SolarWinds NPMÔ¶³Ì´úÂëÖ´ÐЩ¶´£¨CVE-2021-31474£©
Ðû²¼Ê±¼ä 2021-05-260x00 ©¶´¸ÅÊö
CVE ID | CVE-2021-31474 | ʱ ¼ä | 2021-05-26 |
Àà ÐÍ | RCE | µÈ ¼¶ | ÑÏÖØ |
Ô¶³ÌÀûÓà | ÊÇ | Ó°Ï췶Χ | 2020.2.1 |
PoC/EXP | δ¹ûÈ» | ÔÚÒ°ÀûÓà | ·ñ |
0x01 ©¶´ÏêÇé
SolarWinds Network Performance Monitor£¨NPM£©ÊǼ¯ÍøÂç¼à²â¡¢É豸ÐÔÄÜά»¤¹ÜÀí¡¢¹ÊÕÏ¼à¿Ø¡¢ÍøÂçʵʱÁ÷Á¿¼à¿ØºÍÀúÊ·Êý¾Ýͳ¼Æ¡¢»ã×ܺÍÀúÊ·Êý¾Ý·ÖÎöµÈ¹¦Ð§ÓÚÒ»ÌåµÄÍøÂç¹ÜÀíϵͳ¡£
2021Äê05ÔÂ20ÈÕ£¬Zero Day Initiative¹ûÈ»Åû¶ÁËSolarWinds Network Performance MonitorÖеÄÒ»¸öÔ¶³Ì´úÂëÖ´ÐЩ¶´£¨CVE-2021-31474£©£¬ÆäCVSSÆÀ·ÖΪ9.8¡£
¸Ã©¶´´æÔÚÓÚSolarWinds.Serialization¿âÖУ¬ÓÉÓÚ¶ÔÓû§ÌṩµÄÊý¾Ýȱ·¦ÕýÈ·ÑéÖ¤£¬µ¼Ö²»ÐÅÈÎÊý¾ÝµÄ·´ÐòÁл¯¡£ÀÖ³ÉÀûÓôË©¶´µÄ¹¥»÷Õß¿ÉÒÔÔÚϵͳÉÏÏÂÎÄÖÐÖ´ÐÐÈÎÒâ´úÂ룬¶øÎÞÐè¾¹ýÉí·ÝÑéÖ¤¡£
Ó°Ï췶Χ
SolarWinds Network Performance Monitor 2020.2.1
0x02 ´¦Öý¨Òé
ĿǰSolarWindsÒѾÐÞ¸´Á˸é¶´£¬½¨Ò龡¿ì½øÐÐÉý¼¶¸üС£
ÏÂÔØÁ´½Ó£º
https://documentation.solarwinds.com/en/success_center/sam/content/release_notes/sam_2020-2-5_release_notes.htm
0x03 ²Î¿¼Á´½Ó
https://www.zerodayinitiative.com/advisories/ZDI-21-602/
https://nvd.nist.gov/vuln/detail/CVE-2021-31474
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-31474
0x04 ʱ¼äÏß
2021-05-20 ZDI¹ûÈ»Åû¶©¶´
2021-05-26 VSRCÐû²¼Äþ¾²Í¨¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/