ÆóÒµVPN cookie²»°²È«´æ´¢·½Ê½·ì϶°²È«¹«¸æ
°ä²¼¹¦·ò 2019-04-15·ì϶±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-1573£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
Palo Alto Networks GlobalProtect Agent 4.1.0µÄWindows °æ±¾ºÍ GlobalProtect Agent 4.1.10֮ǰµÄ macOS°æ±¾ (CVE-2019-1573)
Pulse Secure Connect Secure ÔçÓÚ8.1R14¡¢8.2¡¢8.3R6 ºÍ9.0R2 µÄ°æ±¾
Palo Alto Networks GlobalProtect Agent 4.1.0µÄWindows °æ±¾ºÍ GlobalProtect Agent 4.1.10֮ǰµÄ macOS °æ±¾ (CVE-2019-1573)
Pulse Secure Connect Secure ÔçÓÚ8.1R14¡¢8.2¡¢8.3R6 ºÍ9.0R2 µÄ°æ±¾
˼¿Æ AnyConnect 4.7.x ºÍ֮ǰ°æ±¾
·ì϶¸ÅÊö
¿¨ÄÚ»ù÷¡´óѧCERT/CCÖ¸³ö£¬ÖÁÉÙËÄ¿îÆóÒµVPN ÀûÓÃÖдæÔÚ°²È«È±µã£¬Ô̺¬Ë¼¿Æ¡¢F5 Networks¡¢Palo Alto Networks ºÍ Pulse Secure µÄ VPN ÀûÓá£
ÕâËÄ¿îÀûÓÃÒѱ»Ö¤ÊµÒԷǼÓÃÜ´ó¾Ö½«ÈÏÖ¤ºÍ»á»°cookie´æ´¢ÔÚÍÆËã»úÄÚ´æ»òÈÕÖ¾ÎļþÖС£ÓµÓÐÍÆËã»ú½Ó¼ûȨÏ޵Ĺ¥»÷Õß»òÔÚÍÆËã»úÉÏÔËÐеĶñÒâÈí¼þ¿ÉÄܼìË÷¸ÃÐÅÏ¢²¢ÓÃÓÚÁí±íϵͳÖÐÒÔ¸´ÔÊܺ¦ÕßµÄ VPN »á»°¶øÎÞÐèÈÏÖ¤¡£Õâ¾Íµ¼Ö¹¥»÷ÕßÖ±½ÓÇÒ²»ÊܹÊÕϵĽӼû¹«Ë¾µÄÄÚ²¿ÍøÂç¡¢ÄÚ²¿ÍøÃÅ»§»òÆäËüÃô¸ÐµÄÀûÓ÷¨Ê½¡£
·ì϶ÑéÖ¤
ÔÝÎÞPOC/EXP¡£
½¨¸´½¨Òé
Palo AltoNetworks ÒѰ䲼¸üнâ¾öÕâÁ½¸öÎÊÌ⣺
Palo Alto Networks GlobalProtect Agent 4.1.1µÄWindows °æ±¾ºÍ GlobalProtect Agent 4.1.11µÄ macOS0°æ±¾£ºhttps://securityadvisories.paloaltonetworks.com/Home/Detail/146?AspxAutoDetectCookieSupport=1¡£
F5 Networks °µÊ¾ÒÑÔÚ2013Äê°ÑÎȵ½½«ÈÏÖ¤/»á»° cookie ÒÔ²»°²È«µÄ·½Ê½´æ´¢ÔÚ OSÄÚ´æÖеÄÇé¿ö£¬²»Íâ¾ö¶¨²»°ä²¼²¹¶¡£¬¶øÊǽ¨ÒéÏû·ÑÕßΪVPN ¿Í»§¶ËÆôÓÃÒ»´ÎÐÔÃÜÂë»òË«³É·ÖÈÏÖ¤»úÔ죻¶ø´æ´¢ÔÚ±¾µØÈÕÖ¾ÎļþÖеÄÎÊÌâÒÑÓÚ2017ÄêÔÚ F5 Networks BIG-IP app Öнâ¾ö¡£
˼¿ÆºÍ Pulse Secure ÉÐδ¹«¿ªÈϿɸÃÕâЩÎÊÌâµÄ´æÔÚ¡£
²Î¿¼Á´½Ó


¾©¹«Íø°²±¸11010802024551ºÅ