CVE-2020-2040 | PAN-OS»º³åÇøÒç¶Âí½Å¹«¸æ

°ä²¼¹¦·ò 2020-09-11


0x00 ·ì϶¸ÅÊö


CVE   ID

CVE-2020-2040

ʱ    ¼ä

2020-09-11

Àà    ÐÍ

»º³åÇøÒç³ö

µÈ    ¼¶

¸ßΣ

Ô¶³ÌÀûÓÃ

ÊÇ

Ó°ÏìÁìÓò

 8.0ËùÓа汾£»£»£»£»£»£»£»£»

< 8.1.15 µÄ 8.1°æ±¾;

< 9.0.9µÄ9.0°æ±¾£»£»£»£»£»£»£»£»

<9.1.3µÄ9.1°æ±¾£»£»£»£»£»£»£»£»

10°æ±¾²»ÊÜÓ°Ïì¡£¡£ ¡£¡£¡£¡£¡£


2020Äê09ÔÂ09ÈÕ £¬£¬£¬£¬£¬£¬£¬£¬Palo Alto Networks£¨PAN£©°ä²¼ÁË9·Ý°²È«²¼¸æ £¬£¬£¬£¬£¬£¬£¬£¬ÆäÖÐÖ»ÓÐÒ»¸ö±»ÆÀΪÑϳÁ £¬£¬£¬£¬£¬£¬£¬£¬Æä·ì϶±àºÅΪCVE-2020-2040 £¬£¬£¬£¬£¬£¬£¬£¬CVSSÆÀ·ÖΪ9.8¡£¡£ ¡£¡£¡£¡£¡£¸Ã·ì϶ÊÇPAN-OSÉϵÄÒ»¸ö»º³åÇøÒç¶Âí½Å £¬£¬£¬£¬£¬£¬£¬£¬ÆäÀûÓÃÄÑ¶ÈµÍ £¬£¬£¬£¬£¬£¬£¬£¬ÎÞÐèÓû§½»»¥¡£¡£ ¡£¡£¡£¡£¡£PAN-OSÊÇÒ»¸öÔËÐÐÔÚPalo Alto Networks·À»ðǽºÍÆóÒµVPNÉ豸ÉϵIJÙ×÷ϵͳ¡£¡£ ¡£¡£¡£¡£¡£Palo Alto Networks°µÊ¾ £¬£¬£¬£¬£¬£¬£¬£¬½ØÖÁĿǰ»¹ÉÐδ·¢Ïָ÷ì϶ÔÚÒ°±í±»ÀûÓᣡ£ ¡£¡£¡£¡£¡£

¸Ã·ì϶µÄ»ã±¨×÷Õß˵£º¡°ÈôÊDz»¸üР£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÄܹ»ÀûÓÃÕâЩ·ì϶À´ÇÔÈ¡Ãô¸ÐÊý¾Ý £¬£¬£¬£¬£¬£¬£¬£¬»òÕßͨ¹ý¹¥»÷À´»ñÈ¡ÄÚ²¿ÍøÂçµÄ½Ó¼ûȨÏÞ¡£¡£ ¡£¡£¡£¡£¡£¡±

¡°¿ÉÀûÓÃÕâЩ·ì϶ÔÚ²Ù×÷ϵͳÖлñÈ¡rootÌØÈ¨ £¬£¬£¬£¬£¬£¬£¬£¬´Ó¶øÊ¹ºÚ¿Í¿ÉÄÜÔÚPalo AltoÀûÓ÷¨Ê½ÖÐʹÓÃÖÎÀíÔ±¼¶´ËÍâȨÏÞÖ´ÐÐÈκβÙ×÷¡£¡£ ¡£¡£¡£¡£¡£¡±

 

0x01 ·ì϶ÏêÇé


image.png


δ¾­Éí·ÝÑéÖ¤µÄ¹¥»÷Õßͨ¹ýÏòCaptive Portal»òMulti-Factor Authentication½Ó¿Ú·¢ËͶñÒâÒªÇóÀ´ÀûÓÃCVE-2020-2040¡£¡£ ¡£¡£¡£¡£¡£³É¹¦ÀûÓô˷ì϶¿ÉÄܵ¼ÖÂϵͳ¹ý³ÌÖÐ¶Ï £¬£¬£¬£¬£¬£¬£¬£¬²¢ÔÊÐíʹÓÃrootÌØÈ¨ÔÚPAN-OSÉ豸ÉÏÖ´ÐÐËÁÒâ´úÂë¡£¡£ ¡£¡£¡£¡£¡£¸Ã·ì϶½öµ±ÆôÓÃÁËÇ¿ÔìÃÅ»§ºÍ¶à³ÁÉí·ÝÑéÖ¤£¨MFA£©Ê±²Å´æÔÚ¡£¡£ ¡£¡£¡£¡£¡£

ͨ¹ýShodanµÄËÑË÷ÏÔʾ £¬£¬£¬£¬£¬£¬£¬£¬Ä¿Ç°Óг¬¹ý14000¸öPAN-OSÉ豸¿É¹«¿ª½Ó¼û¡£¡£ ¡£¡£¡£¡£¡£µ«ÊÇ £¬£¬£¬£¬£¬£¬£¬£¬Ä¿Ç°Éв»Ã÷ÏÔ14000¸öPAN-OSÉ豸ÖÐÓм¸¶à¸öÒ×Êܹ¥»÷¡£¡£ ¡£¡£¡£¡£¡£

image.png


³ýCVE-2020-2040±í £¬£¬£¬£¬£¬£¬£¬£¬PAN»¹°ä²¼ÁËÒÔÏÂ8ÏîÓйØPAN-OSÖзì϶µÄ°²È«²¼¸æ £¬£¬£¬£¬£¬£¬£¬£¬ÈçÏ£º

image.png

ÆäÖÐ £¬£¬£¬£¬£¬£¬£¬£¬CVE-2020-2041ÊÇÓÉÓÚPalo Alto Networks PAN-OS 8.1µÄappwebÊØ»¤·¨Ê½µÄ²»°²È«ÅäÖõ¼Öµķì϶ £¬£¬£¬£¬£¬£¬£¬£¬Ëü¿ÉÄÜÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄÔ¶³ÌÓû§½«´óÁ¿¶ñÒâÒªÇó·¢Ë͵½ÊÜÓ°ÏìµÄÉ豸µ¼ÖÂÆä·þÎñ±ÀÀ£¡£¡£ ¡£¡£¡£¡£¡£

 

0x02 ´ëÖý¨Òé

Ŀǰ £¬£¬£¬£¬£¬£¬£¬£¬Palo Alto NetworksÒѰ䲼ÊÜCVE-2020-2040·ì϶ӰÏìµÄ°æ±¾ºÍ´Ë·ì϶µÄ¸üа汾 £¬£¬£¬£¬£¬£¬£¬£¬ÈçÏ£º

image.png

ÓÉÓÚPAN-OS°æ±¾8.0µÄËùÓа汾¾ùÊܵ½Ó°Ïì £¬£¬£¬£¬£¬£¬£¬£¬Òò¶ø½â¾ö¸Ã·ì϶µÄΨһ½â¾ö¹æ»®ÊÇÉý¼¶µ½8.0Ö®±íµÄÁíÒ»¸ö°²È«°æ±¾°æ±¾8.1.15¼°Æä¸ü¸ß°æ±¾¡£¡£ ¡£¡£¡£¡£¡£´Ë±í £¬£¬£¬£¬£¬£¬£¬£¬PAN°µÊ¾GlobalProtect VPNºÍPAN-OSÖÎÀíWeb½çÃæ²»ÊÜCVE-2020-2040µÄÓ°Ïì¡£¡£ ¡£¡£¡£¡£¡£

PAN-OS 8.1.15¡¢PAN-OS 9.0.9¡¢PAN-OS 9.1.3¼°ÒÔÉϰ汾ÖÐÒѽ¨¸´´Ë·ì϶ £¬£¬£¬£¬£¬£¬£¬£¬½¨ÒéÓйØÓû§ÊµÊ±¸üе½°²È«°æ±¾¡£¡£ ¡£¡£¡£¡£¡£

°æ±¾Éý¼¶Óë¸ü¶à¾ßÌåÐÅÏ¢Çë²Î¿¼£º

https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-admin/software-and-content-updates/pan-os-software-updates.html

0x03 ÓйØÐÂÎÅ

https://www.bankinfosecurity.com/palo-alto-networks-patches-6-firewall-vulnerabilities-a-14977

https://zh-cn.tenable.com/blog/cve-2020-2040-critical-buffer-overflow-vulnerability-in-pan-os-devices-disclosed?tns_redirect=true

0x04 ²Î¿¼Á´½Ó

https://www.security-database.com/detail.php?alert=CVE-2020-2040

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-2040

0x05 ¹¦·òÏß

2020-09-11 VSRC°ä²¼·ì϶¹«¸æ


 

image.png