CVE-2020-2034 | PAN-OS GlobalProtect portalÏÂÁî×¢ÈëÎó²îͨ¸æ
Ðû²¼Ê±¼ä 2020-07-090x00 Îó²î¸ÅÊö
CVE ID |
CVE-2020-2034 |
ʱ ¼ä |
2020-07-09 |
ÀàÐÍ |
CI |
µÈ ¼¶ |
¸ßΣ |
Ô¶³ÌʹÓà |
ÊÇ |
Ó°Ïì¹æÄ£ |
PAN-OS 9.1£º<9.1.3°æ±¾ PAN-OS 9.0£º<9.0.9°æ±¾ PAN-OS 8.1£º<8.1.15°æ±¾ PAN-OS 8.0£ºÈ«°æ±¾ PAN-OS 7.1£ºÈ«°æ±¾ |
0x01 Îó²îÏêÇé
2020Äê7ÔÂ8ÈÕ£¬£¬£¬Palo Alto NetworksÐû²¼Ç徲ͨ¸æ£¬£¬£¬ÐÞ¸´ÁËÒ»¸öPAN-OS GlobalProtect portalÖеÄÏÂÁî×¢ÈëÎó²î£¨CVE-2020-2034£©£¬£¬£¬¸ÃÎó²îµ¼ÖÂδ¾Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÔÚÊÜÓ°ÏìµÄ×°±¸ÉÏÒÔrootȨÏÞÖ´ÐÐí§ÒâOSÏÂÁî¡£¡£¡£¡£
Ç徲ͨ¸æÌåÏÖ£º
? Ê×ÏÈÐèÒªÖªµÀ·À»ðǽµÄÉèÖÃÐÅÏ¢²¢Í¨¹ý±©Á¦ÆÆ½â»ñÈ¡Óû§ÃûºÍÃÜÂë²Å»ªÊ¹ÓøÃÎó²î£»£»£»£»£»£»
? ÈôÊÇGlobalProtect portal¹¦Ð§Î´ÆôÓ㬣¬£¬ÔòÎÞ·¨Ê¹ÓøÃÎó²î£»£»£»£»£»£»
? ¸ÃÎó²î²»Ó°ÏìPrisma AccessЧÀÍ¡£¡£¡£¡£
0x02 ´¦Öóͷ£½¨Òé
ÏÖÔÚ³§ÉÌÒÑÐÞ¸´¸ÃÎó²î£¬£¬£¬ÇëÏà¹ØÓû§ÊµÊ±Éý¼¶£º
PAN-OS 9.1£ºÉý¼¶µ½PAN-OS 9.1.3°æ±¾
PAN-OS 9.0£ºÉý¼¶µ½PAN-OS 9.0.9°æ±¾
PAN-OS 8.1£ºÉý¼¶µ½PAN-OS 8.1.15°æ±¾
PAN-OS 8.0£ºPAN-OS 8.0ÒÑÓÚ2019Äê10ÔÂ31ÈÕ×èֹά»¤£¬£¬£¬½¨ÒéÓû§¸üе½×îа汾
PAN-OS 7.1£ºPAN-OS 8.0ÒÑÓÚ2020Äê6ÔÂ30ÈÕ×èֹά»¤£¬£¬£¬½¨ÒéÓû§¸üе½×îа汾
0x03 Ïà¹ØÐÂÎÅ
https://www.bleepingcomputer.com/news/security/palo-alto-networks-fixes-another-severe-flaw-in-pan-os-devices/
0x04 ²Î¿¼Á´½Ó
https://security.paloaltonetworks.com/CVE-2020-2034
0x05 ʱ¼äÏß
2020-07-08 Palo Alto NetworksÐû²¼Ç徲ͨ¸æ
2020-07-09 VSRCÐû²¼Îó²îͨ¸æ
