SolarWinds NPMÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-31474£©
Ðû²¼Ê±¼ä 2021-05-260x00 Îó²î¸ÅÊö
CVE ID | CVE-2021-31474 | ʱ ¼ä | 2021-05-26 |
Àà ÐÍ | RCE | µÈ ¼¶ | ÑÏÖØ |
Ô¶³ÌʹÓà | ÊÇ | Ó°Ïì¹æÄ£ | 2020.2.1 |
PoC/EXP | δ¹ûÕæ | ÔÚҰʹÓà | ·ñ |
0x01 Îó²îÏêÇé
SolarWinds Network Performance Monitor£¨NPM£©ÊǼ¯ÍøÂç¼à²â¡¢×°±¸ÐÔÄÜά»¤ÖÎÀí¡¢¹ÊÕÏ¼à¿Ø¡¢ÍøÂçʵʱÁ÷Á¿¼à¿ØºÍÀúÊ·Êý¾Ýͳ¼Æ¡¢»ã×ܺÍÀúÊ·Êý¾ÝÆÊÎöµÈ¹¦Ð§ÓÚÒ»ÌåµÄÍøÂçÖÎÀíϵͳ¡£¡£¡£¡£¡£
2021Äê05ÔÂ20ÈÕ£¬£¬£¬Zero Day Initiative¹ûÕæÅû¶ÁËSolarWinds Network Performance MonitorÖеÄÒ»¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-31474£©£¬£¬£¬ÆäCVSSÆÀ·ÖΪ9.8¡£¡£¡£¡£¡£
¸ÃÎó²î±£´æÓÚSolarWinds.Serialization¿âÖУ¬£¬£¬ÓÉÓÚ¶ÔÓû§ÌṩµÄÊý¾Ýȱ·¦×¼È·ÑéÖ¤£¬£¬£¬µ¼Ö²»ÐÅÈÎÊý¾ÝµÄ·´ÐòÁл¯¡£¡£¡£¡£¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔÔÚϵͳÉÏÏÂÎÄÖÐÖ´ÐÐí§Òâ´úÂ룬£¬£¬¶øÎÞÐè¾ÓÉÉí·ÝÑéÖ¤¡£¡£¡£¡£¡£
Ó°Ïì¹æÄ£
SolarWinds Network Performance Monitor 2020.2.1
0x02 ´¦Öóͷ£½¨Òé
ÏÖÔÚSolarWindsÒѾÐÞ¸´Á˸ÃÎó²î£¬£¬£¬½¨Ò龡¿ì¾ÙÐÐÉý¼¶¸üС£¡£¡£¡£¡£
ÏÂÔØÁ´½Ó£º
https://documentation.solarwinds.com/en/success_center/sam/content/release_notes/sam_2020-2-5_release_notes.htm
0x03 ²Î¿¼Á´½Ó
https://www.zerodayinitiative.com/advisories/ZDI-21-602/
https://nvd.nist.gov/vuln/detail/CVE-2021-31474
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-31474
0x04 ʱ¼äÏß
2021-05-20 ZDI¹ûÕæÅû¶Îó²î
2021-05-26 VSRCÐû²¼Ç徲ͨ¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/