CVE-2020- 5135 | SonicOS»º³åÇøÒç³öÎó²îͨ¸æ

Ðû²¼Ê±¼ä 2020-10-15

0x00 Îó²î¸ÅÊö

CVE   ID

CVE-2020- 5135

ʱ   ¼ä

2020-10-15

Àà   ÐÍ

»º³åÇøÒç³ö

µÈ   ¼¶

¸ßΣ

Ô¶³ÌʹÓÃ

ÊÇ

Ó°Ïì¹æÄ£


 

SonicWallµÄSSL VPN¿ÉÒÔʹԶ³ÌÓû§Çå¾²µØÅþÁ¬ºÍÔËÐй«Ë¾WindowsºÍLinuxϵͳ¼°ÍøÂçÉϵÄÈκÎÓ¦ÓóÌÐò£¬£¬£¬Óû§¿ÉÒÔÇáËÉÉÏ´«ºÍÏÂÔØÎļþ¡¢×°ÖÃÍøÂçÇý¶¯Æ÷ÒÔ¼°»á¼û×ÊÔ´µÈ¡£¡£¡£¡£¡£¡£SonicWallÍøÂçÇå¾²×°±¸NSA¾ßÓÐSSL VPN²¦ºÅ¹¦Ð§£¬£¬£¬¿ÉÒÔͨ¹ýSSL VPN¿Í»§¶ËNextenderÔ¶³Ì»á¼û¹«Ë¾»òÄÚ²¿ÍøÂç¡£¡£¡£¡£¡£¡£

 

0x01 Îó²îÏêÇé

image.png

 

2020Äê10ÔÂ12ÈÕ£¬£¬£¬SonicWallÐû²¼Ç徲ͨ¸æ£¬£¬£¬SonicWall NSAÓÃÓÚ²úÆ·ÖÎÀíºÍSSL VPNÔ¶³Ì»á¼ûµÄHTTP/HTTPSЧÀÍÖб£´æÒ»¸ö»ùÓÚ¿ÍÕ»µÄ»º³åÇøÒç³öÎó²î£¬£¬£¬Îó²î¸ú×ÙΪCVE-2020-5135¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔͨ¹ýʹÓôËÎó²îÏò·À»ðǽ·¢ËͶñÒâÇëÇóµ¼Ö¾ܾøÐ§ÀÍ£¨DoS£©²¢Ö´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£

ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿É×èÖ¹Óû§ÅþÁ¬µ½¹«Ë¾×ÊÔ´£¬£¬£¬²¢µ¼ÖÂ×°±¸Íß½âµÈ¡£¡£¡£¡£¡£¡£×èÖ¹ÏÖÔÚ£¬£¬£¬ShodanËÑË÷µ½ÊÜÓ°ÏìµÄHTTPЧÀÍÆ÷Ö÷»úΪ818£¬£¬£¬694̨¡£¡£¡£¡£¡£¡£

image.png

Îó²îÓ°Ïì¹æÄ££º

SonicOS 6.5.4.7-79n¼°¸üÔç°æ±¾

SonicOS 6.5.1.11-4n¼°¸üÔç°æ±¾

SonicOS 6.0.5.3-93o¼°¸üÔç°æ±¾

SonicOSv 6.5.4.4-44v-21-794¼°¸üÔç°æ±¾

SonicOS 7.0.0.0-1

 

0x02 ´¦Öóͷ£½¨Òé

ÏÖÔÚSonicWallÒÑÐû²¼ÐÞ¸´°æ±¾£¬£¬£¬½¨ÒéʵʱÉý¼¶£º

SonicOS 6.5.4.7-83n

SonicOS 6.5.1.12-1n

SonicOS 6.0.5.3-94o

SonicOS 6.5.4.v-21s-987

µÚ7´ú7.0.0.0-2¼°¸ü¸ß°æ±¾

Á´½ÓµØµã£º

https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2020-0010

ÔÝʱ²½·¥£º

ÔÚÓ¦ÓÃÐÞ²¹³ÌÐò֮ǰ£¬£¬£¬¿ÉÒÔÔÝʱ½«SSL VPNÓëInternet¶Ï¿ªÅþÁ¬¡£¡£¡£¡£¡£¡£

 

0x03 ²Î¿¼Á´½Ó

https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2020-0010

https://www.tripwire.com/state-of-security/vert/sonicwall-vpn-portal-critical-flaw-cve-2020-5135/

https://threatpost.com/critical-sonicwall-vpn-bug/160108/

0x04 ʱ¼äÏß

2020-10-12  SonicWallÊ×´ÎÐû²¼Ç徲ͨ¸æ

2020-10-15  SonicWallÐû²¼¸üÐÂÐÞ¶©

2020-10-15  VSRCÐû²¼Ç徲ͨ¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/

 

 

 

image.png