Pulse Connect SecureÔ¶³Ì´úÂëÖ´ÐЩ¶´£¨CVE-2021-22893£©
Ðû²¼Ê±¼ä 2021-04-210x00 ©¶´¸ÅÊö
CVE ID | CVE-2021-22893 | ʱ ¼ä | 2021-04-21 |
Àà ÐÍ | RCE | µÈ ¼¶ | ÑÏÖØ |
Ô¶³ÌÀûÓà | ÊÇ | Ó°Ï췶Χ | 9.0R3<= PCS <9.1R.11.4 |
PoC/EXP | ÔÚÒ°ÀûÓÃ | ÊÇ |
0x01 ©¶´ÏêÇé
2021Äê04ÔÂ20ÈÕ£¬PulseSecureÐû²¼Äþ¾²Í¨¸æ£¬¹ûÈ»ÁËPulse Connect Secure£¨PCS£©ÖеÄÒ»¸öÉí·ÝÑéÖ¤ÈÆ¹ý©¶´£¨CVE-2021-22893£©£¬¸Ã©¶´µÄCVSSv3»ù±¾µÃ·ÖΪ10.0·Ö¡£Ô¶³Ì¹¥»÷¿ÉÒÔͨ¹ýÀûÓôË©¶´ÔÚPulse Connect SecureÍø¹ØÉÏÖ´ÐÐÈÎÒâ´úÂ룬ÇҸé¶´ÎÞÐè¾¹ýÉí·ÝÑéÖ¤¼´¿ÉÀûÓá£
Ŀǰ¸Ã©¶´ÔÚÕë¶ÔÈ«Çò×éÖ¯µÄ¹¥»÷ÖÐÒѱ»»ý¼«ÀûÓ㬹¥»÷Õßͨ¹ý½«WebShell·ÅÖÃÔÚPulse Connect SecureÉ豸ÉÏ£¬ÒÔʵÏÖ½øÒ»²½µÄ·ÃÎʺͳ־ÃÐÔ¡£ÒÑÖªµÄWebshell¾ßÓаüÂÞÉí·ÝÑéÖ¤ÈÆ¹ý¡¢¶àÒòËØÉí·ÝÑéÖ¤ÈÆ¹ý¡¢ÃÜÂë¼Ç¼ºÍ³Ö¾ÃÐԵȶàÖÖ¹¦Ð§¡£
0x02 ´¦Öý¨Òé
ĿǰPulseSecureÔÚPCS 9.1R.11.4°æ±¾ÖÐÐÞ¸´ÁË´Ë©¶´£¬¸Ã©¶´µÄÄþ¾²¸üÐÂÔ¤¼Æ½«ÓÚ5Ô³õÐû²¼£¬½¨Ò鼰ʱÉý¼¶ÖÁ×îа汾¡£´ËÍ⣬Pulse Secure»¹Ðû²¼ÁËPulse ConnectÄþ¾²ÍêÕûÐÔ¹¤¾ß£¬ÒÔ×ÊÖú¿Í»§È·¶¨ÆäϵͳÊÇ·ñÊܵ½Ó°Ïì¡£
»º½â´ëÊ©
ͨ¹ýµ¼ÈëWorkaround-2104.xmlÎļþ¿ÉÒÔ»º½âCVE-2021-22893£¬µ«¸ÃÎļþ»á½ûÓÃWindows File Share BrowserºÍPulse Secure Collaboration¹¦Ð§¡£
ÏÂÔØÁ´½Ó£º
https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44784
0x03 ²Î¿¼Á´½Ó
https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44784
https://kb.pulsesecure.net/articles/Pulse_Secure_Article/KB44755
https://us-cert.cisa.gov/ncas/alerts/aa21-110a
https://www.bleepingcomputer.com/news/security/pulse-secure-vpn-zero-day-used-to-hack-defense-firms-govt-orgs/
0x04 ʱ¼äÏß
2021-04-20 PluseSecureÐû²¼Äþ¾²Í¨¸æ
2021-04-21 VSRCÐû²¼Äþ¾²Í¨¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/