CVE-2020-2021 | PAN-OS SAMLÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶¹«¸æ
°ä²¼¹¦·ò 2020-06-300x00 ·ì϶¸ÅÊö
|
CVE ID |
CVE-2020-2021 |
ʱ ¼ä |
2020-06-30 |
| Àà ÐÍ |
AB |
µÈ ¼¶ |
ÑϳÁ |
|
Ô¶³ÌÀûÓà |
ÊÇ |
Ó°ÏìÁìÓò |
|
0x01 ·ì϶ÏêÇé
2020Äê6ÔÂ29ÈÕ£¬£¬£¬£¬£¬£¬Palo Alto Networks¹Ù·½°ä²¼°²È«²¼¸æ£¬£¬£¬£¬£¬£¬½¨¸´ÁËÒ»¸öPAN-OS SAMLÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶£¨CVE-2020-2021£©¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÎÞÐè¾¹ýÉí·ÝÑéÖ¤¼´¿ÉÀûÓø÷ì϶½Ó¼ûÉ豸¡£¡£¡£¡£¡£¡£¡£¡£
ÔÚÆôÓð²È«ÐÔ¶ÏÑÔÏóÕ÷˵»°£¨SAML£©Éí·ÝÑéÖ¤²¢½ûÓá°ÑéÖ¤Éí·ÝÌṩÉÌÖ¤Ê顱ѡÏîʱ£¬£¬£¬£¬£¬£¬ÓÉÓÚPAN-OS SAMLÉí·ÝÑéÖ¤¹ý³ÌÖÐûÓÐÕýÈ·µØÑéÖ¤ÊðÃû£¬£¬£¬£¬£¬£¬µ¼ÖÂδ¾Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÄܹ»¸ü¸ÄPAN OSµÄÉèÖúÍÖ°ÄÜ¡£¡£¡£¡£¡£¡£¡£¡£Ç°ÌáǰÌáÊǹ¥»÷Õß±ØÐëÄܹ»½Ó¼ûÒ×Êܹ¥»÷µÄ·þÎñÆ÷£¬£¬£¬£¬£¬£¬ÄÜÁ¦ÀûÓô˷ì϶¡£¡£¡£¡£¡£¡£¡£¡£
¸Ã·ì϶ÊÇÔÚCVSSv3ÑϳÁµÈ¼¶ÖлñµÃ10·ÖµÄº±¼û·ì϶֮һ£¬£¬£¬£¬£¬£¬¼È²»±ØÒª¸ß¼¶¼¼Êõ¼¼Êõ£¬£¬£¬£¬£¬£¬ÓÖÄܹ»Í¨¹ýInternet½øÐÐÔ¶³ÌÀûÓᣡ£¡£¡£¡£¡£¡£¡£ÃÀ¹úÍøÂç˾ÁҪÇóËùÓÐÊÜCVE-2020-2021Ó°ÏìµÄÉ豸Á¢¼´½¨¸´¸Ã·ì϶£¬£¬£¬£¬£¬£¬²¢°µÊ¾±í¹úµÄAPT×éÖ¯¿ÉÄܺܿì¾Í»á³¢ÊÔÀûÓø÷ì϶ÌáÒé¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£
Äܹ»Í¨¹ý»ùÓÚSAMLµÄµ¥µãµÇ¼£¨SSO£©Éí·ÝÑéÖ¤±£»£»£»£»£»£»¤µÄ×ÊÔ´ÓУº
GlobalProtect Gateway,
GlobalProtect Portal,
GlobalProtect Clientless VPN,
Authentication and Captive Portal,
PAN-OS next-generation firewalls (PA-Series, VM-Series) and Panorama web interfaces
Prisma Access
¶ÔÓÚGlobalProtectÍø¹Ø¡¢GlobalProtectÃÅ»§¡¢ÎÞ¿Í»§¶ËVPN¡¢Captive PortalºÍPrisma Access£¬£¬£¬£¬£¬£¬Î´¾Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÄܹ»Í¨¹ýÍøÂç½Ó¼û·þÎñÆ÷ÉÏÊܱ£»£»£»£»£»£»¤µÄ×ÊÔ´£¬£¬£¬£¬£¬£¬²»»áÓ°ÏìÍø¹Ø£¬£¬£¬£¬£¬£¬ÃÅ»§»òVPN·þÎñÆ÷µÄÆëÈ«ÐԺͿÉÓÃÐÔ£¬£¬£¬£¬£¬£¬µ«¹¥»÷ÕßÎÞ·¨²é³»ò´Û¸Äͨ³£Óû§µÄ»á»°¡£¡£¡£¡£¡£¡£¡£¡£ÕâÊÇÒ»¸öÑϳÁ¼¶´ËÍâ·ì϶£¬£¬£¬£¬£¬£¬CVSSÆÀ·Ö10.0¡£¡£¡£¡£¡£¡£¡£¡£
¶ÔÓÚPAN-OSºÍPanorama Web½çÃæ£¬£¬£¬£¬£¬£¬ÈôÊÇδ¾Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÓµÓжÔPAN-OS»òPanorama Web½çÃæµÄ½Ó¼ûȨ£¬£¬£¬£¬£¬£¬¼´Äܹ»ÖÎÀíÔ±Éí·ÝµÇ¼²¢Ö´ÐÐÖÎÀí²Ù×÷¡£¡£¡£¡£¡£¡£¡£¡£ÕâÊÇÒ»¸öÑϳÁ¼¶´ËÍâ·ì϶£¬£¬£¬£¬£¬£¬CVSSÆÀ·Ö10.0£¬£¬£¬£¬£¬£¬ÈôÊǽö¿Éͨ¹ýÊÜÏÞÖÎÀíÍøÂç½Ó¼ûWeb½çÃæ£¬£¬£¬£¬£¬£¬ÔòCVSSÆÀ·Ö9.6¡£¡£¡£¡£¡£¡£¡£¡£
ÒÔÏÂÊÇCVE-2020-2021·ì϶ӰÏìµÄPalo Alto Networks PAN-OS°æ±¾£º
ÇëÓйØÓû§¾¡¿ì²é¿´ÅäÖ㬣¬£¬£¬£¬£¬ÊµÊ±È·ÈÏÊÇ·ñÊܵ½¸Ã·ì϶ӰÏ죬£¬£¬£¬£¬£¬¾ßÌå²½ÖèÈçÏ£º
? ½öµ±ÆôÓÃÁËSAMLÉí·ÝÑéÖ¤²¢ÇÒÔÚ¡°SAMLÉí·ÝÌṩÉÌ·þÎñÆ÷ÅäÖÃÎļþ¡±ÖнûÓá°Éí·ÝÌṩÉÌÖ¤Ê顱ѡÏîʱ£¬£¬£¬£¬£¬£¬ÄÜÁ¦¹»ÀûÓø÷ì϶¡£¡£¡£¡£¡£¡£¡£¡£
? ÈôÊDz»Ê¹ÓÃSAML½øÐÐÉí·ÝÑéÖ¤£¬£¬£¬£¬£¬£¬ÔòÎÞ·¨ÀûÓø÷ì϶¡£¡£¡£¡£¡£¡£¡£¡£
? ÈôÊÇÔÚSAMLÉí·ÝÌṩÉÌ·þÎñÆ÷ÅäÖÃÎļþÖÐÆôÓÃÁË¡°ÑéÖ¤Éí·ÝÌṩÉÌÖ¤Ê顱ѡÏ£¬£¬£¬£¬£¬ÔòÎÞ·¨ÀûÓø÷ì϶¡£¡£¡£¡£¡£¡£¡£¡£
¹ØÓÚÈôºÎ²é³·þÎñÆ÷ÅäÖò¢Ö´Ðлº½â´ëÊ©µÄ×¢Ã÷£¬£¬£¬£¬£¬£¬Çë²Î¿¼£ºhttps://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000008UXK
? Òª²é³ÊÇ·ñÔÚ·À»ðǽÉÏÆôÓÃÁËSAMLÉí·ÝÑéÖ¤£¬£¬£¬£¬£¬£¬Çë²Î¿¼Device > Server Profiles > SAML Identity Provider£»£»£»£»£»£»
? Òª²é³ÊÇ·ñΪPanoramaÖÎÀíÔ±Éí·ÝÑéÖ¤ÆôÓÃÁËSAMLÉí·ÝÑéÖ¤£¬£¬£¬£¬£¬£¬Çë²Î¿¼Panorama >Server Profiles > SAML Identity Provider£»£»£»£»£»£»
? Òª²é³ÊÇ·ñΪPanoramaÖÎÀíµÄ·À»ðǽÆôÓÃÁËSAMLÉí·ÝÑéÖ¤£¬£¬£¬£¬£¬£¬Çë²Î¿¼Device > [template]> Server Profiles > SAML Identity Provider¡£¡£¡£¡£¡£¡£¡£¡£
ƾ¾ÝÅäÖ㬣¬£¬£¬£¬£¬ÈκÎδ¾ÊÚȨµÄ½Ó¼û³ÇÊмͼÔÚϵͳÈÕÖ¾ÖУ¬£¬£¬£¬£¬£¬µ«ÊǺÜÄÑ·Ö±æÓÐЧµÇ¼ÃûºÍ¶ñÒâµÇ¼Ãû¡£¡£¡£¡£¡£¡£¡£¡£
0x02 ´ëÖý¨Òé
¹Ù·½ÒѰ䲼PAN-OS 8.1.15¡¢PAN-OS 9.0.9¡¢PAN-OS 9.1.3ºÍ¸ü¸ß°æ±¾£¬£¬£¬£¬£¬£¬ÇëÓйØÓû§ÊµÊ±Éý¼¶¡£¡£¡£¡£¡£¡£¡£¡£
°ÑÎÈ£ºÔÚÉý¼¶µ½¹Ì¶¨°æ±¾Ö®Ç°£¬£¬£¬£¬£¬£¬ÇëÈ·±£½«SAMLÉí·ÝÌṩÉ̵ÄÊðÃûÖ¤ÊéÅäÖÃΪ¡°Éí·ÝÌṩÉÌÖ¤Ê顱£¬£¬£¬£¬£¬£¬ÒÔÈ·±£Óû§Äܹ»³ÖÐø½øÐÐÉí·ÝÑéÖ¤¡£¡£¡£¡£¡£¡£¡£¡£Çë²Î¿¼£ºhttps://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/authentication/configure-saml-authentication
? PAN-OSÉý¼¶Ö®Ç°ºÍÖ®ºóËùÐèµÄËùÓвÙ×÷µÄ¾ßÌåÐÅÏ¢£¬£¬£¬£¬£¬£¬Çë²Î¿¼£ºhttps://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000008UXK
? ΪÁ˶ϸùGlobalProtectÃÅ»§ºÍÍø¹ØÉϵÄδÊÚȨ»á»°£¬£¬£¬£¬£¬£¬Prisma Accessͨ¹ýPanoramaÖÎÀí£¬£¬£¬£¬£¬£¬ÇëʹÓÃPanorama¸ü¸ÄAuthentication Override cookieµÄÅäÖᣡ£¡£¡£¡£¡£¡£¡£Çë²Î¿¼£ºhttps://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000008UXy
³ÁÐÂÆô¶¯·À»ðǽºÍPanoramaÄܹ»¶Ï¸ùWeb½çÃæÉϵÄÈκÎδ¾ÊÚȨµÄ»á»°¡£¡£¡£¡£¡£¡£¡£¡£
? Òª¶Ï¸ùCaptive PortalÖеÄÈκÎδÊÚȨÓû§»á»°£¬£¬£¬£¬£¬£¬ÇëÖ´ÐÐÒÔϲ½Ö裺
ÔËÐÐÒÔϺÅÁî
show user ip-user-mapping all type SSO
¶ÔÓÚ·µ»ØµÄËùÓÐIP£¬£¬£¬£¬£¬£¬ÇëÔËÐÐÒÔÏÂÁ½¸öºÅÁîÒԶϸùÓû§£º
? PAN-OS 8.0ÒÑÖÕÖ¹Ö§³Ö£¨½ØÖÁ2019Äê10ÔÂ31ÈÕ£©£¬£¬£¬£¬£¬£¬²»ÔÙÊØ»¤¡£¡£¡£¡£¡£¡£¡£¡£
ËùÓÐPrisma Access·þÎñ¾ùÒÑÉý¼¶ÒÔ½â¾ö´ËÎÊÌ⣬£¬£¬£¬£¬£¬²¢ÇÒ²»ÔÙÒ×Êܹ¥»÷¡£¡£¡£¡£¡£¡£¡£¡£Prisma Access¿Í»§²»±ØÒª¶ÔSAML»òIdPÅäÖýøÐÐÈκθü¸Ä¡£¡£¡£¡£¡£¡£¡£¡£
һʱ´ëÊ©£º
? ʹÓÃÆäËûÉí·ÝÑéÖ¤²½Öè²¢½ûÓÃSAMLÉí·ÝÑéÖ¤£»£»£»£»£»£»
? ÔÚÖ´ÐÐÉý¼¶Ö®Ç°£¬£¬£¬£¬£¬£¬Í¬Ê±ÀûÓã¨a£©ºÍ£¨b£©Á½Ï½â´ëÊ©¡£¡£¡£¡£¡£¡£¡£¡£
£¨a£©È·±£ÒÑÅäÖá°Éí·ÝÌṩÉÌÖ¤Ê顱¡£¡£¡£¡£¡£¡£¡£¡£ÅäÖá°Éí·ÝÌṩÉÌÖ¤Ê顱Êǰ²È«SAMLÉí·ÝÑéÖ¤ÅäÖõijÁÒª×é³É²¿ÃÅ¡£¡£¡£¡£¡£¡£¡£¡£
£¨b£©ÈôÊÇÉí·ÝÌṩÉÌ£¨IDP£©Ö¤ÊéÊÇÖ¤ÊéÐû¸æ»ú¹¹£¨CA£©ÊðÃûµÄÖ¤Ê飬£¬£¬£¬£¬£¬ÔòÈ·±£ÔÚSAMLÉí·ÝÌṩÉÌ·þÎñÆ÷ÅäÖÃÎļþÖÐÆôÓÃÁË¡°Éí·ÝÌṩÉÌÖ¤Ê顱ѡÏî¡£¡£¡£¡£¡£¡£¡£¡£Ä¬ÈÏÇé¿öÏ£¬£¬£¬£¬£¬£¬ºÜ¶àÊ¢ÐеÄIDP³ÇÊÐÌìÉú×ÔÊðÃûIDPÖ¤Ê飬£¬£¬£¬£¬£¬²¢ÇÒÎÞ·¨ÆôÓá°ÑéÖ¤Éí·ÝÌṩÉÌÖ¤Ê顱ѡÏî¡£¡£¡£¡£¡£¡£¡£¡£ÒªÊ¹ÓÃÓÉCAÊðÃûµÄÖ¤Ê飬£¬£¬£¬£¬£¬¿ÉÄܱØÒªÖ´ÐÐÆäËû²½Öè¡£¡£¡£¡£¡£¡£¡£¡£¸ÃÖ¤ÊéÄܹ»ÓÉÄÚ²¿ÆóÒµCA£¬£¬£¬£¬£¬£¬PAN OSÉϵÄCA»ò¹«¹²CAÊðÃû¡£¡£¡£¡£¡£¡£¡£¡£¿£¿£¿£¿£¿£¿£¿ÉÔÚhttps://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000008UXPÉÏ»ñÈ¡ÓйØÔÚIDPÉÏÅäÖÃCAÐû¸æµÄÖ¤ÊéµÄ×¢Ã÷¡£¡£¡£¡£¡£¡£¡£¡£
0x03 ÓйØÐÂÎÅ
https://www.zdnet.com/article/us-cyber-command-says-foreign-hackers-will-most-likely-exploit-new-pan-os-security-bug/
0x04 ²Î¿¼Á´½Ó
https://security.paloaltonetworks.com/CVE-2020-2021?from=timeline&isappinstalled=0
0x05 ¹¦·òÏß
2020-06-29 Palo Alto Networks°ä²¼°²È«²¼¸æ
2020-06-30 VSRC°ä²¼·ì϶¹«¸æ


¾©¹«Íø°²±¸11010802024551ºÅ