CVE-2020-2021 | PAN-OS SAMLÉí·ÝÑéÖ¤ÈÆ¹ýÎó²îͨ¸æ
Ðû²¼Ê±¼ä 2020-06-300x00 Îó²î¸ÅÊö
|
CVE ID |
CVE-2020-2021 |
ʱ ¼ä |
2020-06-30 |
| Àà ÐÍ |
AB |
µÈ ¼¶ |
ÑÏÖØ |
|
Ô¶³ÌʹÓà |
ÊÇ |
Ó°Ïì¹æÄ£ |
|
0x01 Îó²îÏêÇé
2020Äê6ÔÂ29ÈÕ£¬£¬£¬£¬Palo Alto Networks¹Ù·½Ðû²¼Ç徲ͨ¸æ£¬£¬£¬£¬ÐÞ¸´ÁËÒ»¸öPAN-OS SAMLÉí·ÝÑéÖ¤ÈÆ¹ýÎó²î£¨CVE-2020-2021£©¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÎÞÐè¾ÓÉÉí·ÝÑéÖ¤¼´¿ÉʹÓøÃÎó²î»á¼û×°±¸¡£¡£¡£¡£¡£¡£¡£
ÔÚÆôÓÃÇå¾²ÐÔ¶ÏÑÔ±ê¼ÇÓïÑÔ£¨SAML£©Éí·ÝÑéÖ¤²¢½ûÓá°ÑéÖ¤Éí·ÝÌṩÉÌÖ¤Ê顱ѡÏîʱ£¬£¬£¬£¬ÓÉÓÚPAN-OS SAMLÉí·ÝÑéÖ¤Àú³ÌÖÐûÓÐ׼ȷµØÑéÖ¤ÊðÃû£¬£¬£¬£¬µ¼ÖÂδ¾Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔ¸ü¸ÄPAN OSµÄÉèÖú͹¦Ð§¡£¡£¡£¡£¡£¡£¡£Ìõ¼þÌõ¼þÊǹ¥»÷Õß±ØÐè¿ÉÒÔ»á¼ûÒ×Êܹ¥»÷µÄЧÀÍÆ÷£¬£¬£¬£¬²Å»ªÊ¹ÓôËÎó²î¡£¡£¡£¡£¡£¡£¡£
¸ÃÎó²îÊÇÔÚCVSSv3ÑÏÖØÆ·¼¶ÖлñµÃ10·ÖµÄÓÐÊýÎó²îÖ®Ò»£¬£¬£¬£¬¼È²»ÐèÒª¸ß¼¶ÊÖÒÕÊÖÒÕ£¬£¬£¬£¬ÓÖ¿ÉÒÔͨ¹ýInternet¾ÙÐÐÔ¶³ÌʹÓᣡ£¡£¡£¡£¡£¡£ÃÀ¹úÍøÂç˾ÁҪÇóËùÓÐÊÜCVE-2020-2021Ó°ÏìµÄ×°±¸Á¬Ã¦ÐÞ¸´¸ÃÎó²î£¬£¬£¬£¬²¢ÌåÏÖÍâ¹úµÄAPT×éÖ¯¿ÉÄܺܿì¾Í»áʵÑéʹÓøÃÎó²îÌᳫ¹¥»÷¡£¡£¡£¡£¡£¡£¡£
¿ÉÒÔͨ¹ý»ùÓÚSAMLµÄµ¥µãµÇ¼£¨SSO£©Éí·ÝÑéÖ¤±£»£»£»£»£»£»£»¤µÄ×ÊÔ´ÓУº
GlobalProtect Gateway,
GlobalProtect Portal,
GlobalProtect Clientless VPN,
Authentication and Captive Portal,
PAN-OS next-generation firewalls (PA-Series, VM-Series) and Panorama web interfaces
Prisma Access
¹ØÓÚGlobalProtectÍø¹Ø¡¢GlobalProtectÃÅ»§¡¢ÎÞ¿Í»§¶ËVPN¡¢Captive PortalºÍPrisma Access£¬£¬£¬£¬Î´¾Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔͨ¹ýÍøÂç»á¼ûЧÀÍÆ÷ÉÏÊܱ£»£»£»£»£»£»£»¤µÄ×ÊÔ´£¬£¬£¬£¬²»»áÓ°ÏìÍø¹Ø£¬£¬£¬£¬ÃÅ»§»òVPNЧÀÍÆ÷µÄÍêÕûÐԺͿÉÓÃÐÔ£¬£¬£¬£¬µ«¹¥»÷ÕßÎÞ·¨¼ì²é»ò¸Ä¶¯Í¨Ë×Óû§µÄ»á»°¡£¡£¡£¡£¡£¡£¡£ÕâÊÇÒ»¸öÑÏÖØ¼¶±ðµÄÎó²î£¬£¬£¬£¬CVSSÆÀ·Ö10.0¡£¡£¡£¡£¡£¡£¡£
¹ØÓÚPAN-OSºÍPanorama Web½çÃæ£¬£¬£¬£¬ÈôÊÇδ¾Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¾ßÓжÔPAN-OS»òPanorama Web½çÃæµÄ»á¼ûȨ£¬£¬£¬£¬¼´¿ÉÒÔÖÎÀíÔ±Éí·ÝµÇ¼²¢Ö´ÐÐÖÎÀí²Ù×÷¡£¡£¡£¡£¡£¡£¡£ÕâÊÇÒ»¸öÑÏÖØ¼¶±ðµÄÎó²î£¬£¬£¬£¬CVSSÆÀ·Ö10.0£¬£¬£¬£¬ÈôÊǽö¿Éͨ¹ýÊÜÏÞÖÎÀíÍøÂç»á¼ûWeb½çÃæ£¬£¬£¬£¬ÔòCVSSÆÀ·Ö9.6¡£¡£¡£¡£¡£¡£¡£
ÒÔÏÂÊÇCVE-2020-2021Îó²îÓ°ÏìµÄPalo Alto Networks PAN-OS°æ±¾£º
ÇëÏà¹ØÓû§¾¡¿ìÉó²éÉèÖ㬣¬£¬£¬ÊµÊ±È·ÈÏÊÇ·ñÊܵ½¸ÃÎó²îÓ°Ï죬£¬£¬£¬ÏêϸҪÁìÈçÏ£º
? ½öµ±ÆôÓÃÁËSAMLÉí·ÝÑéÖ¤²¢ÇÒÔÚ¡°SAMLÉí·ÝÌṩÉÌЧÀÍÆ÷ÉèÖÃÎļþ¡±ÖнûÓá°Éí·ÝÌṩÉÌÖ¤Ê顱ѡÏîʱ£¬£¬£¬£¬²Å¿ÉÒÔʹÓøÃÎó²î¡£¡£¡£¡£¡£¡£¡£
? ÈôÊDz»Ê¹ÓÃSAML¾ÙÐÐÉí·ÝÑéÖ¤£¬£¬£¬£¬ÔòÎÞ·¨Ê¹ÓøÃÎó²î¡£¡£¡£¡£¡£¡£¡£
? ÈôÊÇÔÚSAMLÉí·ÝÌṩÉÌЧÀÍÆ÷ÉèÖÃÎļþÖÐÆôÓÃÁË¡°ÑéÖ¤Éí·ÝÌṩÉÌÖ¤Ê顱ѡÏ£¬£¬£¬ÔòÎÞ·¨Ê¹ÓøÃÎó²î¡£¡£¡£¡£¡£¡£¡£
¹ØÓÚÔõÑù¼ì²éЧÀÍÆ÷ÉèÖò¢ÊµÑ黺½â²½·¥µÄ˵Ã÷£¬£¬£¬£¬Çë²Î¿¼£ºhttps://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000008UXK
? Òª¼ì²éÊÇ·ñÔÚ·À»ðǽÉÏÆôÓÃÁËSAMLÉí·ÝÑéÖ¤£¬£¬£¬£¬Çë²Î¿¼Device > Server Profiles > SAML Identity Provider£»£»£»£»£»£»£»
? Òª¼ì²éÊÇ·ñΪPanoramaÖÎÀíÔ±Éí·ÝÑéÖ¤ÆôÓÃÁËSAMLÉí·ÝÑéÖ¤£¬£¬£¬£¬Çë²Î¿¼Panorama >Server Profiles > SAML Identity Provider£»£»£»£»£»£»£»
? Òª¼ì²éÊÇ·ñΪPanoramaÖÎÀíµÄ·À»ðǽÆôÓÃÁËSAMLÉí·ÝÑéÖ¤£¬£¬£¬£¬Çë²Î¿¼Device > [template]> Server Profiles > SAML Identity Provider¡£¡£¡£¡£¡£¡£¡£
ƾ֤ÉèÖ㬣¬£¬£¬ÈκÎδ¾ÊÚȨµÄ»á¼û¶¼»á¼Í¼ÔÚϵͳÈÕÖ¾ÖУ¬£¬£¬£¬¿ÉÊǺÜÄÑÇø·ÖÓÐÓõǼÃûºÍ¶ñÒâµÇ¼Ãû¡£¡£¡£¡£¡£¡£¡£
0x02 ´¦Öóͷ£½¨Òé
¹Ù·½ÒÑÐû²¼PAN-OS 8.1.15¡¢PAN-OS 9.0.9¡¢PAN-OS 9.1.3ºÍ¸ü¸ß°æ±¾£¬£¬£¬£¬ÇëÏà¹ØÓû§ÊµÊ±Éý¼¶¡£¡£¡£¡£¡£¡£¡£
×¢ÖØ£ºÔÚÉý¼¶µ½Àο¿°æ±¾Ö®Ç°£¬£¬£¬£¬ÇëÈ·±£½«SAMLÉí·ÝÌṩÉ̵ÄÊðÃûÖ¤ÊéÉèÖÃΪ¡°Éí·ÝÌṩÉÌÖ¤Ê顱£¬£¬£¬£¬ÒÔÈ·±£Óû§¿ÉÒÔ¼ÌÐø¾ÙÐÐÉí·ÝÑéÖ¤¡£¡£¡£¡£¡£¡£¡£Çë²Î¿¼£ºhttps://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/authentication/configure-saml-authentication
? PAN-OSÉý¼¶Ö®Ç°ºÍÖ®ºóËùÐèµÄËùÓвÙ×÷µÄÏêϸÐÅÏ¢£¬£¬£¬£¬Çë²Î¿¼£ºhttps://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000008UXK
? ΪÁËɨ³ýGlobalProtectÃÅ»§ºÍÍø¹ØÉϵÄδÊÚȨ»á»°£¬£¬£¬£¬Prisma Accessͨ¹ýPanoramaÖÎÀí£¬£¬£¬£¬ÇëʹÓÃPanorama¸ü¸ÄAuthentication Override cookieµÄÉèÖᣡ£¡£¡£¡£¡£¡£Çë²Î¿¼£ºhttps://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000008UXy
ÖØÐÂÆô¶¯·À»ðǽºÍPanorama¿ÉÒÔɨ³ýWeb½çÃæÉϵÄÈκÎδ¾ÊÚȨµÄ»á»°¡£¡£¡£¡£¡£¡£¡£
? Ҫɨ³ýCaptive PortalÖеÄÈκÎδÊÚȨÓû§»á»°£¬£¬£¬£¬ÇëÖ´ÐÐÒÔϰ취£º
ÔËÐÐÒÔÏÂÏÂÁî
show user ip-user-mapping all type SSO
¹ØÓÚ·µ»ØµÄËùÓÐIP£¬£¬£¬£¬ÇëÔËÐÐÒÔÏÂÁ½¸öÏÂÁîÒÔɨ³ýÓû§£º
? PAN-OS 8.0ÒÑÖÕÖ¹Ö§³Ö£¨×èÖ¹2019Äê10ÔÂ31ÈÕ£©£¬£¬£¬£¬²»ÔÙά»¤¡£¡£¡£¡£¡£¡£¡£
ËùÓÐPrisma AccessЧÀ;ùÒÑÉý¼¶ÒÔ½â¾ö´ËÎÊÌ⣬£¬£¬£¬²¢ÇÒ²»ÔÙÒ×Êܹ¥»÷¡£¡£¡£¡£¡£¡£¡£Prisma Access¿Í»§²»ÐèÒª¶ÔSAML»òIdPÉèÖþÙÐÐÈκθü¸Ä¡£¡£¡£¡£¡£¡£¡£
ÔÝʱ²½·¥£º
? ʹÓÃÆäËûÉí·ÝÑéÖ¤ÒªÁì²¢½ûÓÃSAMLÉí·ÝÑéÖ¤£»£»£»£»£»£»£»
? ÔÚÖ´ÐÐÉý¼¶Ö®Ç°£¬£¬£¬£¬Í¬Ê±Ó¦Óã¨a£©ºÍ£¨b£©Á½Ï½â²½·¥¡£¡£¡£¡£¡£¡£¡£
£¨a£©È·±£ÒÑÉèÖá°Éí·ÝÌṩÉÌÖ¤Ê顱¡£¡£¡£¡£¡£¡£¡£ÉèÖá°Éí·ÝÌṩÉÌÖ¤Ê顱ÊÇÇå¾²SAMLÉí·ÝÑéÖ¤ÉèÖõÄÖ÷Òª×é³É²¿·Ö¡£¡£¡£¡£¡£¡£¡£
£¨b£©ÈôÊÇÉí·ÝÌṩÉÌ£¨IDP£©Ö¤ÊéÊÇÖ¤Êé½ÒÏþ»ú¹¹£¨CA£©ÊðÃûµÄÖ¤Ê飬£¬£¬£¬ÔòÈ·±£ÔÚSAMLÉí·ÝÌṩÉÌЧÀÍÆ÷ÉèÖÃÎļþÖÐÆôÓÃÁË¡°Éí·ÝÌṩÉÌÖ¤Ê顱ѡÏî¡£¡£¡£¡£¡£¡£¡£Ä¬ÈÏÇéÐÎÏ£¬£¬£¬£¬Ðí¶àÊ¢ÐеÄIDP¶¼»áÌìÉú×ÔÊðÃûIDPÖ¤Ê飬£¬£¬£¬²¢ÇÒÎÞ·¨ÆôÓá°ÑéÖ¤Éí·ÝÌṩÉÌÖ¤Ê顱ѡÏî¡£¡£¡£¡£¡£¡£¡£ÒªÊ¹ÓÃÓÉCAÊðÃûµÄÖ¤Ê飬£¬£¬£¬¿ÉÄÜÐèÒªÖ´ÐÐÆäËû°ì·¨¡£¡£¡£¡£¡£¡£¡£¸ÃÖ¤Êé¿ÉÒÔÓÉÄÚ²¿ÆóÒµCA£¬£¬£¬£¬PAN OSÉϵÄCA»ò¹«¹²CAÊðÃû¡£¡£¡£¡£¡£¡£¡£¿£¿£¿£¿£¿ÉÔÚhttps://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000008UXPÉÏ»ñÈ¡ÓйØÔÚIDPÉÏÉèÖÃCA½ÒÏþµÄÖ¤ÊéµÄ˵Ã÷¡£¡£¡£¡£¡£¡£¡£
0x03 Ïà¹ØÐÂÎÅ
https://www.zdnet.com/article/us-cyber-command-says-foreign-hackers-will-most-likely-exploit-new-pan-os-security-bug/
0x04 ²Î¿¼Á´½Ó
https://security.paloaltonetworks.com/CVE-2020-2021?from=timeline&isappinstalled=0
0x05 ʱ¼äÏß
2020-06-29 Palo Alto NetworksÐû²¼Ç徲ͨ¸æ
2020-06-30 VSRCÐû²¼Îó²îͨ¸æ


¾©¹«Íø°²±¸11010802024551ºÅ