SolarWinds NPMÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-31474£©

Ðû²¼Ê±¼ä 2021-05-26

0x00 Îó²î¸ÅÊö

CVE  ID

CVE-2021-31474

ʱ    ¼ä

2021-05-26

Àà   ÐÍ

RCE

µÈ    ¼¶

ÑÏÖØ

Ô¶³ÌʹÓÃ

ÊÇ

Ó°Ïì¹æÄ£

2020.2.1

PoC/EXP

δ¹ûÕæ

ÔÚҰʹÓÃ

·ñ

 

0x01 Îó²îÏêÇé

image.png

 

SolarWinds Network Performance Monitor£¨NPM£©ÊǼ¯ÍøÂç¼à²â¡¢×°±¸ÐÔÄÜά»¤ÖÎÀí¡¢¹ÊÕÏ¼à¿Ø¡¢ÍøÂçʵʱÁ÷Á¿¼à¿ØºÍÀúÊ·Êý¾Ýͳ¼Æ¡¢»ã×ܺÍÀúÊ·Êý¾ÝÆÊÎöµÈ¹¦Ð§ÓÚÒ»ÌåµÄÍøÂçÖÎÀíϵͳ¡£¡£¡£¡£¡£

2021Äê05ÔÂ20ÈÕ£¬£¬£¬Zero Day Initiative¹ûÕæÅû¶ÁËSolarWinds Network Performance MonitorÖеÄÒ»¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-31474£©£¬£¬£¬ÆäCVSSÆÀ·ÖΪ9.8¡£¡£¡£¡£¡£

¸ÃÎó²î±£´æÓÚSolarWinds.Serialization¿âÖУ¬£¬£¬ÓÉÓÚ¶ÔÓû§ÌṩµÄÊý¾Ýȱ·¦×¼È·ÑéÖ¤£¬£¬£¬µ¼Ö²»ÐÅÈÎÊý¾ÝµÄ·´ÐòÁл¯¡£¡£¡£¡£¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔÔÚϵͳÉÏÏÂÎÄÖÐÖ´ÐÐí§Òâ´úÂ룬£¬£¬¶øÎÞÐè¾­ÓÉÉí·ÝÑéÖ¤¡£¡£¡£¡£¡£

 

Ó°Ïì¹æÄ£

SolarWinds Network Performance Monitor 2020.2.1

 

0x02 ´¦Öóͷ£½¨Òé

ÏÖÔÚSolarWindsÒѾ­ÐÞ¸´Á˸ÃÎó²î£¬£¬£¬½¨Ò龡¿ì¾ÙÐÐÉý¼¶¸üС£¡£¡£¡£¡£

ÏÂÔØÁ´½Ó£º

https://documentation.solarwinds.com/en/success_center/sam/content/release_notes/sam_2020-2-5_release_notes.htm

 

0x03 ²Î¿¼Á´½Ó

https://www.zerodayinitiative.com/advisories/ZDI-21-602/

https://nvd.nist.gov/vuln/detail/CVE-2021-31474

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-31474

 

0x04 ʱ¼äÏß

2021-05-20  ZDI¹ûÕæÅû¶Îó²î

2021-05-26  VSRCÐû²¼Ç徲ͨ¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/

image.png