Palo Alto Networks Cortex XSOARδÊÚȨ·ÃÎÊ©¶´£¨CVE-2021-3044£©
Ðû²¼Ê±¼ä 2021-06-230x00 ©¶´¸ÅÊö
CVE ID | CVE-2021-3044 | ʱ ¼ä | 2021-06-23 |
Àà ÐÍ | δÊÚȨ·ÃÎÊ | µÈ ¼¶ | ÑÏÖØ |
Ô¶³ÌÀûÓà | ÊÇ | Ó°Ï췶Χ | |
¹¥»÷ÅÓ´ó¶È | µÍ | ¿ÉÓÃÐÔ | ¸ß |
Óû§½»»¥ | ÎÞ | ËùÐèȨÏÞ | ÎÞ |
PoC/EXP | δ¹ûÈ» | ÔÚÒ°ÀûÓà | ·ñ |
0x01 ©¶´ÏêÇé
Cortex? XSOARÊÇÈ«ÇòÍøÂçÄþ¾²Áìµ¼ÆóÒµPalo Alto NetworksÍÆ³öµÄÒ»¸öÈ«ÐÂÀ©Õ¹µÄÄþ¾²±àÅÅ¡¢×Ô¶¯»¯ÓëÏìӦƽ̨£¬²¢¼¯³ÉÁËÍþвÇ鱨¹ÜÀí¹¦Ð§£¬´Ó¶øÎªÆóÒµÄþ¾²Ìṩ¼´Ê±¡¢È«ÃæµÄÍþв·ÀÓù¡£
2021Äê06ÔÂ22ÈÕ£¬Palo Alto NetworksÐû²¼Äþ¾²Í¨¸æ£¬ÐÞ¸´ÁËCortex XSOARÖеÄÒ»¸öδÊÚȨ·ÃÎÊ©¶´£¨CVE-2021-3044£©£¬¸Ã©¶´µÄCVSSv3ÆÀ·ÖΪ9.8¡£Î´¾Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓôË©¶´Í¨¹ýREST APIÖ´ÐÐδ¾ÊÚȨµÄ·ÃÎÊ¡£
¸Ã©¶´½ö´æÔÚÓÚÅäÖÃÁ˻µÄ¼¯³ÉAPI KeyµÄCortex XSOAR¡£¿ÉÒÔ´ÓCortex XSOAR Web ¿Í»§¶ËÑ¡Ôñ¡®Settings > Integration > API Keys¡¯ À´¼ì²ìÅäÖÃÊÇ·ñÊܵ½Ó°Ïì¡£
Ó°Ï췶Χ
Cortex XSOAR 6.1.0£ºbuilds >= 1016923 and < 1271064
Cortex XSOAR 6.2.0£ºbuilds < 1271065
0x02 ´¦Öý¨Òé
Ŀǰ´Ë©¶´ÒѾÐÞ¸´£¬½¨Òé²Î¿¼ÏÂ±í¼°Ê±Éý¼¶¸üС£´ËÍ⣬ÓÉPalo Alto NetworksÍйܵÄËùÓÐCortex XSOARʵÀý¶¼ÒÑÉý¼¶£¬²»ÐèÒªÔÙÖ´ÐÐÆäËü²Ù×÷¡£
°æ±¾ | ÊÜÓ°Ïì°æ±¾ | ²»ÊÜÓ°Ïì°æ±¾ |
Cortex XSOAR 6.2.0 | < 1271065 | >= 1271065 |
Cortex XSOAR 6.1.0 | >= 1016923 and < 1271064 | < 1016923£¬ >= 1271064 |
Cortex XSOAR 6.0.2 | None | all |
Cortex XSOAR 6.0.1 | None | all |
Cortex XSOAR 6.0.0 | None | all |
Cortex XSOAR 5.5.0 | None | all |
ÏÂÔØÁ´½Ó£º
https://support.paloaltonetworks.com/support
»º½â´ëÊ©
È¡ÏûËùÓлµÄ¼¯³É API Key£¬´ÓCortex XSOAR web ¿Í»§¶ËµÄSettings > Integration > API Keys£¬È»ºóÈ¡Ïûÿ¸öAPI Key¡£¿ÉÒÔ½«Cortex XSOARÉý¼¶µ½Àι̰汾ºó´´½¨ÐµÄAPI Key¡£
ÏÞÖÆ¶ÔCortex XSOAR·þÎñÆ÷µÄÍøÂç·ÃÎÊ£¬Ö»ÔÊÐíÊÜÐÅÈεÄÓû§·ÃÎÊ¡£
0x03 ²Î¿¼Á´½Ó
https://security.paloaltonetworks.com/CVE-2021-3044
https://security.paloaltonetworks.com/
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3044
0x04 ʱ¼äÏß
2021-06-22 Palo Alto NetworksÐû²¼Äþ¾²Í¨¸æ
2021-06-23 VSRCÐû²¼Äþ¾²Í¨¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/