¡¾Îó²îͨ¸æ¡¿CVE-2020-10148 SolarWinds Orion RCEÎó²î

Ðû²¼Ê±¼ä 2020-12-28

0x00 Îó²î¸ÅÊö

CVE  ID

CVE-2020-10148

ʱ   ¼ä

2020-12-28

Àà   ÐÍ

RCE

µÈ   ¼¶

¸ßΣ

Ô¶³ÌʹÓÃ

ÊÇ

Ó°Ïì¹æÄ£


 

0x01 Îó²îÏêÇé

image.png

 

SolarWinds Orion PlatformÊÇ»ù´¡ÉèÊ©ºÍϵͳÖÎÀí²úÆ·Ì×¼þ¡£¡£ ¡£¡£¡£¡£¡£SolarWinds Orion API±»Ç¶Èëµ½OrionÄÚºËÖÐ £¬£¬£¬£¬ÓÃÓÚÓëËùÓÐSolarWinds Orionƽ̨²úÆ·¾ÙÐÐÅþÁ¬¡£¡£ ¡£¡£¡£¡£¡£

¿ËÈÕ £¬£¬£¬£¬SolarWinds Orion APIÖб»Åû¶±£´æÒ»¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2020-10148£©¡£¡£ ¡£¡£¡£¡£¡£¸ÃÎó²îÊÇÓÉÓÚSolarWinds Orion APIÉí·ÝÑéÖ¤Äܹ»±»Èƹý £¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔͨ¹ýÔÚRequest.PathInfo URIÇëÇóÖÐʹÓÃÌØ¶¨²ÎÊýÀ´Ê¹ÓôËÎó²î £¬£¬£¬£¬×îÖÕ¹¥»÷Õß¿ÉÒÔÔ¶³ÌÖ´ÐÐδ¾­Éí·ÝÑéÖ¤µÄAPIÏÂÁî¡£¡£ ¡£¡£¡£¡£¡£ÓÈÆäÊǵ±¹¥»÷Õ߸½¼ÓÒ»¸öPathInfoº¯ÊýµÄ²ÎÊýΪWebResource.adx¡¢ScriptResource.adx¡¢i18n.ashx¡¢»òSkipi18nµÄÇëÇó¸øSolarWinds OrionЧÀÍÆ÷ʱ £¬£¬£¬£¬SolarWinds¿ÉÒÔÉèÖÃSkipAuthorization flag £¬£¬£¬£¬ÕâÑù¿ÉÒÔÔÚ²»ÐèÒªÉí·ÝÑéÖ¤µÄÇéÐÎÏ´¦Öóͷ£APIÇëÇ󡣡£ ¡£¡£¡£¡£¡£

0x02 ´¦Öóͷ£½¨Òé

ÏÖÔÚ £¬£¬£¬£¬SolarWindsÒѾ­Ðû²¼ÁË´ËÎó²îµÄÇå¾²¸üР£¬£¬£¬£¬½¨Ò齫SolarWinds Orion¸üÐÂÖÁÈçϰ汾£º

2019.4 HF 6£¨2020Äê12ÔÂ14ÈÕÐû²¼£©

2020.2.1 HF 2£¨2020Äê12ÔÂ15ÈÕÐû²¼£©

2019.2 SUPERNOVA²¹¶¡£¡£ ¡£¡£¡£¡£¡£¨2020Äê12ÔÂ23ÈÕÐû²¼£©

2018.4 SUPERNOVA²¹¶¡£¡£ ¡£¡£¡£¡£¡£¨2020Äê12ÔÂ23ÈÕÐû²¼£©

2018.2 SUPERNOVA²¹¶¡£¡£ ¡£¡£¡£¡£¡£¨2020Äê12ÔÂ23ÈÕÐû²¼£©

ÏÂÔØÁ´½Ó£º

https://www.solarwinds.com/securityadvisory

 

0x03 ²Î¿¼Á´½Ó

https://kb.cert.org/vuls/id/843464

https://github.com/solarwinds/OrionSDK/wiki

https://cyber.dhs.gov/ed/21-01/

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-10148

 

0x04 ʱ¼äÏß

2020-12-26  CERT/CCÅû¶Îó²î

2020-12-27  CERT/CC¸üÐÂÎó²î

2020-12-28  VSRCÐû²¼Ç徲ͨ¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/

image.png