Palo Alto Networks Cortex XSOARδÊÚȨ»á¼ûÎó²î£¨CVE-2021-3044£©

Ðû²¼Ê±¼ä 2021-06-23

0x00 Îó²î¸ÅÊö

CVE   ID

CVE-2021-3044

ʱ    ¼ä

2021-06-23

Àà    ÐÍ

δÊÚȨ»á¼û

µÈ    ¼¶

ÑÏÖØ

Ô¶³ÌʹÓÃ

ÊÇ

Ó°Ïì¹æÄ£


¹¥»÷ÖØÆ¯ºó

µÍ

¿ÉÓÃÐÔ

¸ß

Óû§½»»¥

ÎÞ

ËùÐèȨÏÞ

ÎÞ

PoC/EXP

δ¹ûÕæ

ÔÚҰʹÓÃ

·ñ

 

0x01 Îó²îÏêÇé

image.png

Cortex? XSOARÊÇÈ«ÇòÍøÂçÇå¾²Ïòµ¼ÆóÒµPalo Alto NetworksÍÆ³öµÄÒ»¸öÈ«ÐÂÀ©Õ¹µÄÇå¾²±àÅÅ¡¢×Ô¶¯»¯ÓëÏìӦƽ̨£¬£¬£¬£¬£¬£¬²¢¼¯³ÉÁËÍþвÇ鱨ÖÎÀí¹¦Ð§£¬£¬£¬£¬£¬£¬´Ó¶øÎªÆóÒµÇå¾²Ìṩ¼´Ê±¡¢ÖÜÈ«µÄÍþв·ÀÓù¡£¡£¡£¡£¡£¡£¡£

2021Äê06ÔÂ22ÈÕ£¬£¬£¬£¬£¬£¬Palo Alto NetworksÐû²¼Ç徲ͨ¸æ£¬£¬£¬£¬£¬£¬ÐÞ¸´ÁËCortex XSOARÖеÄÒ»¸öδÊÚȨ»á¼ûÎó²î£¨CVE-2021-3044£©£¬£¬£¬£¬£¬£¬¸ÃÎó²îµÄCVSSv3ÆÀ·ÖΪ9.8¡£¡£¡£¡£¡£¡£¡£Î´¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÄܹ»Ê¹ÓôËÎó²îͨ¹ýREST APIÖ´ÐÐδ¾­ÊÚȨµÄ»á¼û¡£¡£¡£¡£¡£¡£¡£

¸ÃÎó²î½ö±£´æÓÚÉèÖÃÁ˻µÄ¼¯³ÉAPI KeyµÄCortex XSOAR¡£¡£¡£¡£¡£¡£¡£¿£¿£¿ £¿ÉÒÔ´ÓCortex XSOAR Web ¿Í»§¶ËÑ¡Ôñ¡®Settings > Integration > API Keys¡¯ À´Éó²éÉèÖÃÊÇ·ñÊܵ½Ó°Ïì¡£¡£¡£¡£¡£¡£¡£


Ó°Ïì¹æÄ£

Cortex XSOAR 6.1.0£ºbuilds >= 1016923 and < 1271064

Cortex XSOAR 6.2.0£ºbuilds < 1271065

 

0x02 ´¦Öóͷ£½¨Òé

ÏÖÔÚ´ËÎó²îÒѾ­ÐÞ¸´£¬£¬£¬£¬£¬£¬½¨Òé²Î¿¼Ï±íʵʱÉý¼¶¸üС£¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬ÓÉPalo Alto NetworksÍйܵÄËùÓÐCortex XSOARʵÀý¶¼ÒÑÉý¼¶£¬£¬£¬£¬£¬£¬²»ÐèÒªÔÙÖ´ÐÐÆäËü²Ù×÷¡£¡£¡£¡£¡£¡£¡£

°æ±¾

ÊÜÓ°Ïì°æ±¾

²»ÊÜÓ°Ïì°æ±¾

Cortex XSOAR 6.2.0

< 1271065

>= 1271065

Cortex XSOAR 6.1.0

>= 1016923 and < 1271064

< 1016923£¬£¬£¬£¬£¬£¬ >= 1271064

Cortex XSOAR 6.0.2

None

all

Cortex XSOAR 6.0.1

None

all

Cortex XSOAR 6.0.0

None

all

Cortex XSOAR 5.5.0

None

all

 

ÏÂÔØÁ´½Ó£º

https://support.paloaltonetworks.com/support

 

»º½â²½·¥

×÷·ÏËùÓлµÄ¼¯³É API Key£¬£¬£¬£¬£¬£¬´ÓCortex XSOAR web ¿Í»§¶ËµÄSettings > Integration > API Keys£¬£¬£¬£¬£¬£¬È»ºó×÷·Ïÿ¸öAPI Key¡£¡£¡£¡£¡£¡£¡£¿£¿£¿ £¿ÉÒÔ½«Cortex XSOARÉý¼¶µ½Àο¿°æ±¾ºó½¨ÉèеÄAPI Key¡£¡£¡£¡£¡£¡£¡£

ÏÞÖÆ¶ÔCortex XSOARЧÀÍÆ÷µÄÍøÂç»á¼û£¬£¬£¬£¬£¬£¬Ö»ÔÊÐíÊÜÐÅÈεÄÓû§»á¼û¡£¡£¡£¡£¡£¡£¡£

 

0x03 ²Î¿¼Á´½Ó

https://security.paloaltonetworks.com/CVE-2021-3044

https://security.paloaltonetworks.com/

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3044

 

0x04 ʱ¼äÏß

2021-06-22  Palo Alto NetworksÐû²¼Ç徲ͨ¸æ

2021-06-23  VSRCÐû²¼Ç徲ͨ¸æ

 

0x05 ¸½Â¼

CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/

image.png