Palo Alto Networks PAN-OSÔ¶³Ì´úÂëÖ´ÐÐÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-07-24

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-1579£¬£¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º8.1


Ó°Ïì°æ±¾


ÊÜÓ°ÏìµÄ°æ±¾


Palo Alto Networks PAN-OS 7.1.18¼°Ö®Ç°°æ±¾
Palo Alto Networks PAN-OS 8.0.11¼°Ö®Ç°°æ±¾
Palo Alto Networks PAN-OS 8.1.2¼°Ö®Ç°°æ±¾


²»ÊÜÓ°ÏìµÄ°æ±¾


Palo Alto Networks PAN-OS 9.0


Îó²î¸ÅÊö


Palo Alto Networks PAN-OSÊÇÃÀ¹úPalo Alto Networks¹«Ë¾µÄÒ»Ì×ΪÆä·À»ðǽװ±¸¿ª·¢µÄ²Ù×÷ϵͳ¡£¡£ ¡£¡£¡£


Palo Alto Networks PAN-OS±£´æÇå¾²Îó²î£¬£¬£¬£¬£¬£¬£¬£¬Ó°ÏìGlobalProtectÃÅ»§ÍøÕ¾ºÍGlobalProtect Gateway½Ó¿Ú²úÆ·£¬£¬£¬£¬£¬£¬£¬£¬GlobalProtect ²úÆ·ÔÊÐí×éÖ¯½¨ÉèÐéÄâרÓÃÍø£¨VPN£©»á¼û£¬£¬£¬£¬£¬£¬£¬£¬²¢ÊµÏÖÆäËûÇå¾²ºÍÖÎÀí¹¦Ð§¡£¡£ ¡£¡£¡£ÒòÍø¹ØÒÔδ¾­³éÑùºÍ¿ÉʹÓõķ½·¨½«Ìض¨²ÎÊýֵת´ï¸øsnprintf£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíºÚ¿ÍʹÓøÃÎó²îÏòÒ×Êܹ¥»÷µÄSSL VPNÄ¿µÄ·¢ËÍÌØÖÆÇëÇ󣬣¬£¬£¬£¬£¬£¬£¬Ô¶³ÌÖ´ÐÐϵͳÉϵĴúÂë¡£¡£ ¡£¡£¡£


Îó²îÑéÖ¤


POC£ºhttp://blog.orange.tw/2019/07/attacking-ssl-vpn-part-1-preauth-rce-on-palo-alto.html¡£¡£ ¡£¡£¡£


ÐÞ¸´½¨Òé


ÏÖÔÚ³§ÉÌÒÑÐû²¼Éý¼¶²¹¶¡ÒÔÐÞ¸´Îó²î£¬£¬£¬£¬£¬£¬£¬£¬²¹¶¡»ñÈ¡Á´½Ó£ºhttps://securityadvisories.paloaltonetworks.com/Home/Detail/158¡£¡£ ¡£¡£¡£


²Î¿¼Á´½Ó


https://securityadvisories.paloaltonetworks.com/Home/Detail/158