¡¾Â©¶´Í¨¸æ¡¿TLStorm 2.0£ºAruba & Avaya½»»»»úÔ¶³Ì´úÂëÖ´ÐЩ¶´

Ðû²¼Ê±¼ä 2022-05-05

0x00 ©¶´¸ÅÊö

2022Äê5ÔÂ3ÈÕ£¬ArmisµÄÑо¿ÈËÔ±Åû¶ÁËÔÚ Aruba ºÍ Avaya ¶àÖÖÐͺŵĽ»»»»úÖз¢ÏÖµÄ5¸ö©¶´£¬ÕâЩ©¶´Í³³ÆÎª¡°TLStorm 2.0¡±£¬¿ÉÄܵ¼ÖÂÔÚÊÜÓ°ÏìµÄÉ豸ÉÏÔ¶³ÌÖ´ÐдúÂë¡£

 

0x01 ©¶´ÏêÇé

TLStorm 2.0©¶´ÓëTLS ¿â NanoSSLÓйأ¨NanoSSL ÊÇDigiCert µÄ×Ó¹«Ë¾MocanaÌṩµÄ×ÛºÏÐÔ±ÕÔ´ SSL Ì×¼þ£©£¬²¢´æÔÚÓÚAruba ºÍ Avaya ¶àÖÖ½»»»»úÐͺŵÄTLS ͨÐÅʵʩÖС£

ÔÚArubaÉ豸ÉÏ£¬NanoSSL±»ÓÃÓÚRadiusÉí·ÝÑéÖ¤£¬Ò²±»ÓÃÓÚcaptive portalϵͳ£º

l  CVE-2022-23677£¨CVSS ÆÀ·Ö 9.0£©£ºNanoSSL ÔÚ¶à¸ö½Ó¿ÚÉϵÄÀÄÓà (RCE)£º¿ÉÄܵ¼ÖÂÔÚûÓÐÓû§½»»¥µÄÇé¿öÏÂͨ¹ý½»»»»úʵÏÖÔ¶³Ì´úÂëÖ´ÐС£

l  CVE-2022-23676£¨CVSS ÆÀ·Ö 9.1£©£ºRADIUS ¿Í»§¶ËÄÚ´æËð»µÂ©¶´£ºÄܹ»µ¼Ö¹¥»÷Õß¿ØÖƵÄÊý¾ÝµÄ¶ÑÒç³ö£¬Õâ¿ÉÄÜÔÊÐí¶ñÒâµÄRADIUS·þÎñÆ÷£¬»òÄܹ»·ÃÎÊRADIUS¹²ÏíÃØÃܵĹ¥»÷Õߣ¬ÔÚ½»»»»úÉÏÔ¶³ÌÖ´ÐдúÂë¡£

ÔÚAvayaÉ豸ÉÏ£¬¸Ã¿âµÄʵÏÖµ¼ÖÂÁË3¸öÄþ¾²Â©¶´£¬ÕâЩ©¶´ÎÞÐèÉí·ÝÑéÖ¤»òÓû§½»»¥¼´¿ÉÀûÓãº

l  CVE-2022-29860£¨CVSS ÆÀ·Ö 9.8£©£ºTLS ÖØ×é¶ÑÒç³ö©¶´£ºÔÚ Web ·þÎñÆ÷ÉÏ´¦Öà POST ÇëÇóµÄ½ø³ÌδÕýÈ·ÑéÖ¤ NanoSSL ·µ»ØÖµ£¬µ¼Ö¶ÑÒç³ö£¬´Ó¶øµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£

l  CVE-2022-29861£¨CVSS ÆÀ·Ö 9.8£©£ºHTTP Í·½âÎö¶ÑÕ»Òç³ö©¶´£ºÔÚ´¦ÖöಿÃÅ±íµ¥Êý¾Ýʱ£¬²»ÕýÈ·µÄ½çÏÞ¼ì²éÓë·Ç¿ÕÖÕÖ¹µÄ×Ö·û´®Ïà½áºÏ»áµ¼Ö¹¥»÷Õß¿ØÖƵĶÑÕ»Òç³ö£¬¿ÉÄܵ¼Ö RCE¡£

l  HTTP POSTÇëÇó´¦ÖöÑÒç³ö©¶´£ºÓÉÓÚȱÉÙ Mocana NanoSSL ¿âµÄ´íÎó¼ì²é£¬ÔÚ´¦ÖÃHTTP POSTÇëÇóʱ´æÔÚ©¶´£¬µ¼Ö¹¥»÷Õß¿ØÖƳ¤¶ÈµÄ¶ÑÒç³ö£¬¿ÉÄܵ¼ÖÂRCE¡£¸Ã©¶´ÔÝÎÞCVE ID¡£

 

Ó°Ï췶Χ

Avaya ERS3500

Avaya ERS3600

Avaya ERS4900

Avaya ERS5900

Aruba 5400R Series

Aruba 3810 Series

Aruba 2920 Series

Aruba 2930F Series

Aruba 2930M Series

Aruba 2530 Series

Aruba 2540 Series

 

 

0x02 ´¦Öý¨Òé

ĿǰAruba£¨HPÓµÓУ©ºÍ Avaya£¨ExtremeNetworks ÓµÓУ©ÒѾ­Ðû²¼ÁË´ó¶àÊý©¶´µÄ²¹¶¡£¬½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ì¸üС£

Aruba£º

https://asp.arubanetworks.com/

Avaya£º

https://extremeportal.force.com/ExtrSupportHome

 

0x03 ²Î¿¼Á´½Ó

https://www.armis.com/blog/tlstorm-2-nanossl-tls-library-misuse-leads-to-vulnerabilities-in-common-switches/

https://www.bleepingcomputer.com/news/security/aruba-and-avaya-network-switches-are-vulnerable-to-rce-attacks/

https://www.darkreading.com/vulnerabilities-threats/tls-flaws-leave-avaya-aruba-switches-open-to-complete-takeover

 

0x04 ¸üа汾

°æ±¾

ÈÕÆÚ

ÐÞ¸ÄÄÚÈÝ

V1.0

2022-05-05

Ê×´ÎÐû²¼

 

0x05 ¸½Â¼

¶¶È¦Îª¶Ä¶øÉú¼ò½é

¶¶È¦Îª¶Ä¶øÉú¹«Ë¾½¨Á¢ÓÚ1996Ä꣬²¢ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉî½»ËùÖÐС°åÕýʽ¹ÒÅÆÉÏÊУ¬ÊǹúÄÚ¼«¾ßʵÁ¦µÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÍøÂçÄþ¾²²úÎï¡¢¿ÉÐÅÄþ¾²¹ÜÀíÆ½Ì¨¡¢Äþ¾²·þÎñÓë½â¾ö·½°¸µÄ×ÛºÏÌṩÉÌ¡£

¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°£¬ÔÚÈ«¹ú¸÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÓзÖÖ§»ú¹¹£¬ÓµÓÐÁýÕÖÈ«¹úµÄÇþµÀÌåϵºÍ¼¼ÊõÖ§³ÖÖÐÐÄ£¬²¢ÔÚ±±¾©¡¢ÉϺ£¡¢³É¶¼¡¢¹ãÖÝ¡¢³¤É³¡¢º¼ÖÝµÈ¶àµØÉèÓÐÑз¢ÖÐÐÄ¡£

¶àÄêÀ´£¬¶¶È¦Îª¶Ä¶øÉúÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷´´ÐµÄÄþ¾²²úÎïºÍ×î¼Ñʵ¼ù·þÎñ£¬×ÊÖú¿Í»§È«ÃæÌáÉýÆäIT»ù´¡ÉèÊ©µÄÄþ¾²ÐÔºÍÉú²úЧÄÜ£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Äþ¾²¹¤ÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸Å¬Á¦¡£

 

¹ØÓÚ¶¶È¦Îª¶Ä¶øÉú

¶¶È¦Îª¶Ä¶øÉúÄþ¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÖ÷ÒªÕë¶ÔÖØÒªÄþ¾²Â©¶´µÄÔ¤¾¯¡¢¸ú×ٺͷÖÏíÈ«Çò×îеÄÍþвÇ鱨ºÍÄþ¾²³ÂËß¡£

¹Ø×¢ÒÔϹ«Öںţ¬»ñȡȫÇò×îÐÂÄþ¾²×ÊѶ£º

image.png