CVE-2020-2050 | PAN-OSÉí·ÝÑéÖ¤ÈÆ¹ýÎó²îͨ¸æ
Ðû²¼Ê±¼ä 2020-11-120x00 Îó²î¸ÅÊö
CNVD ID | CVE-2020-2050 | ʱ ¼ä | 2020-11-12 |
Àà ÐÍ | Éí·ÝÑéÖ¤ÈÆ¹ý | µÈ ¼¶ | ¸ßΣ |
Ô¶³ÌʹÓà | ÊÇ | Ó°Ïì¹æÄ£ | <10.0.1 <9.1.5 <9.0.11 <8.1.17 |
0x01 Îó²îÏêÇé
2020Äê11ÔÂ11ÈÕ£¬Palo Alto NetworksÐû²¼Ç徲ͨ¸æ£¬PAN-OSµÄGlobalProtect SSL VPN×é¼þÖб£´æÒ»¸öÉí·ÝÑéÖ¤ÈÆ¹ýÎó²î£¨CVE-2020-2050£©£¬ÆäCVSSÆÀ·Ö8.2¡£
µ±Íø¹ØµÄÉí·ÝÑéÖ¤·½·¨ÉèÖÃΪÍêÈ«»ùÓÚÖ¤Êéʱ£¬¹¥»÷Õß¿ÉÒÔʹÓôËÎó²îÈÆ¹ýËùÓÐʹÓÃÎÞЧ֤ÊéµÄ¿Í»§¶ËÖ¤Êé¼ì²é£¬²¢Äܹ»ÒÔÈκÎÓû§µÄÉí·Ý¾ÙÐÐÉí·ÝÑéÖ¤£¬×îÖÕ»ñµÃ¶ÔVPNÍøÂç×ÊÔ´µÄ»á¼ûȨÏÞ¡£
½«SSL VPNÉèÖÃΪ¿Í»§¶ËÖ¤ÊéÑéÖ¤Ó°ÏìµÄ¹¦Ð§°üÀ¨£º
GlobalProtect Gateway
GlobalProtect Portal
GlobalProtect Clientless VPN
ÔÚ½«¿Í»§¶ËÖ¤ÊéÑéÖ¤ÓëÆäËüÉí·ÝÑéÖ¤ÒªÁìÍŽáʹÓõÄÇéÐÎÏ£¬´ËÎó²î½«Ê¹µÃÖ¤ÊéÌí¼ÓµÄ±£»¤±»ºöÂÔ¡£
´ËÎó²î»áÓ°ÏìʹÓÃGlobalProtect SSL VPN²¢½«Íø¹ØºÍÃÅ»§ÍøÕ¾ÉèÖÃΪÔÊÐíÓû§Ê¹Óÿͻ§¶ËÖ¤ÊéÉí·ÝÑéÖ¤µÄPAN OS×°±¸¡£±ðµÄ£¬ÈôÊÇʹÓÃÁ˿ͻ§¶ËÖ¤ÊéÈÏÖ¤£¬Ôò»ùÓÚIPSecµÄVPNÒ²½«Êܵ½Ó°Ïì¡£ÈôÊÇδʹÓÿͻ§¶ËÖ¤Êé¾ÙÐÐÉí·ÝÑéÖ¤£¬ÔòÎÞ·¨Ê¹ÓôËÎó²î¡£
0x02 ´¦Öóͷ£½¨Òé
ÏÖÔÚPalo Alto NetworksÒѾÐû²¼Á˸üа汾¡£½¨Òé²Î¿¼Ï±íʵʱÉý¼¶£º
°æ±¾ºÅ | ÊÜÓ°Ïì°æ±¾ | ¸üа汾 |
PAN OS 10.0 | <10.0.1 | > = 10.0.1 |
PAN OS 9.1 | <9.1.5 | > = 9.1.5 |
PAN OS 9.0 | <9.0.11 | > = 9.0.11 |
PAN OS 8.1 | <8.1.17 | > = 8.1.17 |
ÔÝʱ²½·¥£º
½«GlobalProtect SSL VPNÉèÖÃΪҪÇóÓû§Ê¹ÓÃÆäÆ¾Ö¤¾ÙÐÐÉí·ÝÑéÖ¤¡£
ÏÂÔØÁ´½Ó£º
https://www.paloaltonetworks.com/search
0x03 ²Î¿¼Á´½Ó
https://security.paloaltonetworks.com/CVE-2020-2050
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-2050
0x04 ʱ¼äÏß
2020-11-11 Palo Alto NetworksÐû²¼Ç徲ͨ¸æ
2020-11-12 VSRCÐû²¼Ç徲ͨ¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/


¾©¹«Íø°²±¸11010802024551ºÅ