Òø·å & ˼¿Æ & Citrix & VMware | SD-WANÇå¾²Îó²îͨ¸æ

Ðû²¼Ê±¼ä 2020-12-02

0x00 Îó²î¸ÅÊö

¿ËÈÕ£¬£¬£¬Realmode LabsµÄÑо¿Ö°Ô±·¢Ã÷ÁËÊг¡ÉÏÅÅÃûǰËĵÄSD-WANµÄ²úÆ·Öб£´æ¶à¸öÇå¾²Îó²î£¬£¬£¬Æä³§ÉÌ»®·ÖÎªÒø·å¡¢Ë¼¿Æ¡¢CitrixºÍVMware¡£¡£¡£Ôڴ˴η¢Ã÷µÄÎó²îÖУ¬£¬£¬Óжà¸ö¿ÉÔì³ÉÔ¶³Ì´úÂëÖ´ÐУ¬£¬£¬ÇÒÎÞÐèÈκÎÉí·ÝÑéÖ¤¼´¿ÉʹÓᣡ£¡£¹¥»÷Õß¿ÉÒÔʹÓÃÕâЩÎó²îÀ´×èµ²»ò¶ñÒâÖ¸µ¼Á÷Á¿£¬£¬£¬ÉõÖÁ¿Éµ¼ÖÂÍøÂçÖÐÖ¹¡£¡£¡£

 

0x01 Îó²îÏêÇé

image.png

                                                        

²úÆ·Ãû³Æ

CVE   ID

Àà   ÐÍ

Îó²îÆ·¼¶

Ô¶³ÌʹÓÃ

Òø·åSD-WAN

CVE-2020-12145

Éí·ÝÑéÖ¤ÈÆ¹ý

ÑÏÖØ

ÊÇ

CVE-2020-12146

·¾¶±éÀú

¸ßΣ

ÊÇ

CVE-2020-12147

í§ÒâSQLÅÌÎÊ

¸ßΣ

ÊÇ

Citrix SD-WAN

CVE-2020-8271

·¾¶±éÀú¡¢Shell×¢Èë

ÑÏÖØ

ÊÇ

CVE-2020-8272

Éí·ÝÑéÖ¤ÈÆ¹ý

¸ßΣ

ÊÇ

CVE-2020-8273

Shell×¢Èë

¸ßΣ

ÊÇ

˼¿ÆViptela vManage

 

 

CVE-2020-27128

SSRF¡¢í§ÒâÎļþдÈë

ÖÐΣ

ÊÇ

CVE-2020-27129

ÏÂÁî×¢Èë

ÖÐΣ

ÊÇ

CVE-2020-26073

Îļþ¶ÁÈ¡¡¢Ä¿Â¼±éÀú

¸ßΣ

ÊÇ

CVE-2020-26074

ȨÏÞÌáÉý

¸ßΣ

·ñ

VMware VeloCloud Orchestrator

CVE-2020-4001

Éí·ÝÑéÖ¤ÈÆ¹ý

ÖÐΣ

ÊÇ

CVE-2020-3984

SQL×¢Èë

¸ßΣ

ÊÇ

CVE-2020-4000

Ŀ¼±éÀú¡¢´úÂëÖ´ÐÐ

ÖÐΣ

ÊÇ

 

Òø·åµÄSD-WANÖб£´æÈý¸öÇå¾²Îó²î£¬£¬£¬»®·ÖΪCVE-2020-12145¡¢CVE-2020-12146ºÍCVE-2020-12147£¬£¬£¬ÕâЩÎó²îλÓÚOrchestratorÖ÷ÖÎÀí½çÃæ£¬£¬£¬¿É¼¯ÖпØÖƹ«Ë¾µÄSD-WANÍØÆË¡£¡£¡£¹¥»÷Õß¿ÉÅäºÏʹÓÃÕâÈý¸öÎó²îÀ´¶ÔSD-PWNÍøÂç¾ÙÐй¥»÷¡£¡£¡£

Citrix SD-WANÒÔCakePHP2Ϊ¿ò¼ÜÔÚApacheÉÏÔËÐС£¡£¡£ÓÉÓÚCakePHP2¿ò¼ÜÔÚ´¦Öóͷ£URLʱ±£´æÎÊÌ⣬£¬£¬Citrix SD-WANÖÐÐı£´æÈý¸öÇå¾²Îó²î£¬£¬£¬»®·ÖΪCVE-2020-8271¡¢CVE-2020-8272ºÍCVE-2020-8273£¬£¬£¬ÀÖ³ÉʹÓÃÎó²îµÄ¹¥»÷Õß¿É×¢ÈëshellÏÂÁ£¬£¬×îÖÕ¿ØÖÆÕû¸öÍøÂç¡£¡£¡£

˼¿ÆViptela vManageÊÇ˼¿ÆSD-WAN»ù´¡¼Ü¹¹µÄÖÐÐÄ£¬£¬£¬¿ÉÖÎÀíÍøÂçÖÐËùÓÐÖÕ¶Ë¡£¡£¡£ÓÉÓÚSD-WANÉè¼ÆµÄ¼¯ÖÐÐÔ£¬£¬£¬´ÓÇå¾²½Ç¶ÈÀ´¿´£¬£¬£¬vManageÉϵĶà¸öÎó²îÊôÓÚµ¥µã¹ÊÕÏ¡£¡£¡£

ͨ¹ýʹÓÃCVE-2020-27128¡¢CVE-2020-27129¡¢CVE-2020-26073ºÍCVE-2020-26074£¬£¬£¬¹¥»÷ÕßÄܹ»Ô¶³ÌÖ´ÐдúÂëÀ´»ñµÃvManageµÄ¿ØÖÆÈ¨£¬£¬£¬¶ø¸ÃÖÕ¶Ëͨ³£ÍйÜÔÚÔÆÇéÐÎÖС£¡£¡£¹¥»÷Õß²»ÐèÒªÈκÎÉèÖü´¿ÉʹÓÃÕâЩÎó²î¡£¡£¡£

VMware VeloCloud OrchestratorÊÇÅþÁ¬µ½±ßÑØÂ·ÓÉÆ÷²¢¼¯ÖпØÖƵÄÍøÂçÍØÆË¡£¡£¡£VMware VeloCloud»ù´¡¼Ü¹¹ÓÉnginx×é³É£¬£¬£¬ÆäÖ÷ÒªÓÃ×÷node.jsЧÀÍÆ÷µÄ·´ÏòÊðÀí£¬£¬£¬ÓÉÓÚÆä½Ó¿Ú±£´æÇå¾²Îó²î£¬£¬£¬»®·ÖΪCVE-2020-4001¡¢CVE-2020-3984ºÍCVE-2020-4000¡£¡£¡£¹¥»÷Õß¿ÉÒÔʹÓÃÕâЩÎó²îÐÞ¸ÄVelocloudµÇ¼Ãû»òÖØÖÃÃÜÂë¡£¡£¡£

 

²¿·ÖÎó²îÏêÇéÈçÏ£º

Òø·åSD-WANÉí·ÝÑéÖ¤ÈÆ¹ýÎó²î£¨CVE-2020-12145£©

ÓÉÓÚ¶ÔδִÐÐÉí·ÝÑé֤ȷµ±ÌïÖ÷»úµÄAPIŲÓõÄÌØÊâ´¦Öóͷ£±£´æÇå¾²ÎÊÌ⣬£¬£¬ÈκÎÒÔ¡°localhost¡±×÷ΪÆäHTTP Host±êÍ·µÄÇëÇó¶¼Öª×ã¼ì²éÒªÇ󣬣¬£¬ÕâÈÝÒ×µ¼ÖÂÉí·ÝÑéÖ¤ÈÆ¹ý¡£¡£¡£¿£¿£¿£¿£¿£¿ÉʹÓÃrequest.getBaseUri().getHost().equals(¡°localhost¡±)ÏÂÁî¾ÙÐÐlocalhost¼ì²é¡£¡£¡£


Citrix SD-WAN·¾¶±éÀúºÍshell×¢ÈëÎó²î£¨CVE-2020-8271£©

ÓÉÓÚ/collector/diagnostics/stop_ping¶Ëµã¶ÁÈ¡"/tmp/pid_" . $req_idÎļþ£¬£¬£¬²¢ÔÚshell_execŲÓÃÖÐʹÓÃÆäÄÚÈÝ£¬£¬£¬¶øÃ»ÓжÔÔÊÐí·¾¶±éÀúµÄ$req_id¾ÙÐÐÕûÀí¡£¡£¡£¹¥»÷Õß¿ÉÒÔ½«¶ñÒâÎļþÉÏ´«µ½Èκεط½²¢Ö´ÐÐí§ÒâshellÏÂÁî¡£¡£¡£

 

0x02 ´¦Öóͷ£½¨Òé

ÏÖÔÚÏà¹Ø³§ÉÌÒѾ­Ðû²¼¸üУ¬£¬£¬½¨Òé²Î¿¼¹Ù·½µÄ½¨Òéʵʱ¸üС£¡£¡£

 

0x03 ²Î¿¼Á´½Ó

https://www.securityweek.com/sd-wan-product-vulnerabilities-allow-hackers-steer-traffic-shut-down-networks

https://medium.com/realmodelabs/sd-pwn-part-4-vmware-velocloud-the-last-takeover-a7016f9a9175

https://tools.cisco.com/security/center/publicationListing.x?product=Cisco&sort=-day_sir&offset=20#~Vulnerabilities

https://www.vmware.com/security/advisories/VMSA-2020-0025.html

 

0x04 ʱ¼äÏß

2020-12-01  VSRCÐû²¼Ç徲ͨ¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/



image.png