Pulse Connect SecureËÁÒâ´úÂëÖ´Ðзì϶£¨CVE-2021-22908£©

°ä²¼¹¦·ò 2021-05-25

0x00 ·ì϶¸ÅÊö

CVE  ID

CVE-2021-22908

ʱ   ¼ä

2021-05-25

Àà   ÐÍ

´úÂëÖ´ÐÐ

µÈ   ¼¶

¸ßΣ

Ô¶³ÌÀûÓÃ

ÊÇ

Ó°ÏìÁìÓò

9.0RX¡¢9.1RX

PoC/EXP

δ¹«¿ª

ÔÚÒ°ÀûÓÃ

·ñ

 

0x01 ·ì϶ÏêÇé

image.png

 

Pulse Connect Secure£¨PCS£©ÊÇÃÀ¹úPulse Secure¹«Ë¾µÄÒ»Ì×SSL VPN½â¾ö¹æ»®¡£¡£¡£¡£¡£¡£ ¡£

2021Äê05ÔÂ24ÈÕ£¬£¬£¬£¬£¬£¬¿¨ÄÚ»ù÷¡´óѧÅû¶ÁËPulse Connect SecureÖеÄÒ»¸ö»º³åÇøÒç¶Âí½Å£¨CVE-2021-22908£©£¬£¬£¬£¬£¬£¬¸Ã·ì϶µÄCVSSÆÀ·ÖΪ8.5¡£¡£¡£¡£¡£¡£ ¡£¾­¹ýÉí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓô˷ì϶ÔÚÊÜÓ°ÏìµÄPCS·þÎñÆ÷ÉÏÒÔrootȨÏÞÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£ ¡£

 

·ì϶ϸ½Ú

ÓÉÓÚPCSÖ§³ÖÏνӵ½WindowsÎļþ¹²Ïí£¨SMB£©µÄÖ°ÄÜÓÉ»ùÓÚSamba 4.5.10µÄ¿âºÍ¸¨ÖúÀûÓ÷¨Ê½µÄCGI¾ç±¾Ìṩ¡£¡£¡£¡£¡£¡£ ¡£µ±ÎªÄ³Ð©SMB²Ù×÷Ö¸¶¨Ò»¸ö³¤µÄ·þÎñÆ÷Ãû³ÆÊ±£¬£¬£¬£¬£¬£¬smbcltÀûÓ÷¨Ê½¿ÉÄÜ»áÓÉÓÚ»º³åÇøÒç³ö¶ø±ÀÀ££¬£¬£¬£¬£¬£¬¾ßÌåÈ¡¾öÓÚÖ¸¶¨µÄ·þÎñÆ÷Ãû³Æ³¤¶È¡£¡£¡£¡£¡£¡£ ¡£

ÒѾ­È·ÈÏPCS 9.1R11.4ϵͳ´æÔÚ´Ë·ì϶£¬£¬£¬£¬£¬£¬Ö¸±êCGI¶ËµãΪ/dana/fb/smb/wnf.cgi£¬£¬£¬£¬£¬£¬ÆäËüCGI¶ËµãÒ²¿ÉÄܻᴥ·¢´Ë·ì϶¡£¡£¡£¡£¡£¡£ ¡£

ÈôÊǹ¥»÷ÕßÔڳɹ¦ÀûÓô˷ì϶ºóûÓнøÐÐËãÕÊ£¬£¬£¬£¬£¬£¬ÔòÖ¸¶¨Ò»¸ö³¤µÄ·þÎñÆ÷Ãû³Æ¿ÉÄܻᵼÖÂÈçÏÂPCSÊÂÎñÈÕÖ¾Ìõ¿î£º

Critical ERR31093 2021-05-24 14:05:37 - ive - [127.0.0.1] Root::System()[] - Program smbclt recently failed.

 

µ«ÒªÀûÓô˷ì϶£¬£¬£¬£¬£¬£¬PCS·þÎñÆ÷±ØÐëÓÐÒ»¸öallows \\*µÄWindowsÎļþ½Ó¼ûÕ½Êõ»òÔÊÐí¹¥»÷ÕßÏνӵ½ËÁÒâ·þÎñÆ÷µÄÆäËüµÄÕ½Êõ¡£¡£¡£¡£¡£¡£ ¡£¿£¿£¿£¿ £¿£¿£Äܹ»ÔÚPCSµÄÖÎÀíÒ³ÃæÖУ¬£¬£¬£¬£¬£¬²é¿´Óû§->×ÊÔ´Õ½Êõ->WindowsÎļþ½Ó¼ûÕ½Êõ£¬£¬£¬£¬£¬£¬À´²é¿´µ±Ç°µÄSMBÕ½Êõ¡£¡£¡£¡£¡£¡£ ¡£9.1R2¼°Ö®Ç°µÄPCSÉ豸ʹÓÃÔÊÐíÏνӵ½ËÁÒâSMBÖ÷»úµÄĬÈÏÕ½Êõ£¬£¬£¬£¬£¬£¬´Ó9.1R3ÆðÍ·£¬£¬£¬£¬£¬£¬Õâ¸öÕ½Êõ´ÓĬÈÏÔÊÐí¸ü¸ÄΪĬÈϻؾø¡£¡£¡£¡£¡£¡£ ¡£

 

Ó°ÏìÁìÓò

Pulse Connect Secure 9.0RXºÍ9.1RX

 

0x02 ´ëÖý¨Òé

Pulse SecureÔ¤¼ÆÔÚPulse Connect Secure 9.1R11.5»ò¸ü¸ß°æ±¾Öн¨¸´¸Ã·ì϶£¬£¬£¬£¬£¬£¬µ«Ä¿Ç°ÉÐδ°ä²¼¡£¡£¡£¡£¡£¡£ ¡£

ÏÂÔØÁ´½Ó£º

https://my.pulsesecure.net/

 

0x03 ²Î¿¼Á´½Ó

https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44800

https://kb.cert.org/vuls/id/667933

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-22908

 

0x04 ¹¦·òÏß

2021-05-24 ¿¨ÄÚ»ù÷¡´óѧÅû¶·ì϶

2021-05-25  VSRC°ä²¼°²È«¹«¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/

image.png