Palo Alto Networks Cortex XSOARδÊÚȨ»á¼ûÎó²î£¨CVE-2021-3044£©
Ðû²¼Ê±¼ä 2021-06-230x00 Îó²î¸ÅÊö
CVE ID | CVE-2021-3044 | ʱ ¼ä | 2021-06-23 |
Àà ÐÍ | δÊÚȨ»á¼û | µÈ ¼¶ | ÑÏÖØ |
Ô¶³ÌʹÓà | ÊÇ | Ó°Ïì¹æÄ£ | |
¹¥»÷ÖØÆ¯ºó | µÍ | ¿ÉÓÃÐÔ | ¸ß |
Óû§½»»¥ | ÎÞ | ËùÐèȨÏÞ | ÎÞ |
PoC/EXP | δ¹ûÕæ | ÔÚҰʹÓà | ·ñ |
0x01 Îó²îÏêÇé
Cortex? XSOARÊÇÈ«ÇòÍøÂçÇå¾²Ïòµ¼ÆóÒµPalo Alto NetworksÍÆ³öµÄÒ»¸öÈ«ÐÂÀ©Õ¹µÄÇå¾²±àÅÅ¡¢×Ô¶¯»¯ÓëÏìӦƽ̨£¬£¬£¬£¬£¬£¬²¢¼¯³ÉÁËÍþвÇ鱨ÖÎÀí¹¦Ð§£¬£¬£¬£¬£¬£¬´Ó¶øÎªÆóÒµÇå¾²Ìṩ¼´Ê±¡¢ÖÜÈ«µÄÍþв·ÀÓù¡£¡£¡£¡£¡£¡£¡£
2021Äê06ÔÂ22ÈÕ£¬£¬£¬£¬£¬£¬Palo Alto NetworksÐû²¼Ç徲ͨ¸æ£¬£¬£¬£¬£¬£¬ÐÞ¸´ÁËCortex XSOARÖеÄÒ»¸öδÊÚȨ»á¼ûÎó²î£¨CVE-2021-3044£©£¬£¬£¬£¬£¬£¬¸ÃÎó²îµÄCVSSv3ÆÀ·ÖΪ9.8¡£¡£¡£¡£¡£¡£¡£Î´¾Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÄܹ»Ê¹ÓôËÎó²îͨ¹ýREST APIÖ´ÐÐδ¾ÊÚȨµÄ»á¼û¡£¡£¡£¡£¡£¡£¡£
¸ÃÎó²î½ö±£´æÓÚÉèÖÃÁ˻µÄ¼¯³ÉAPI KeyµÄCortex XSOAR¡£¡£¡£¡£¡£¡£¡£¿£¿£¿£¿ÉÒÔ´ÓCortex XSOAR Web ¿Í»§¶ËÑ¡Ôñ¡®Settings > Integration > API Keys¡¯ À´Éó²éÉèÖÃÊÇ·ñÊܵ½Ó°Ïì¡£¡£¡£¡£¡£¡£¡£
Ó°Ïì¹æÄ£
Cortex XSOAR 6.1.0£ºbuilds >= 1016923 and < 1271064
Cortex XSOAR 6.2.0£ºbuilds < 1271065
0x02 ´¦Öóͷ£½¨Òé
ÏÖÔÚ´ËÎó²îÒѾÐÞ¸´£¬£¬£¬£¬£¬£¬½¨Òé²Î¿¼Ï±íʵʱÉý¼¶¸üС£¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬ÓÉPalo Alto NetworksÍйܵÄËùÓÐCortex XSOARʵÀý¶¼ÒÑÉý¼¶£¬£¬£¬£¬£¬£¬²»ÐèÒªÔÙÖ´ÐÐÆäËü²Ù×÷¡£¡£¡£¡£¡£¡£¡£
°æ±¾ | ÊÜÓ°Ïì°æ±¾ | ²»ÊÜÓ°Ïì°æ±¾ |
Cortex XSOAR 6.2.0 | < 1271065 | >= 1271065 |
Cortex XSOAR 6.1.0 | >= 1016923 and < 1271064 | < 1016923£¬£¬£¬£¬£¬£¬ >= 1271064 |
Cortex XSOAR 6.0.2 | None | all |
Cortex XSOAR 6.0.1 | None | all |
Cortex XSOAR 6.0.0 | None | all |
Cortex XSOAR 5.5.0 | None | all |
ÏÂÔØÁ´½Ó£º
https://support.paloaltonetworks.com/support
»º½â²½·¥
×÷·ÏËùÓлµÄ¼¯³É API Key£¬£¬£¬£¬£¬£¬´ÓCortex XSOAR web ¿Í»§¶ËµÄSettings > Integration > API Keys£¬£¬£¬£¬£¬£¬È»ºó×÷·Ïÿ¸öAPI Key¡£¡£¡£¡£¡£¡£¡£¿£¿£¿£¿ÉÒÔ½«Cortex XSOARÉý¼¶µ½Àο¿°æ±¾ºó½¨ÉèеÄAPI Key¡£¡£¡£¡£¡£¡£¡£
ÏÞÖÆ¶ÔCortex XSOARЧÀÍÆ÷µÄÍøÂç»á¼û£¬£¬£¬£¬£¬£¬Ö»ÔÊÐíÊÜÐÅÈεÄÓû§»á¼û¡£¡£¡£¡£¡£¡£¡£
0x03 ²Î¿¼Á´½Ó
https://security.paloaltonetworks.com/CVE-2021-3044
https://security.paloaltonetworks.com/
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3044
0x04 ʱ¼äÏß
2021-06-22 Palo Alto NetworksÐû²¼Ç徲ͨ¸æ
2021-06-23 VSRCÐû²¼Ç徲ͨ¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/