Palo Alto Networks Cortex XSOARδÊÚȨ·ÃÎÊ©¶´£¨CVE-2021-3044£©

Ðû²¼Ê±¼ä 2021-06-23

0x00 ©¶´¸ÅÊö

CVE   ID

CVE-2021-3044

ʱ    ¼ä

2021-06-23

Àà    ÐÍ

δÊÚȨ·ÃÎÊ

µÈ    ¼¶

ÑÏÖØ

Ô¶³ÌÀûÓÃ

ÊÇ

Ó°Ï췶Χ


¹¥»÷ÅÓ´ó¶È

µÍ

¿ÉÓÃÐÔ

¸ß

Óû§½»»¥

ÎÞ

ËùÐèȨÏÞ

ÎÞ

PoC/EXP

δ¹ûÈ»

ÔÚÒ°ÀûÓÃ

·ñ

 

0x01 ©¶´ÏêÇé

image.png

Cortex? XSOARÊÇÈ«ÇòÍøÂçÄþ¾²Áìµ¼ÆóÒµPalo Alto NetworksÍÆ³öµÄÒ»¸öÈ«ÐÂÀ©Õ¹µÄÄþ¾²±àÅÅ¡¢×Ô¶¯»¯ÓëÏìӦƽ̨ £¬²¢¼¯³ÉÁËÍþвÇ鱨¹ÜÀí¹¦Ð§ £¬´Ó¶øÎªÆóÒµÄþ¾²Ìṩ¼´Ê±¡¢È«ÃæµÄÍþв·ÀÓù¡£

2021Äê06ÔÂ22ÈÕ £¬Palo Alto NetworksÐû²¼Äþ¾²Í¨¸æ £¬ÐÞ¸´ÁËCortex XSOARÖеÄÒ»¸öδÊÚȨ·ÃÎÊ©¶´£¨CVE-2021-3044£© £¬¸Ã©¶´µÄCVSSv3ÆÀ·ÖΪ9.8¡£Î´¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓôË©¶´Í¨¹ýREST APIÖ´ÐÐδ¾­ÊÚȨµÄ·ÃÎÊ¡£

¸Ã©¶´½ö´æÔÚÓÚÅäÖÃÁ˻µÄ¼¯³ÉAPI KeyµÄCortex XSOAR¡£¿ÉÒÔ´ÓCortex XSOAR Web ¿Í»§¶ËÑ¡Ôñ¡®Settings > Integration > API Keys¡¯ À´¼ì²ìÅäÖÃÊÇ·ñÊܵ½Ó°Ïì¡£


Ó°Ï췶Χ

Cortex XSOAR 6.1.0£ºbuilds >= 1016923 and < 1271064

Cortex XSOAR 6.2.0£ºbuilds < 1271065

 

0x02 ´¦Öý¨Òé

Ŀǰ´Ë©¶´ÒѾ­ÐÞ¸´ £¬½¨Òé²Î¿¼ÏÂ±í¼°Ê±Éý¼¶¸üС£´ËÍâ £¬ÓÉPalo Alto NetworksÍйܵÄËùÓÐCortex XSOARʵÀý¶¼ÒÑÉý¼¶ £¬²»ÐèÒªÔÙÖ´ÐÐÆäËü²Ù×÷¡£

°æ±¾

ÊÜÓ°Ïì°æ±¾

²»ÊÜÓ°Ïì°æ±¾

Cortex XSOAR 6.2.0

< 1271065

>= 1271065

Cortex XSOAR 6.1.0

>= 1016923 and < 1271064

< 1016923 £¬ >= 1271064

Cortex XSOAR 6.0.2

None

all

Cortex XSOAR 6.0.1

None

all

Cortex XSOAR 6.0.0

None

all

Cortex XSOAR 5.5.0

None

all

 

ÏÂÔØÁ´½Ó£º

https://support.paloaltonetworks.com/support

 

»º½â´ëÊ©

È¡ÏûËùÓлµÄ¼¯³É API Key £¬´ÓCortex XSOAR web ¿Í»§¶ËµÄSettings > Integration > API Keys £¬È»ºóÈ¡Ïûÿ¸öAPI Key¡£¿ÉÒÔ½«Cortex XSOARÉý¼¶µ½Àι̰汾ºó´´½¨ÐµÄAPI Key¡£

ÏÞÖÆ¶ÔCortex XSOAR·þÎñÆ÷µÄÍøÂç·ÃÎÊ £¬Ö»ÔÊÐíÊÜÐÅÈεÄÓû§·ÃÎÊ¡£

 

0x03 ²Î¿¼Á´½Ó

https://security.paloaltonetworks.com/CVE-2021-3044

https://security.paloaltonetworks.com/

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3044

 

0x04 ʱ¼äÏß

2021-06-22  Palo Alto NetworksÐû²¼Äþ¾²Í¨¸æ

2021-06-23  VSRCÐû²¼Äþ¾²Í¨¸æ

 

0x05 ¸½Â¼

CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/

image.png