¡¾Â©¶´Í¨¸æ¡¿Pulse Connect Secure 8Ô¶à¸öÄþ¾²Â©¶´
Ðû²¼Ê±¼ä 2021-08-090x00 ©¶´¸ÅÊö
2021Äê8ÔÂ2ÈÕ£¬Ivanti Ðû²¼ÁË Pulse Connect Secure ϵͳÈí¼þ°æ±¾ 9.1R12£¬ÐÞ¸´ÁËPulse Connect Secure VPNÉ豸ÖеĶà¸öÄþ¾²Â©¶´£¬ÀÖ³ÉÀûÓÃÕâЩ©¶´µÄ¹¥»÷Õß¿ÉÒÔʵÏÖRCE¡¢XSS¹¥»÷¡¢ÃüÁî×¢Èë»òÈÎÒâÎļþɾ³ý¡£Ä¿Ç°£¬ÕâЩ©¶´ÔÝδ·¢ÏÖÔÚÒ°ÀûÓá£
0x01 ©¶´ÏêÇé
±¾´Î¹ûÈ»µÄ£¶¸ö©¶´¶¼¿ÉÒÔ±»Ô¶³ÌÀûÓã¬ÆäÖУ¬CVE-2021-22937ºÍCVE-2021-22935×îΪÑÏÖØ¡£ÕâЩ©¶´µÄÏêÇéÈçÏ£º
Pulse Connect SecureÔ¶³Ì´úÂëÖ´ÐЩ¶´£¨CVE-2021-22937£©
¾¹ýÉí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔÀûÓôË©¶´ÔÚweb½çÃæÉÏ´«¶ñÒâÎļþÀ´ÊµÏÖÎļþдÈë»òÖ´ÐдúÂë¡£¸Ã©¶´µÄCVSSv3ÆÀ·ÖΪ9.1¡£
Pulse Connect SecureÈÎÒâÎļþɾ³ý©¶´£¨CVE-2021-22933£©
¾¹ýÉí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔͨ¹ý¶ñÒâÖÆ×÷µÄ Web ÇëÇóʵÏÖÈÎÒâÎļþɾ³ý¡£¸Ã©¶´µÄCVSSv3ÆÀ·ÖΪ7.6¡£
Pulse Connect Secure»º³åÇøÒç³ö©¶´£¨CVE-2021-22934£©
¾¹ýÉí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔͨ¹ý¶ñÒâÖÆ×÷µÄWebÇëÇóÔì³ÉPulse Connect Secure É豸»º³åÇøÒç³ö¡£¸Ã©¶´µÄCVSSv3ÆÀ·ÖΪ8.0¡£
Pulse Connect SecureÃüÁî×¢Èë©¶´£¨CVE-2021-22935£©
¾¹ýÉí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔͨ¹ýδ´¦ÖõÄweb²ÎÊýÖ´ÐÐÃüÁî×¢Èë¡£¸Ã©¶´µÄCVSSv3ÆÀ·ÖΪ9.1¡£
Pulse Connect Secure XSS©¶´£¨CVE-2021-22936£©
¹¥»÷Õß¿ÉÒÔͨ¹ýδ´¦ÖõÄweb²ÎÊý¶Ô¾¹ýÉí·ÝÑéÖ¤µÄ¹ÜÀíÔ±½øÐпçÕ¾½Å±¾¹¥»÷¡£¸Ã©¶´µÄCVSSv3ÆÀ·ÖΪ8.2¡£
Pulse Connect Secure ÃüÁî×¢Èë©¶´£¨CVE-2021-22938£©
¾¹ýÉí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔͨ¹ý¹ÜÀíÔ± Web ¿ØÖÆÌ¨ÖÐδ´¦ÖõÄWeb ²ÎÊýÖ´ÐÐÃüÁî×¢Èë¡£¸Ã©¶´µÄCVSSv3ÆÀ·ÖΪ7.9¡£
Ó°Ï췶Χ
Pulse Connect Secure < 9.1R12
0x02 ´¦Öý¨Òé
ĿǰÕâЩ©¶´ÒѾÐÞ¸´¡£½¨ÒéÊÜÓ°ÏìµÄ¿Í»§¼°Ê±Éý¼¶¸üÐÂÖÁPCS 9.1R12°æ±¾£¨ÒÑÓÚ2021 Äê 8 Ô 2 ÈÕÐû²¼£©¡£
ÏÂÔØÁ´½Ó£º
https://www.ivanti.com/products/connect-secure-vpn?psredirect
0x03 ²Î¿¼Á´½Ó
https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44858
https://us-cert.cisa.gov/ncas/current-activity/2021/08/06/ivanti-releases-security-update-pulse-connect-secure
https://securityaffairs.co/wordpress/120880/security/pulse-connect-secure-vpn-flaw-2.html?
0x04 ¸üа汾
°æ±¾ | ÈÕÆÚ | ÐÞ¸ÄÄÚÈÝ |
V1.0 | 2021-08-09 | Ê×´ÎÐû²¼ |
0x05 Îĵµ¸½Â¼
CNVD£ºwww.cnvd.org.cn
CNNVD£ºwww.cnnvd.org.cn
CVE£ºcve.mitre.org
NVD£ºnvd.nist.gov
CVSS£ºwww.first.org
0x06 ¹ØÓÚ¶¶È¦Îª¶Ä¶øÉú
¹Ø×¢ÒÔϹ«Öںţ¬»ñÈ¡¸ü¶à×ÊѶ£º