CVE-2020-2021 | PAN-OS SAMLÉí·ÝÑéÖ¤ÈÆ¹ýÎó²îͨ¸æ

Ðû²¼Ê±¼ä 2020-06-30

0x00 Îó²î¸ÅÊö



CVE   ID

CVE-2020-2021

ʱ    ¼ä

2020-06-30

Àà  ÐÍ

AB

µÈ    ¼¶

ÑÏÖØ

Ô¶³ÌʹÓÃ

ÊÇ

Ó°Ïì¹æÄ£


0x01 Îó²îÏêÇé


ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾


2020Äê6ÔÂ29ÈÕ£¬ £¬£¬Palo Alto Networks¹Ù·½Ðû²¼Ç徲ͨ¸æ£¬ £¬£¬ÐÞ¸´ÁËÒ»¸öPAN-OS SAMLÉí·ÝÑéÖ¤ÈÆ¹ýÎó²î£¨CVE-2020-2021£©¡£ ¡£¡£¡£¡£¹¥»÷ÕßÎÞÐè¾­ÓÉÉí·ÝÑéÖ¤¼´¿ÉʹÓøÃÎó²î»á¼û×°±¸¡£ ¡£¡£¡£¡£

ÔÚÆôÓÃÇå¾²ÐÔ¶ÏÑÔ±ê¼ÇÓïÑÔ£¨SAML£©Éí·ÝÑéÖ¤²¢½ûÓá°ÑéÖ¤Éí·ÝÌṩÉÌÖ¤Ê顱ѡÏîʱ£¬ £¬£¬ÓÉÓÚPAN-OS SAMLÉí·ÝÑéÖ¤Àú³ÌÖÐûÓÐ׼ȷµØÑéÖ¤ÊðÃû£¬ £¬£¬µ¼ÖÂδ¾­Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔ¸ü¸ÄPAN OSµÄÉèÖú͹¦Ð§¡£ ¡£¡£¡£¡£Ìõ¼þÌõ¼þÊǹ¥»÷Õß±ØÐè¿ÉÒÔ»á¼ûÒ×Êܹ¥»÷µÄЧÀÍÆ÷£¬ £¬£¬²Å»ªÊ¹ÓôËÎó²î¡£ ¡£¡£¡£¡£


ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾


¸ÃÎó²îÊÇÔÚCVSSv3ÑÏÖØÆ·¼¶ÖлñµÃ10·ÖµÄÓÐÊýÎó²îÖ®Ò»£¬ £¬£¬¼È²»ÐèÒª¸ß¼¶ÊÖÒÕÊÖÒÕ£¬ £¬£¬ÓÖ¿ÉÒÔͨ¹ýInternet¾ÙÐÐÔ¶³ÌʹÓᣠ¡£¡£¡£¡£ÃÀ¹úÍøÂç˾ÁҪÇóËùÓÐÊÜCVE-2020-2021Ó°ÏìµÄ×°±¸Á¬Ã¦ÐÞ¸´¸ÃÎó²î£¬ £¬£¬²¢ÌåÏÖÍâ¹úµÄAPT×éÖ¯¿ÉÄܺܿì¾Í»áʵÑéʹÓøÃÎó²îÌᳫ¹¥»÷¡£ ¡£¡£¡£¡£

¿ÉÒÔͨ¹ý»ùÓÚSAMLµÄµ¥µãµÇ¼£¨SSO£©Éí·ÝÑéÖ¤±£»£»£»£»£»£»£»£»¤µÄ×ÊÔ´ÓУº

GlobalProtect Gateway,

GlobalProtect Portal,

GlobalProtect Clientless VPN,

Authentication and Captive Portal,

PAN-OS next-generation firewalls (PA-Series, VM-Series) and Panorama web interfaces

Prisma Access

¹ØÓÚGlobalProtectÍø¹Ø¡¢GlobalProtectÃÅ»§¡¢ÎÞ¿Í»§¶ËVPN¡¢Captive PortalºÍPrisma Access£¬ £¬£¬Î´¾­Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔͨ¹ýÍøÂç»á¼ûЧÀÍÆ÷ÉÏÊܱ£»£»£»£»£»£»£»£»¤µÄ×ÊÔ´£¬ £¬£¬²»»áÓ°ÏìÍø¹Ø£¬ £¬£¬ÃÅ»§»òVPNЧÀÍÆ÷µÄÍêÕûÐԺͿÉÓÃÐÔ£¬ £¬£¬µ«¹¥»÷ÕßÎÞ·¨¼ì²é»ò¸Ä¶¯Í¨Ë×Óû§µÄ»á»°¡£ ¡£¡£¡£¡£ÕâÊÇÒ»¸öÑÏÖØ¼¶±ðµÄÎó²î£¬ £¬£¬CVSSÆÀ·Ö10.0¡£ ¡£¡£¡£¡£

¹ØÓÚPAN-OSºÍPanorama Web½çÃæ£¬ £¬£¬ÈôÊÇδ¾­Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¾ßÓжÔPAN-OS»òPanorama Web½çÃæµÄ»á¼ûȨ£¬ £¬£¬¼´¿ÉÒÔÖÎÀíÔ±Éí·ÝµÇ¼²¢Ö´ÐÐÖÎÀí²Ù×÷¡£ ¡£¡£¡£¡£ÕâÊÇÒ»¸öÑÏÖØ¼¶±ðµÄÎó²î£¬ £¬£¬CVSSÆÀ·Ö10.0£¬ £¬£¬ÈôÊǽö¿Éͨ¹ýÊÜÏÞÖÎÀíÍøÂç»á¼ûWeb½çÃæ£¬ £¬£¬ÔòCVSSÆÀ·Ö9.6¡£ ¡£¡£¡£¡£

ÒÔÏÂÊÇCVE-2020-2021Îó²îÓ°ÏìµÄPalo Alto Networks PAN-OS°æ±¾£º


ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾



ÇëÏà¹ØÓû§¾¡¿ìÉó²éÉèÖ㬠£¬£¬ÊµÊ±È·ÈÏÊÇ·ñÊܵ½¸ÃÎó²îÓ°Ï죬 £¬£¬ÏêϸҪÁìÈçÏ£º

? ½öµ±ÆôÓÃÁËSAMLÉí·ÝÑéÖ¤²¢ÇÒÔÚ¡°SAMLÉí·ÝÌṩÉÌЧÀÍÆ÷ÉèÖÃÎļþ¡±ÖнûÓá°Éí·ÝÌṩÉÌÖ¤Ê顱ѡÏîʱ£¬ £¬£¬²Å¿ÉÒÔʹÓøÃÎó²î¡£ ¡£¡£¡£¡£

? ÈôÊDz»Ê¹ÓÃSAML¾ÙÐÐÉí·ÝÑéÖ¤£¬ £¬£¬ÔòÎÞ·¨Ê¹ÓøÃÎó²î¡£ ¡£¡£¡£¡£

? ÈôÊÇÔÚSAMLÉí·ÝÌṩÉÌЧÀÍÆ÷ÉèÖÃÎļþÖÐÆôÓÃÁË¡°ÑéÖ¤Éí·ÝÌṩÉÌÖ¤Ê顱ѡÏ £¬£¬ÔòÎÞ·¨Ê¹ÓøÃÎó²î¡£ ¡£¡£¡£¡£

¹ØÓÚÔõÑù¼ì²éЧÀÍÆ÷ÉèÖò¢ÊµÑ黺½â²½·¥µÄ˵Ã÷£¬ £¬£¬Çë²Î¿¼£ºhttps://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000008UXK

? Òª¼ì²éÊÇ·ñÔÚ·À»ðǽÉÏÆôÓÃÁËSAMLÉí·ÝÑéÖ¤£¬ £¬£¬Çë²Î¿¼Device > Server Profiles > SAML Identity Provider£»£»£»£»£»£»£»£»

? Òª¼ì²éÊÇ·ñΪPanoramaÖÎÀíÔ±Éí·ÝÑéÖ¤ÆôÓÃÁËSAMLÉí·ÝÑéÖ¤£¬ £¬£¬Çë²Î¿¼Panorama >Server Profiles > SAML Identity Provider£»£»£»£»£»£»£»£»

? Òª¼ì²éÊÇ·ñΪPanoramaÖÎÀíµÄ·À»ðǽÆôÓÃÁËSAMLÉí·ÝÑéÖ¤£¬ £¬£¬Çë²Î¿¼Device > [template]> Server Profiles > SAML Identity Provider¡£ ¡£¡£¡£¡£

ƾ֤ÉèÖ㬠£¬£¬ÈκÎδ¾­ÊÚȨµÄ»á¼û¶¼»á¼Í¼ÔÚϵͳÈÕÖ¾ÖУ¬ £¬£¬¿ÉÊǺÜÄÑÇø·ÖÓÐÓõǼÃûºÍ¶ñÒâµÇ¼Ãû¡£ ¡£¡£¡£¡£


0x02 ´¦Öóͷ£½¨Òé


¹Ù·½ÒÑÐû²¼PAN-OS 8.1.15¡¢PAN-OS 9.0.9¡¢PAN-OS 9.1.3ºÍ¸ü¸ß°æ±¾£¬ £¬£¬ÇëÏà¹ØÓû§ÊµÊ±Éý¼¶¡£ ¡£¡£¡£¡£

×¢ÖØ£ºÔÚÉý¼¶µ½Àο¿°æ±¾Ö®Ç°£¬ £¬£¬ÇëÈ·±£½«SAMLÉí·ÝÌṩÉ̵ÄÊðÃûÖ¤ÊéÉèÖÃΪ¡°Éí·ÝÌṩÉÌÖ¤Ê顱£¬ £¬£¬ÒÔÈ·±£Óû§¿ÉÒÔ¼ÌÐø¾ÙÐÐÉí·ÝÑéÖ¤¡£ ¡£¡£¡£¡£Çë²Î¿¼£ºhttps://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/authentication/configure-saml-authentication

? PAN-OSÉý¼¶Ö®Ç°ºÍÖ®ºóËùÐèµÄËùÓвÙ×÷µÄÏêϸÐÅÏ¢£¬ £¬£¬Çë²Î¿¼£ºhttps://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000008UXK

? ΪÁËɨ³ýGlobalProtectÃÅ»§ºÍÍø¹ØÉϵÄδÊÚȨ»á»°£¬ £¬£¬Prisma Accessͨ¹ýPanoramaÖÎÀí£¬ £¬£¬ÇëʹÓÃPanorama¸ü¸ÄAuthentication Override cookieµÄÉèÖᣠ¡£¡£¡£¡£Çë²Î¿¼£ºhttps://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000008UXy

ÖØÐÂÆô¶¯·À»ðǽºÍPanorama¿ÉÒÔɨ³ýWeb½çÃæÉϵÄÈκÎδ¾­ÊÚȨµÄ»á»°¡£ ¡£¡£¡£¡£

? Ҫɨ³ýCaptive PortalÖеÄÈκÎδÊÚȨÓû§»á»°£¬ £¬£¬ÇëÖ´ÐÐÒÔϰ취£º

ÔËÐÐÒÔÏÂÏÂÁî

show user ip-user-mapping all type SSO

¹ØÓÚ·µ»ØµÄËùÓÐIP£¬ £¬£¬ÇëÔËÐÐÒÔÏÂÁ½¸öÏÂÁîÒÔɨ³ýÓû§£º

clear user-cache-mp

clear user-cache

? PAN-OS 8.0ÒÑÖÕÖ¹Ö§³Ö£¨×èÖ¹2019Äê10ÔÂ31ÈÕ£©£¬ £¬£¬²»ÔÙά»¤¡£ ¡£¡£¡£¡£

ËùÓÐPrisma AccessЧÀ;ùÒÑÉý¼¶ÒÔ½â¾ö´ËÎÊÌ⣬ £¬£¬²¢ÇÒ²»ÔÙÒ×Êܹ¥»÷¡£ ¡£¡£¡£¡£Prisma Access¿Í»§²»ÐèÒª¶ÔSAML»òIdPÉèÖþÙÐÐÈκθü¸Ä¡£ ¡£¡£¡£¡£

ÔÝʱ²½·¥£º

? ʹÓÃÆäËûÉí·ÝÑéÖ¤ÒªÁì²¢½ûÓÃSAMLÉí·ÝÑéÖ¤£»£»£»£»£»£»£»£»

? ÔÚÖ´ÐÐÉý¼¶Ö®Ç°£¬ £¬£¬Í¬Ê±Ó¦Óã¨a£©ºÍ£¨b£©Á½Ï½â²½·¥¡£ ¡£¡£¡£¡£

£¨a£©È·±£ÒÑÉèÖá°Éí·ÝÌṩÉÌÖ¤Ê顱¡£ ¡£¡£¡£¡£ÉèÖá°Éí·ÝÌṩÉÌÖ¤Ê顱ÊÇÇå¾²SAMLÉí·ÝÑéÖ¤ÉèÖõÄÖ÷Òª×é³É²¿·Ö¡£ ¡£¡£¡£¡£

£¨b£©ÈôÊÇÉí·ÝÌṩÉÌ£¨IDP£©Ö¤ÊéÊÇÖ¤Êé½ÒÏþ»ú¹¹£¨CA£©ÊðÃûµÄÖ¤Ê飬 £¬£¬ÔòÈ·±£ÔÚSAMLÉí·ÝÌṩÉÌЧÀÍÆ÷ÉèÖÃÎļþÖÐÆôÓÃÁË¡°Éí·ÝÌṩÉÌÖ¤Ê顱ѡÏî¡£ ¡£¡£¡£¡£Ä¬ÈÏÇéÐÎÏ£¬ £¬£¬Ðí¶àÊ¢ÐеÄIDP¶¼»áÌìÉú×ÔÊðÃûIDPÖ¤Ê飬 £¬£¬²¢ÇÒÎÞ·¨ÆôÓá°ÑéÖ¤Éí·ÝÌṩÉÌÖ¤Ê顱ѡÏî¡£ ¡£¡£¡£¡£ÒªÊ¹ÓÃÓÉCAÊðÃûµÄÖ¤Ê飬 £¬£¬¿ÉÄÜÐèÒªÖ´ÐÐÆäËû°ì·¨¡£ ¡£¡£¡£¡£¸ÃÖ¤Êé¿ÉÒÔÓÉÄÚ²¿ÆóÒµCA£¬ £¬£¬PAN OSÉϵÄCA»ò¹«¹²CAÊðÃû¡£ ¡£¡£¡£¡£¿£¿£¿£¿ÉÔÚhttps://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000008UXPÉÏ»ñÈ¡ÓйØÔÚIDPÉÏÉèÖÃCA½ÒÏþµÄÖ¤ÊéµÄ˵Ã÷¡£ ¡£¡£¡£¡£


0x03 Ïà¹ØÐÂÎÅ


https://www.zdnet.com/article/us-cyber-command-says-foreign-hackers-will-most-likely-exploit-new-pan-os-security-bug/


0x04 ²Î¿¼Á´½Ó


https://security.paloaltonetworks.com/CVE-2020-2021?from=timeline&isappinstalled=0


0x05 ʱ¼äÏß


2020-06-29 Palo Alto NetworksÐû²¼Ç徲ͨ¸æ

2020-06-30 VSRCÐû²¼Îó²îͨ¸æ


ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾