡£¡£¡£¡£¡£


Palo Alto Networks PAN-OS´æÔÚ°²È«·ì϶£¬ £¬£¬£¬£¬£¬£¬Ó°ÏìGlobalProtectÃÅ»§ÍøÕ¾ºÍGlobalProtect Gateway½Ó¿Ú²úÆ·£¬ £¬£¬£¬£¬£¬£¬GlobalProtect ²úÆ·ÔÊÐí×éÖ¯³ÉÁ¢Ð鹹רÓÃÍø£¨VPN£©½Ó¼û£¬ £¬£¬£¬£¬£¬£¬²¢ÊµÏÔìäËû°²È«ºÍÖÎÀíÖ°ÄÜ¡£¡£¡£¡£¡£ÒòÍø¹ØÒÔδ¾­³éÑùºÍ¿ÉÀûÓõķ½Ê½½«Ìض¨²ÎÊýÖµ´«µÝ¸øsnprintf£¬ £¬£¬£¬£¬£¬£¬ÔÊÐíºÚ¿ÍÀûÓø÷ì϶ÏòÒ×Êܹ¥»÷µÄSSL VPNÖ¸±ê·¢ËÍÌØÔìÒªÇó£¬ £¬£¬£¬£¬£¬£¬Ô¶³ÌÖ´ÐÐϵͳÉϵĴúÂë¡£¡£¡£¡£¡£


·ì϶ÑéÖ¤


POC£ºhttp://blog.orange.tw/2019/07/attacking-ssl-vpn-part-1-preauth-rce-on-palo-alto.html¡£¡£¡£¡£¡£


½¨¸´½¨Òé


Ŀǰ³§ÉÌÒѰ䲼Éý¼¶²¹¶¡ÒÔ½¨¸´·ì϶£¬ £¬£¬£¬£¬£¬£¬²¹¶¡»ñÈ¡Á´½Ó£ºhttps://securityadvisories.paloaltonetworks.com/Home/Detail/158¡£¡£¡£¡£¡£


²Î¿¼Á´½Ó


https://securityadvisories.paloaltonetworks.com/Home/Detail/158