CVE-2020-2050 | PAN-OSÉí·ÝÑéÖ¤ÈÆ¹ýÎó²îͨ¸æ

Ðû²¼Ê±¼ä 2020-11-12

0x00 Îó²î¸ÅÊö

CNVD   ID

CVE-2020-2050

ʱ      ¼ä

2020-11-12

Àà    ÐÍ

Éí·ÝÑéÖ¤ÈÆ¹ý

µÈ      ¼¶

¸ßΣ

Ô¶³ÌʹÓÃ

ÊÇ

Ó°Ïì¹æÄ£

<10.0.1

<9.1.5

 <9.0.11

 <8.1.17

 

0x01 Îó²îÏêÇé

image.png 

2020Äê11ÔÂ11ÈÕ£¬£¬£¬£¬£¬£¬ £¬Palo Alto NetworksÐû²¼Ç徲ͨ¸æ£¬£¬£¬£¬£¬£¬ £¬PAN-OSµÄGlobalProtect SSL VPN×é¼þÖб£´æÒ»¸öÉí·ÝÑéÖ¤ÈÆ¹ýÎó²î£¨CVE-2020-2050£©£¬£¬£¬£¬£¬£¬ £¬ÆäCVSSÆÀ·Ö8.2¡£¡£¡£¡£¡£¡£¡£

µ±Íø¹ØµÄÉí·ÝÑéÖ¤·½·¨ÉèÖÃΪÍêÈ«»ùÓÚÖ¤Êéʱ£¬£¬£¬£¬£¬£¬ £¬¹¥»÷Õß¿ÉÒÔʹÓôËÎó²îÈÆ¹ýËùÓÐʹÓÃÎÞЧ֤ÊéµÄ¿Í»§¶ËÖ¤Êé¼ì²é£¬£¬£¬£¬£¬£¬ £¬²¢Äܹ»ÒÔÈκÎÓû§µÄÉí·Ý¾ÙÐÐÉí·ÝÑéÖ¤£¬£¬£¬£¬£¬£¬ £¬×îÖÕ»ñµÃ¶ÔVPNÍøÂç×ÊÔ´µÄ»á¼ûȨÏÞ¡£¡£¡£¡£¡£¡£¡£

½«SSL VPNÉèÖÃΪ¿Í»§¶ËÖ¤ÊéÑéÖ¤Ó°ÏìµÄ¹¦Ð§°üÀ¨£º

GlobalProtect Gateway

GlobalProtect Portal

GlobalProtect Clientless VPN

ÔÚ½«¿Í»§¶ËÖ¤ÊéÑéÖ¤ÓëÆäËüÉí·ÝÑéÖ¤ÒªÁìÁ¬ÏµÊ¹ÓõÄÇéÐÎÏ£¬£¬£¬£¬£¬£¬ £¬´ËÎó²î½«Ê¹µÃÖ¤ÊéÌí¼ÓµÄ±£»£»£»¤±»ºöÂÔ¡£¡£¡£¡£¡£¡£¡£

´ËÎó²î»áÓ°ÏìʹÓÃGlobalProtect SSL VPN²¢½«Íø¹ØºÍÃÅ»§ÍøÕ¾ÉèÖÃΪÔÊÐíÓû§Ê¹Óÿͻ§¶ËÖ¤ÊéÉí·ÝÑéÖ¤µÄPAN OS×°±¸¡£¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬ £¬ÈôÊÇʹÓÃÁ˿ͻ§¶ËÖ¤ÊéÈÏÖ¤£¬£¬£¬£¬£¬£¬ £¬Ôò»ùÓÚIPSecµÄVPNÒ²½«Êܵ½Ó°Ïì¡£¡£¡£¡£¡£¡£¡£ÈôÊÇδʹÓÿͻ§¶ËÖ¤Êé¾ÙÐÐÉí·ÝÑéÖ¤£¬£¬£¬£¬£¬£¬ £¬ÔòÎÞ·¨Ê¹ÓôËÎó²î¡£¡£¡£¡£¡£¡£¡£


0x02 ´¦Öóͷ£½¨Òé

ÏÖÔÚPalo Alto NetworksÒѾ­Ðû²¼Á˸üа汾¡£¡£¡£¡£¡£¡£¡£½¨Òé²Î¿¼Ï±íʵʱÉý¼¶£º

°æ±¾ºÅ

ÊÜÓ°Ïì°æ±¾

¸üа汾

PAN OS 10.0

<10.0.1

> = 10.0.1

PAN OS 9.1

<9.1.5

> = 9.1.5

PAN OS 9.0

<9.0.11

> = 9.0.11

PAN OS 8.1

<8.1.17

> = 8.1.17

 

ÔÝʱ²½·¥£º

½«GlobalProtect SSL VPNÉèÖÃΪҪÇóÓû§Ê¹ÓÃÆäÆ¾Ö¤¾ÙÐÐÉí·ÝÑéÖ¤¡£¡£¡£¡£¡£¡£¡£

ÏÂÔØÁ´½Ó£º

https://www.paloaltonetworks.com/search

0x03 ²Î¿¼Á´½Ó

https://security.paloaltonetworks.com/CVE-2020-2050

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-2050

0x04 ʱ¼äÏß

2020-11-11  Palo Alto NetworksÐû²¼Ç徲ͨ¸æ

2020-11-12  VSRCÐû²¼Ç徲ͨ¸æ

0x05 ¸½Â¼

 

CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/

 

image.png