Òø·å & ˼¿Æ & Citrix & VMware | SD-WANÇå¾²Îó²îͨ¸æ
Ðû²¼Ê±¼ä 2020-12-020x00 Îó²î¸ÅÊö
¿ËÈÕ£¬£¬£¬£¬Realmode LabsµÄÑо¿Ö°Ô±·¢Ã÷ÁËÊг¡ÉÏÅÅÃûǰËĵÄSD-WANµÄ²úÆ·Öб£´æ¶à¸öÇå¾²Îó²î£¬£¬£¬£¬Æä³§ÉÌ»®·ÖÎªÒø·å¡¢Ë¼¿Æ¡¢CitrixºÍVMware¡£¡£¡£¡£Ôڴ˴η¢Ã÷µÄÎó²îÖУ¬£¬£¬£¬Óжà¸ö¿ÉÔì³ÉÔ¶³Ì´úÂëÖ´ÐУ¬£¬£¬£¬ÇÒÎÞÐèÈκÎÉí·ÝÑéÖ¤¼´¿ÉʹÓᣡ£¡£¡£¹¥»÷Õß¿ÉÒÔʹÓÃÕâЩÎó²îÀ´×èµ²»ò¶ñÒâÖ¸µ¼Á÷Á¿£¬£¬£¬£¬ÉõÖÁ¿Éµ¼ÖÂÍøÂçÖÐÖ¹¡£¡£¡£¡£
0x01 Îó²îÏêÇé
²úÆ·Ãû³Æ | CVE ID | Àà ÐÍ | Îó²îÆ·¼¶ | Ô¶³ÌʹÓà |
Òø·åSD-WAN | CVE-2020-12145 | Éí·ÝÑéÖ¤ÈÆ¹ý | ÑÏÖØ | ÊÇ |
CVE-2020-12146 | ·¾¶±éÀú | ¸ßΣ | ÊÇ | |
CVE-2020-12147 | í§ÒâSQLÅÌÎÊ | ¸ßΣ | ÊÇ | |
Citrix SD-WAN | CVE-2020-8271 | ·¾¶±éÀú¡¢Shell×¢Èë | ÑÏÖØ | ÊÇ |
CVE-2020-8272 | Éí·ÝÑéÖ¤ÈÆ¹ý | ¸ßΣ | ÊÇ | |
CVE-2020-8273 | Shell×¢Èë | ¸ßΣ | ÊÇ | |
˼¿ÆViptela vManage
| CVE-2020-27128 | SSRF¡¢í§ÒâÎļþдÈë | ÖÐΣ | ÊÇ |
CVE-2020-27129 | ÏÂÁî×¢Èë | ÖÐΣ | ÊÇ | |
CVE-2020-26073 | Îļþ¶ÁÈ¡¡¢Ä¿Â¼±éÀú | ¸ßΣ | ÊÇ | |
CVE-2020-26074 | ȨÏÞÌáÉý | ¸ßΣ | ·ñ | |
VMware VeloCloud Orchestrator | CVE-2020-4001 | Éí·ÝÑéÖ¤ÈÆ¹ý | ÖÐΣ | ÊÇ |
CVE-2020-3984 | SQL×¢Èë | ¸ßΣ | ÊÇ | |
CVE-2020-4000 | Ŀ¼±éÀú¡¢´úÂëÖ´ÐÐ | ÖÐΣ | ÊÇ |
Òø·åµÄSD-WANÖб£´æÈý¸öÇå¾²Îó²î£¬£¬£¬£¬»®·ÖΪCVE-2020-12145¡¢CVE-2020-12146ºÍCVE-2020-12147£¬£¬£¬£¬ÕâЩÎó²îλÓÚOrchestratorÖ÷ÖÎÀí½çÃæ£¬£¬£¬£¬¿É¼¯ÖпØÖƹ«Ë¾µÄSD-WANÍØÆË¡£¡£¡£¡£¹¥»÷Õß¿ÉÅäºÏʹÓÃÕâÈý¸öÎó²îÀ´¶ÔSD-PWNÍøÂç¾ÙÐй¥»÷¡£¡£¡£¡£
Citrix SD-WANÒÔCakePHP2Ϊ¿ò¼ÜÔÚApacheÉÏÔËÐС£¡£¡£¡£ÓÉÓÚCakePHP2¿ò¼ÜÔÚ´¦Öóͷ£URLʱ±£´æÎÊÌ⣬£¬£¬£¬Citrix SD-WANÖÐÐı£´æÈý¸öÇå¾²Îó²î£¬£¬£¬£¬»®·ÖΪCVE-2020-8271¡¢CVE-2020-8272ºÍCVE-2020-8273£¬£¬£¬£¬ÀÖ³ÉʹÓÃÎó²îµÄ¹¥»÷Õß¿É×¢ÈëshellÏÂÁ£¬£¬£¬×îÖÕ¿ØÖÆÕû¸öÍøÂç¡£¡£¡£¡£
˼¿ÆViptela vManageÊÇ˼¿ÆSD-WAN»ù´¡¼Ü¹¹µÄÖÐÐÄ£¬£¬£¬£¬¿ÉÖÎÀíÍøÂçÖÐËùÓÐÖÕ¶Ë¡£¡£¡£¡£ÓÉÓÚSD-WANÉè¼ÆµÄ¼¯ÖÐÐÔ£¬£¬£¬£¬´ÓÇå¾²½Ç¶ÈÀ´¿´£¬£¬£¬£¬vManageÉϵĶà¸öÎó²îÊôÓÚµ¥µã¹ÊÕÏ¡£¡£¡£¡£
ͨ¹ýʹÓÃCVE-2020-27128¡¢CVE-2020-27129¡¢CVE-2020-26073ºÍCVE-2020-26074£¬£¬£¬£¬¹¥»÷ÕßÄܹ»Ô¶³ÌÖ´ÐдúÂëÀ´»ñµÃvManageµÄ¿ØÖÆÈ¨£¬£¬£¬£¬¶ø¸ÃÖÕ¶Ëͨ³£ÍйÜÔÚÔÆÇéÐÎÖС£¡£¡£¡£¹¥»÷Õß²»ÐèÒªÈκÎÉèÖü´¿ÉʹÓÃÕâЩÎó²î¡£¡£¡£¡£
VMware VeloCloud OrchestratorÊÇÅþÁ¬µ½±ßÑØÂ·ÓÉÆ÷²¢¼¯ÖпØÖƵÄÍøÂçÍØÆË¡£¡£¡£¡£VMware VeloCloud»ù´¡¼Ü¹¹ÓÉnginx×é³É£¬£¬£¬£¬ÆäÖ÷ÒªÓÃ×÷node.jsЧÀÍÆ÷µÄ·´ÏòÊðÀí£¬£¬£¬£¬ÓÉÓÚÆä½Ó¿Ú±£´æÇå¾²Îó²î£¬£¬£¬£¬»®·ÖΪCVE-2020-4001¡¢CVE-2020-3984ºÍCVE-2020-4000¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔʹÓÃÕâЩÎó²îÐÞ¸ÄVelocloudµÇ¼Ãû»òÖØÖÃÃÜÂë¡£¡£¡£¡£
²¿·ÖÎó²îÏêÇéÈçÏ£º
Òø·åSD-WANÉí·ÝÑéÖ¤ÈÆ¹ýÎó²î£¨CVE-2020-12145£©
ÓÉÓÚ¶ÔδִÐÐÉí·ÝÑé֤ȷµ±ÌïÖ÷»úµÄAPIŲÓõÄÌØÊâ´¦Öóͷ£±£´æÇå¾²ÎÊÌ⣬£¬£¬£¬ÈκÎÒÔ¡°localhost¡±×÷ΪÆäHTTP Host±êÍ·µÄÇëÇó¶¼Öª×ã¼ì²éÒªÇ󣬣¬£¬£¬ÕâÈÝÒ×µ¼ÖÂÉí·ÝÑéÖ¤ÈÆ¹ý¡£¡£¡£¡£¿£¿£¿£¿£¿£¿£¿ÉʹÓÃrequest.getBaseUri().getHost().equals(¡°localhost¡±)ÏÂÁî¾ÙÐÐlocalhost¼ì²é¡£¡£¡£¡£
Citrix SD-WAN·¾¶±éÀúºÍshell×¢ÈëÎó²î£¨CVE-2020-8271£©
ÓÉÓÚ/collector/diagnostics/stop_ping¶Ëµã¶ÁÈ¡"/tmp/pid_" . $req_idÎļþ£¬£¬£¬£¬²¢ÔÚshell_execŲÓÃÖÐʹÓÃÆäÄÚÈÝ£¬£¬£¬£¬¶øÃ»ÓжÔÔÊÐí·¾¶±éÀúµÄ$req_id¾ÙÐÐÕûÀí¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔ½«¶ñÒâÎļþÉÏ´«µ½Èκεط½²¢Ö´ÐÐí§ÒâshellÏÂÁî¡£¡£¡£¡£
0x02 ´¦Öóͷ£½¨Òé
ÏÖÔÚÏà¹Ø³§ÉÌÒѾÐû²¼¸üУ¬£¬£¬£¬½¨Òé²Î¿¼¹Ù·½µÄ½¨Òéʵʱ¸üС£¡£¡£¡£
0x03 ²Î¿¼Á´½Ó
https://www.securityweek.com/sd-wan-product-vulnerabilities-allow-hackers-steer-traffic-shut-down-networks
https://medium.com/realmodelabs/sd-pwn-part-4-vmware-velocloud-the-last-takeover-a7016f9a9175
https://tools.cisco.com/security/center/publicationListing.x?product=Cisco&sort=-day_sir&offset=20#~Vulnerabilities
https://www.vmware.com/security/advisories/VMSA-2020-0025.html
0x04 ʱ¼äÏß
2020-12-01 VSRCÐû²¼Ç徲ͨ¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/