Òø·å & ˼¿Æ & Citrix & VMware | SD-WAN°²È«·ì϶¹«¸æ
°ä²¼¹¦·ò 2020-12-020x00 ·ì϶¸ÅÊö
½üÈÕ£¬£¬£¬£¬£¬£¬£¬£¬Realmode LabsµÄ×êÑÐÈËÔ±·¢ÏÖÁËÊг¡ÉÏÅÅÃûǰËĵÄSD-WANµÄ²úÆ·ÖдæÔÚ¶à¸ö°²È«·ì϶£¬£¬£¬£¬£¬£¬£¬£¬Æä³§É̱ðÀëÎªÒø·å¡¢Ë¼¿Æ¡¢CitrixºÍVMware¡£¡£¡£¡£¡£ÔÚÕâ´Î·¢Ïֵķì϶ÖУ¬£¬£¬£¬£¬£¬£¬£¬Óжà¸ö¿ÉÔì³ÉÔ¶³Ì´úÂëÖ´ÐУ¬£¬£¬£¬£¬£¬£¬£¬ÇÒÎÞÐèÈκÎÉí·ÝÑéÖ¤¼´¿ÉÀûÓᣡ£¡£¡£¡£¹¥»÷ÕßÄܹ»ÀûÓÃÕâЩ·ì϶À´À¹½Ø»ò¶ñÒâÊèµ¼Á÷Á¿£¬£¬£¬£¬£¬£¬£¬£¬ÉõÖÁ¿Éµ¼ÖÂÍøÂçÖжϡ£¡£¡£¡£¡£
0x01 ·ì϶ÏêÇé

²úÆ·Ãû³Æ | CVE ID | Àà ÐÍ | ·ì϶µÈ¼¶ | Ô¶³ÌÀûÓà |
Òø·åSD-WAN | CVE-2020-12145 | Éí·ÝÑéÖ¤ÈÆ¹ý | ÑϳÁ | ÊÇ |
CVE-2020-12146 | õè¾¶±éÀú | ¸ßΣ | ÊÇ | |
CVE-2020-12147 | ËÁÒâSQL²éÎÊ | ¸ßΣ | ÊÇ | |
Citrix SD-WAN | CVE-2020-8271 | õè¾¶±éÀú¡¢Shell×¢Èë | ÑϳÁ | ÊÇ |
CVE-2020-8272 | Éí·ÝÑéÖ¤ÈÆ¹ý | ¸ßΣ | ÊÇ | |
CVE-2020-8273 | Shell×¢Èë | ¸ßΣ | ÊÇ | |
˼¿ÆViptela vManage
| CVE-2020-27128 | SSRF¡¢ËÁÒâÎļþдÈë | ÖÐΣ | ÊÇ |
CVE-2020-27129 | ºÅÁî×¢Èë | ÖÐΣ | ÊÇ | |
CVE-2020-26073 | Îļþ¶ÁÈ¡¡¢Ä¿Â¼±éÀú | ¸ßΣ | ÊÇ | |
CVE-2020-26074 | ȨÏÞÌáÉý | ¸ßΣ | ·ñ | |
VMware VeloCloud Orchestrator | CVE-2020-4001 | Éí·ÝÑéÖ¤ÈÆ¹ý | ÖÐΣ | ÊÇ |
CVE-2020-3984 | SQL×¢Èë | ¸ßΣ | ÊÇ | |
CVE-2020-4000 | Ŀ¼±éÀú¡¢´úÂëÖ´ÐÐ | ÖÐΣ | ÊÇ |
Òø·åµÄSD-WANÖдæÔÚÈý¸ö°²È«·ì϶£¬£¬£¬£¬£¬£¬£¬£¬±ðÀëΪCVE-2020-12145¡¢CVE-2020-12146ºÍCVE-2020-12147£¬£¬£¬£¬£¬£¬£¬£¬ÕâЩ·ì϶λÓÚOrchestratorÖ÷ÖÎÀí½çÃæ£¬£¬£¬£¬£¬£¬£¬£¬¿É¼¯ÖнÚÔ칫˾µÄSD-WANÍØÆË¡£¡£¡£¡£¡£¹¥»÷Õ߿ɹ²Í¬ÀûÓÃÕâÈý¸ö·ì϶À´¶ÔSD-PWNÍøÂç½øÐй¥»÷¡£¡£¡£¡£¡£
Citrix SD-WANÒÔCakePHP2Ϊ¿ò¼ÜÔÚApacheÉÏÔËÐС£¡£¡£¡£¡£ÓÉÓÚCakePHP2¿ò¼ÜÔÚ´¦ÖÃURLʱ´æÔÚÎÊÌ⣬£¬£¬£¬£¬£¬£¬£¬Citrix SD-WANÖÐÐÄ´æÔÚÈý¸ö°²È«·ì϶£¬£¬£¬£¬£¬£¬£¬£¬±ðÀëΪCVE-2020-8271¡¢CVE-2020-8272ºÍCVE-2020-8273£¬£¬£¬£¬£¬£¬£¬£¬³É¹¦ÀûÓ÷ì϶µÄ¹¥»÷Õß¿É×¢ÈëshellºÅÁ£¬£¬£¬£¬£¬£¬£¬×îÖÕ½ÚÔìÕû¸öÍøÂç¡£¡£¡£¡£¡£
˼¿ÆViptela vManageÊÇ˼¿ÆSD-WAN»ù´¡¼Ü¹¹µÄÖÐÐÄ£¬£¬£¬£¬£¬£¬£¬£¬¿ÉÖÎÀíÍøÂçÖÐËùÓÐÖÕ¶Ë¡£¡£¡£¡£¡£ÓÉÓÚSD-WANÉè¼ÆµÄ¼¯ÖÐÐÔ£¬£¬£¬£¬£¬£¬£¬£¬´Ó°²È«½Ç¶ÈÀ´¿´£¬£¬£¬£¬£¬£¬£¬£¬vManageÉϵĶà¸ö·ì϶ÊôÓÚµ¥µã¹ÊÕÏ¡£¡£¡£¡£¡£
ͨ¹ýÀûÓÃCVE-2020-27128¡¢CVE-2020-27129¡¢CVE-2020-26073ºÍCVE-2020-26074£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÄÜÔ¶³ÌÖ´ÐдúÂëÀ´»ñµÃvManageµÄ½ÚÔìȨ£¬£¬£¬£¬£¬£¬£¬£¬¶ø¸ÃÖÕ¶Ëͨ³£ÍйÜÔÚÔÆ»·¾³ÖС£¡£¡£¡£¡£¹¥»÷Õß²»±ØÒªÈκÎÅäÖü´¿ÉÀûÓÃÕâЩ·ì϶¡£¡£¡£¡£¡£
VMware VeloCloud OrchestratorÊÇÏνӵ½±ßԵ·ÓÉÆ÷²¢¼¯ÖнÚÔìµÄÍøÂçÍØÆË¡£¡£¡£¡£¡£VMware VeloCloud»ù´¡¼Ü¹¹ÓÉnginx×é³É£¬£¬£¬£¬£¬£¬£¬£¬ÆäÖØÒªÓÃ×÷node.js·þÎñÆ÷µÄ·´Ïò´úÀí£¬£¬£¬£¬£¬£¬£¬£¬ÓÉÓÚÆä½Ó¿Ú´æÔÚ°²È«·ì϶£¬£¬£¬£¬£¬£¬£¬£¬±ðÀëΪCVE-2020-4001¡¢CVE-2020-3984ºÍCVE-2020-4000¡£¡£¡£¡£¡£¹¥»÷ÕßÄܹ»ÀûÓÃÕâЩ·ì϶Åú¸ÄVelocloudµÇ¼Ãû»ò³ÁÖÃÃÜÂë¡£¡£¡£¡£¡£
²¿ÃÅ·ì϶ÏêÇéÈçÏ£º
Òø·åSD-WANÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶£¨CVE-2020-12145£©
ÓÉÓÚ¶ÔδִÐÐÉí·ÝÑéÖ¤µÄ±¾µØÖ÷»úµÄAPIŲÓõÄÌØÊâ´¦ÖôæÔÚ°²È«ÎÊÌ⣬£¬£¬£¬£¬£¬£¬£¬ÈκÎÒÔ¡°localhost¡±×÷ΪÆäHTTP Host±êÍ·µÄÒªÇó¶¼Âú×ã²é³ÒªÇ󣬣¬£¬£¬£¬£¬£¬£¬ÕâÈÝÒ×µ¼ÖÂÉí·ÝÑéÖ¤ÈÆ¹ý¡£¡£¡£¡£¡£¿£¿£¿£¿£¿£¿£¿ÉʹÓÃrequest.getBaseUri().getHost().equals(¡°localhost¡±)ºÅÁî½øÐÐlocalhost²é³¡£¡£¡£¡£¡£
Citrix SD-WANõè¾¶±éÀúºÍshell×¢Èë·ì϶£¨CVE-2020-8271£©
ÓÉÓÚ/collector/diagnostics/stop_ping¶Ëµã¶ÁÈ¡"/tmp/pid_" . $req_idÎļþ£¬£¬£¬£¬£¬£¬£¬£¬²¢ÔÚshell_execŲÓÃÖÐʹÓÃÆäÄÚÈÝ£¬£¬£¬£¬£¬£¬£¬£¬¶øÃ»ÓжÔÔÊÐíõè¾¶±éÀúµÄ$req_id½øÐÐËãÕÊ¡£¡£¡£¡£¡£¹¥»÷ÕßÄܹ»½«¶ñÒâÎļþÉÏ´«µ½Èκδ¦Ëù²¢Ö´ÐÐËÁÒâshellºÅÁî¡£¡£¡£¡£¡£
0x02 ´ëÖý¨Òé
ĿǰÓйس§ÉÌÒѾ°ä²¼¸üУ¬£¬£¬£¬£¬£¬£¬£¬½¨Òé²Î¿¼¹Ù·½µÄ½¨Òéʵʱ¸üС£¡£¡£¡£¡£
0x03 ²Î¿¼Á´½Ó
https://www.securityweek.com/sd-wan-product-vulnerabilities-allow-hackers-steer-traffic-shut-down-networks
https://medium.com/realmodelabs/sd-pwn-part-4-vmware-velocloud-the-last-takeover-a7016f9a9175
https://tools.cisco.com/security/center/publicationListing.x?product=Cisco&sort=-day_sir&offset=20#~Vulnerabilities
https://www.vmware.com/security/advisories/VMSA-2020-0025.html
0x04 ¹¦·òÏß
2020-12-01 VSRC°ä²¼°²È«¹«¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/



¾©¹«Íø°²±¸11010802024551ºÅ