ÆóÒµVPN cookie²»°²È«´æ´¢·½Ê½·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2019-04-15

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-1573£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


ÈçϲúÆ·ºÍ°æ±¾ÒÔ²»°²È«µÄ·½Ê½½« VPN ÈÏÖ¤/»á»° cookie ´æ´¢ÔÚÈÕÖ¾ÎļþÖУº
Palo Alto Networks GlobalProtect Agent 4.1.0µÄWindows °æ±¾ºÍ GlobalProtect Agent 4.1.10֮ǰµÄ macOS°æ±¾ (CVE-2019-1573)

Pulse Secure Connect Secure ÔçÓÚ8.1R14¡¢8.2¡¢8.3R6 ºÍ9.0R2 µÄ°æ±¾


ÈçϲúÆ·½« VPN ÈÏÖ¤/»á»° cookieÒÔ²»°²È«µÄ·½Ê½´æ´¢ÔÚÄÚ´æÖУº
Palo Alto Networks GlobalProtect Agent 4.1.0µÄWindows °æ±¾ºÍ GlobalProtect Agent 4.1.10֮ǰµÄ macOS °æ±¾ (CVE-2019-1573)
Pulse Secure Connect Secure ÔçÓÚ8.1R14¡¢8.2¡¢8.3R6 ºÍ9.0R2 µÄ°æ±¾

˼¿Æ AnyConnect 4.7.x ºÍ֮ǰ°æ±¾


·ì϶¸ÅÊö


¿¨ÄÚ»ù÷¡´óѧCERT/CCÖ¸³ö£¬ÖÁÉÙËÄ¿îÆóÒµVPN ÀûÓÃÖдæÔÚ°²È«È±µã£¬Ô̺¬Ë¼¿Æ¡¢F5 Networks¡¢Palo Alto Networks ºÍ Pulse Secure µÄ VPN ÀûÓá£


ÕâËÄ¿îÀûÓÃÒѱ»Ö¤ÊµÒԷǼÓÃÜ´ó¾Ö½«ÈÏÖ¤ºÍ»á»°cookie´æ´¢ÔÚÍÆËã»úÄÚ´æ»òÈÕÖ¾ÎļþÖС£ÓµÓÐÍÆËã»ú½Ó¼ûȨÏ޵Ĺ¥»÷Õß»òÔÚÍÆËã»úÉÏÔËÐеĶñÒâÈí¼þ¿ÉÄܼìË÷¸ÃÐÅÏ¢²¢ÓÃÓÚÁí±íϵͳÖÐÒÔ¸´Ô­Êܺ¦ÕßµÄ VPN »á»°¶øÎÞÐèÈÏÖ¤¡£Õâ¾Íµ¼Ö¹¥»÷ÕßÖ±½ÓÇÒ²»ÊܹÊÕϵĽӼû¹«Ë¾µÄÄÚ²¿ÍøÂç¡¢ÄÚ²¿ÍøÃÅ»§»òÆäËüÃô¸ÐµÄÀûÓ÷¨Ê½¡£


·ì϶ÑéÖ¤


ÔÝÎÞPOC/EXP¡£


½¨¸´½¨Òé


Palo AltoNetworks ÒѰ䲼¸üнâ¾öÕâÁ½¸öÎÊÌ⣺

Palo Alto Networks GlobalProtect Agent 4.1.1µÄWindows °æ±¾ºÍ GlobalProtect Agent 4.1.11µÄ macOS0°æ±¾£ºhttps://securityadvisories.paloaltonetworks.com/Home/Detail/146?AspxAutoDetectCookieSupport=1¡£


F5 Networks °µÊ¾ÒÑÔÚ2013Äê°ÑÎȵ½½«ÈÏÖ¤/»á»° cookie ÒÔ²»°²È«µÄ·½Ê½´æ´¢ÔÚ OSÄÚ´æÖеÄÇé¿ö£¬²»Íâ¾ö¶¨²»°ä²¼²¹¶¡£¬¶øÊǽ¨ÒéÏû·ÑÕßΪVPN ¿Í»§¶ËÆôÓÃÒ»´ÎÐÔÃÜÂë»òË«³É·ÖÈÏÖ¤»úÔ죻¶ø´æ´¢ÔÚ±¾µØÈÕÖ¾ÎļþÖеÄÎÊÌâÒÑÓÚ2017ÄêÔÚ F5 Networks BIG-IP app Öнâ¾ö¡£


˼¿ÆºÍ Pulse Secure ÉÐδ¹«¿ªÈϿɸÃÕâЩÎÊÌâµÄ´æÔÚ¡£


²Î¿¼Á´½Ó


https://www.zdnet.com/article/some-enterprise-vpn-apps-store-authentication-session-cookies-insecurely/