¡¾·ì϶¹«¸æ¡¿Pulse Connect Secure 8Ô¶à¸ö°²È«·ì϶
°ä²¼¹¦·ò 2021-08-090x00 ·ì϶¸ÅÊö
2021Äê8ÔÂ2ÈÕ£¬£¬£¬£¬£¬Ivanti °ä²¼ÁË Pulse Connect Secure ϵͳÈí¼þ°æ±¾ 9.1R12£¬£¬£¬£¬£¬½¨¸´ÁËPulse Connect Secure VPNÉ豸ÖеĶà¸ö°²È«·ì϶£¬£¬£¬£¬£¬³É¹¦ÀûÓÃÕâЩ·ì϶µÄ¹¥»÷ÕßÄܹ»ÊµÏÖRCE¡¢XSS¹¥»÷¡¢ºÅÁî×¢Èë»òËÁÒâÎļþɾ³ý¡£¡£¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬ÕâЩ·ì϶ÔÝδ·¢´Ë¿ÌÒ°ÀûÓᣡ£¡£¡£¡£¡£¡£
0x01 ·ì϶ÏêÇé

±¾´Î¹«¿ªµÄ£¶¸ö·ì϶¶¼Äܹ»±»Ô¶³ÌÀûÓ㬣¬£¬£¬£¬ÆäÖУ¬£¬£¬£¬£¬CVE-2021-22937ºÍCVE-2021-22935×îΪÑϳÁ¡£¡£¡£¡£¡£¡£¡£ÕâЩ·ì϶µÄÏêÇéÈçÏ£º
Pulse Connect SecureÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2021-22937£©
¾¹ýÉí·ÝÑéÖ¤µÄ¹¥»÷ÕßÄܹ»ÀûÓô˷ì϶ÔÚweb½çÃæÉÏ´«¶ñÒâÎļþÀ´ÊµÏÖÎļþдÈë»òÖ´ÐдúÂë¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶µÄCVSSv3ÆÀ·ÖΪ9.1¡£¡£¡£¡£¡£¡£¡£
Pulse Connect SecureËÁÒâÎļþɾ³ý·ì϶£¨CVE-2021-22933£©
¾¹ýÉí·ÝÑéÖ¤µÄ¹¥»÷ÕßÄܹ»Í¨¹ý¶ñÒâÔì×÷µÄ Web ÒªÇóʵÏÖËÁÒâÎļþɾ³ý¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶µÄCVSSv3ÆÀ·ÖΪ7.6¡£¡£¡£¡£¡£¡£¡£
Pulse Connect Secure»º³åÇøÒç¶Âí½Å£¨CVE-2021-22934£©
¾¹ýÉí·ÝÑéÖ¤µÄ¹¥»÷ÕßÄܹ»Í¨¹ý¶ñÒâÔì×÷µÄWebÒªÇóÔì³ÉPulse Connect Secure É豸»º³åÇøÒç³ö¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶µÄCVSSv3ÆÀ·ÖΪ8.0¡£¡£¡£¡£¡£¡£¡£
Pulse Connect SecureºÅÁî×¢Èë·ì϶£¨CVE-2021-22935£©
¾¹ýÉí·ÝÑéÖ¤µÄ¹¥»÷ÕßÄܹ»Í¨¹ýδ´¦ÖõÄweb²ÎÊýÖ´ÐкÅÁî×¢Èë¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶µÄCVSSv3ÆÀ·ÖΪ9.1¡£¡£¡£¡£¡£¡£¡£
Pulse Connect Secure XSS·ì϶£¨CVE-2021-22936£©
¹¥»÷ÕßÄܹ»Í¨¹ýδ´¦ÖõÄweb²ÎÊý¶Ô¾¹ýÉí·ÝÑéÖ¤µÄÖÎÀíÔ±½øÐпçÕ¾¾ç±¾¹¥»÷¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶µÄCVSSv3ÆÀ·ÖΪ8.2¡£¡£¡£¡£¡£¡£¡£
Pulse Connect Secure ºÅÁî×¢Èë·ì϶£¨CVE-2021-22938£©
¾¹ýÉí·ÝÑéÖ¤µÄ¹¥»÷ÕßÄܹ»Í¨¹ýÖÎÀíÔ± Web ½ÚÔį̀ÖÐδ´¦ÖõÄWeb ²ÎÊýÖ´ÐкÅÁî×¢Èë¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶µÄCVSSv3ÆÀ·ÖΪ7.9¡£¡£¡£¡£¡£¡£¡£
Ó°ÏìÁìÓò
Pulse Connect Secure < 9.1R12
0x02 ´ëÖý¨Òé
ĿǰÕâЩ·ì϶ÒѾ½¨¸´¡£¡£¡£¡£¡£¡£¡£½¨ÒéÊÜÓ°ÏìµÄ¿Í»§ÊµÊ±Éý¼¶¸üÐÂÖÁPCS 9.1R12°æ±¾£¨ÒÑÓÚ2021 Äê 8 Ô 2 ÈÕ°ä²¼£©¡£¡£¡£¡£¡£¡£¡£
ÏÂÔØÁ´½Ó£º
https://www.ivanti.com/products/connect-secure-vpn?psredirect
0x03 ²Î¿¼Á´½Ó
https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44858
https://us-cert.cisa.gov/ncas/current-activity/2021/08/06/ivanti-releases-security-update-pulse-connect-secure
https://securityaffairs.co/wordpress/120880/security/pulse-connect-secure-vpn-flaw-2.html?
0x04 ¸üа汾
°æ±¾ | ÈÕÆÚ | Åú¸ÄÄÚÈÝ |
V1.0 | 2021-08-09 | ³õ´Î°ä²¼ |
0x05 Îĵµ¸½Â¼
CNVD£ºwww.cnvd.org.cn
CNNVD£ºwww.cnnvd.org.cn
CVE£ºcve.mitre.org
NVD£ºnvd.nist.gov
CVSS£ºwww.first.org
0x06 ¹ØÓÚ8827Ì«Ñô¼¯ÍÅ
¹Ø×¢ÒÔϹ«¼ÒºÅ£¬£¬£¬£¬£¬»ñÈ¡¸ü¶à×ÊѶ£º



¾©¹«Íø°²±¸11010802024551ºÅ