CVE-2020-2034 | PAN-OS GlobalProtect portalÏÂÁî×¢ÈëÎó²îͨ¸æ

Ðû²¼Ê±¼ä 2020-07-09

0x00 Îó²î¸ÅÊö



CVE   ID

CVE-2020-2034

ʱ    ¼ä

2020-07-09

ÀàÐÍ

CI

µÈ    ¼¶

¸ßΣ

Ô¶³ÌʹÓÃ

ÊÇ

Ó°Ïì¹æÄ£

PAN-OS 9.1£º<9.1.3°æ±¾

PAN-OS 9.0£º<9.0.9°æ±¾

PAN-OS 8.1£º<8.1.15°æ±¾

PAN-OS 8.0£ºÈ«°æ±¾

PAN-OS 7.1£ºÈ«°æ±¾

0x01 Îó²îÏêÇé


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨



2020Äê7ÔÂ8ÈÕ£¬ £¬£¬Palo Alto NetworksÐû²¼Ç徲ͨ¸æ£¬ £¬£¬ÐÞ¸´ÁËÒ»¸öPAN-OS GlobalProtect portalÖеÄÏÂÁî×¢ÈëÎó²î£¨CVE-2020-2034£©£¬ £¬£¬¸ÃÎó²îµ¼ÖÂδ¾­Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÔÚÊÜÓ°ÏìµÄ×°±¸ÉÏÒÔrootȨÏÞÖ´ÐÐí§ÒâOSÏÂÁî ¡£¡£¡£¡£

Ç徲ͨ¸æÌåÏÖ£º

? Ê×ÏÈÐèÒªÖªµÀ·À»ðǽµÄÉèÖÃÐÅÏ¢²¢Í¨¹ý±©Á¦ÆÆ½â»ñÈ¡Óû§ÃûºÍÃÜÂë²Å»ªÊ¹ÓøÃÎó²î£»£»£»£»£»£»

? ÈôÊÇGlobalProtect portal¹¦Ð§Î´ÆôÓ㬠£¬£¬ÔòÎÞ·¨Ê¹ÓøÃÎó²î£»£»£»£»£»£»

? ¸ÃÎó²î²»Ó°ÏìPrisma AccessЧÀÍ ¡£¡£¡£¡£


0x02 ´¦Öóͷ£½¨Òé


ÏÖÔÚ³§ÉÌÒÑÐÞ¸´¸ÃÎó²î£¬ £¬£¬ÇëÏà¹ØÓû§ÊµÊ±Éý¼¶£º

PAN-OS 9.1£ºÉý¼¶µ½PAN-OS 9.1.3°æ±¾

PAN-OS 9.0£ºÉý¼¶µ½PAN-OS 9.0.9°æ±¾

PAN-OS 8.1£ºÉý¼¶µ½PAN-OS 8.1.15°æ±¾

PAN-OS 8.0£ºPAN-OS 8.0ÒÑÓÚ2019Äê10ÔÂ31ÈÕ×èֹά»¤£¬ £¬£¬½¨ÒéÓû§¸üе½×îа汾

PAN-OS 7.1£ºPAN-OS 8.0ÒÑÓÚ2020Äê6ÔÂ30ÈÕ×èֹά»¤£¬ £¬£¬½¨ÒéÓû§¸üе½×îа汾


0x03 Ïà¹ØÐÂÎÅ


https://www.bleepingcomputer.com/news/security/palo-alto-networks-fixes-another-severe-flaw-in-pan-os-devices/


0x04 ²Î¿¼Á´½Ó


https://security.paloaltonetworks.com/CVE-2020-2034


0x05 ʱ¼äÏß


2020-07-08 Palo Alto NetworksÐû²¼Ç徲ͨ¸æ

2020-07-09 VSRCÐû²¼Îó²îͨ¸æ


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨