¡¾Îó²îͨ¸æ¡¿Cisco ASA & FTD¾Ü¾øÐ§ÀÍÎó²î£¨CVE-2024-20353£©
Ðû²¼Ê±¼ä 2024-04-25Ò»¡¢Îó²î¸ÅÊö
Îó²îÃû³Æ | Cisco ASA & FTD¾Ü¾øÐ§ÀÍÎó²î | ||
CVE ID | CVE-2024-20353 | ||
Îó²îÀàÐÍ | Dos | ·¢Ã÷ʱ¼ä | 2024-04-25 |
Îó²îÆÀ·Ö | 8.6 | Îó²îÆ·¼¶ | ¸ßΣ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | ÎÞ |
ʹÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ÎÞ |
PoC/EXP | δ֪ | ÔÚҰʹÓà | ÒÑ·¢Ã÷ |
Cisco Adaptive Security Appliance£¨ASA£©ÊÇCisco Systems ÌṩµÄһϵÁм¯³ÉÇå¾²½â¾ö¼Æ»®£¬£¬£¬£¬£¬£¬£¬£¬²úÆ·Ïß°üÀ¨Â·ÓÉÆ÷¡¢Ð§ÀÍÆ÷¡¢·À»ðǽ¡¢VPN Íø¹ØºÍ IDS/IPS ×°±¸¡£¡£¡£Cisco Firepower Threat Defense£¨FTD£©ÊÇÒ»¸öͳһµÄÇå¾²½â¾ö¼Æ»®£¬£¬£¬£¬£¬£¬£¬£¬ÌṩÕë¶ÔÖØ´óÍþвµÄÖÜÈ«±£»£»£»£»¤¡£¡£¡£
2024Äê4ÔÂ25ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬ÍòÀû¹ú¼Ê¹ÙÍøVSRC¼à²âµ½CiscoÐû²¼Õë¶ÔÆä·À»ðǽƽ̨µÄ¹¥»÷ÊÂÎñÏìӦͨ¸æ£¬£¬£¬£¬£¬£¬£¬£¬ÍþвÕßͨ¹ýʹÓÃCisco ASA ºÍ FTDÈí¼þÖеĶà¸öÎó²î¾ÙÐй¥»÷£¬£¬£¬£¬£¬£¬£¬£¬ÒÔÖ²Èë¶ñÒâÈí¼þ¡¢Ö´ÐÐÏÂÁî¡¢²¢¿ÉÄÜ´ÓÊÜѬȾµÄ×°±¸ÖÐÇÔÈ¡Êý¾Ý¡£¡£¡£
CVE-2024-20353£ºCisco ASA & FTD¾Ü¾øÐ§ÀÍÎó²î£¨¸ßΣ£©
Cisco ASA ºÍ FTDÈí¼þµÄÖÎÀíºÍVPN WebЧÀÍÆ÷Öб£´æ¾Ü¾øÐ§ÀÍÎó²î£¬£¬£¬£¬£¬£¬£¬£¬ÓÉÓÚÆÊÎöHTTP±êͷʱ¹ýʧ¼ì²é²»ÍêÕû£¬£¬£¬£¬£¬£¬£¬£¬Î´¾Éí·ÝÑéÖ¤µÄÔ¶³ÌÍþвÕß¿ÉÒÔͨ¹ýÏòÄ¿µÄwebЧÀÍÆ÷·¢ËͶñÒâµÄHTTPÇëÇóÀ´Ê¹ÓøÃÎó²î£¬£¬£¬£¬£¬£¬£¬£¬ÀÖ³ÉʹÓÿÉÄܵ¼ÖÂ×°±¸ÖØÐ¼ÓÔØ£¬£¬£¬£¬£¬£¬£¬£¬´Ó¶øµ¼Ö¾ܾøÐ§ÀÍ¡£¡£¡£¸ÃÎó²îµÄCVSSÆÀ·ÖΪ8.6£¬£¬£¬£¬£¬£¬£¬£¬ÏÖÔÚÒÑ·¢Ã÷±»Ê¹Óᣡ£¡£
CVE-2024-20359£ºCisco ASA & FTD´úÂëÖ´ÐÐÎó²î£¨¸ßΣ£©
Cisco ASA ºÍ FTDµÄijЩ¹¦Ð§Öб£´æÎó²î£¬£¬£¬£¬£¬£¬£¬£¬ÓÉÓÚ´ÓϵͳÉÁ´æ¶ÁÈ¡Îļþʱ¶ÔÎļþÑéÖ¤²»µ±£¬£¬£¬£¬£¬£¬£¬£¬¾ÓÉÉí·ÝÑéÖ¤ÇÒ¾ßÓÐÖÎÀíԱȨÏÞµÄÍâµØÍþвÕß¿ÉÒÔͨ¹ý½«¶ñÒâÉè¼ÆµÄÎļþ¸´ÖƵ½ÊÜÓ°Ïì×°±¸µÄdisk0:ÎļþϵͳÀ´Ê¹ÓøÃÎó²î£¬£¬£¬£¬£¬£¬£¬£¬ÀÖ³ÉʹÓÿÉÄܵ¼ÖÂÍþвÕßÔÚÏ´ÎÖØÐ¼ÓÔØ×°±¸ºóÔÚÊÜÓ°ÏìµÄ×°±¸ÉÏÖ´ÐÐí§Òâ´úÂ룬£¬£¬£¬£¬£¬£¬£¬ÇÒ×¢ÈëµÄ´úÂë¿ÉÄÜ»áÔÚ×°±¸ÖØÐÂÆô¶¯ºóÒ»Á¬±£´æ£¬£¬£¬£¬£¬£¬£¬£¬´Ó¶øµ¼Ö³¤ÆÚÍâµØ´úÂëÖ´ÐС£¡£¡£¸ÃÎó²îµÄCVSSÆÀ·ÖΪ6.0£¬£¬£¬£¬£¬£¬£¬£¬ÏÖÔÚÒÑ·¢Ã÷±»Ê¹Óᣡ£¡£
CVE-2024-20358£ºCisco ASA & FTDÏÂÁî×¢ÈëÎó²î£¨ÖÐΣ£©
Cisco ASA ºÍFTDÖÐµÄ Cisco ASA»Ö¸´¹¦Ð§±£´æÎó²î£¬£¬£¬£¬£¬£¬£¬£¬ÓÉÓÚ±¸·ÝÎļþµÄÄÚÈÝÔÚ»Ö¸´Ê±Î´×¼È·ÕûÀí£¬£¬£¬£¬£¬£¬£¬£¬¾ÓÉÉí·ÝÑéÖ¤ÇÒ¾ßÓÐÖÎÀíԱȨÏÞµÄÍâµØÍþвÕß¿ÉÒÔͨ¹ý½«¶ñÒâÉè¼ÆµÄ±¸·ÝÎļþ»Ö¸´µ½ÊÜÓ°ÏìµÄ×°±¸À´Ê¹ÓøÃÎó²î£¬£¬£¬£¬£¬£¬£¬£¬ÀÖ³ÉʹÓÿÉÄܵ¼ÖÂÒÔrootȨÏÞÔڵײãϵͳÉÏÖ´ÐÐí§ÒâÏÂÁî¡£¡£¡£
¶þ¡¢Ó°Ïì¹æÄ£
Ϊ×ÊÖú¿Í»§È·¶¨Æä Cisco ASA¡¢FMC ºÍ FTD Èí¼þÖÐÊÇ·ñ±£´æÎó²î£¬£¬£¬£¬£¬£¬£¬£¬Ë¼¿ÆÌṩÁË˼¿ÆÈí¼þ¼ì²éÆ÷¹¤¾ß£¬£¬£¬£¬£¬£¬£¬£¬Óû§¿ÉʹÓøù¤¾ßÅжÏÄ¿½ñ×°±¸µÄÈí¼þ°æ±¾ÊÇ·ñÊÜÕâЩÎó²îÓ°Ï죬£¬£¬£¬£¬£¬£¬£¬²¢¸üе½²»ÊÜÓ°Ïì°æ±¾¡£¡£¡£ÒªÊ¹Óøù¤¾ß£¬£¬£¬£¬£¬£¬£¬£¬ÇëתÖÁCisco Software CheckerÒ³Ãæ²¢Æ¾Ìý˵Ã÷¾ÙÐвÙ×÷£ºhttps://sec.cloudapps.cisco.com/security/center/softwarechecker.x
Èý¡¢Çå¾²²½·¥
3.1 Éý¼¶°æ±¾
ÏÖÔÚÕâЩÎó²îÒѾÐÞ¸´£¬£¬£¬£¬£¬£¬£¬£¬ÊÜÓ°ÏìÓû§¿ÉʹÓùٷ½ÌṩµÄ¹¤¾ß»ò²½·¥¾ÙÐÐÅŲ飬£¬£¬£¬£¬£¬£¬£¬²¢Éý¼¶µ½²»ÊÜÓ°Ïì»ò×îеĹ̼þ°æ±¾£¬£¬£¬£¬£¬£¬£¬£¬»ò¹Ø±Õ×°±¸Ò×Êܹ¥»÷µÄÉèÖú͹¦Ð§ÒÔ»º½â¸ÃÎó²î¡£¡£¡£
²Î¿¼Á´½Ó£º
https://sec.cloudapps.cisco.com/security/center/resources/asa_ftd_attacks_event_response?
3.2 ÔÝʱ²½·¥
Õë¶ÔCVE-2024-20353£¬£¬£¬£¬£¬£¬£¬£¬¿É²Î¿¼ÒÔϲ½·¥¾ÙÐÐÊÖ¶¯ÅŲ飺
È·¶¨ASA»òFTD×°±¸ÊÇ·ñÊܵ½Ó°Ïì
Ҫȷ¶¨ÔËÐÐCisco ASAÈí¼þ»òFTDÈí¼þµÄ×°±¸ÊÇ·ñÊܵ½Ó°Ï죬£¬£¬£¬£¬£¬£¬£¬ÇëʹÓÃshow asp table socket | include SSLÏÂÁîÔÚÈκÎTCP ¶Ë¿ÚÉϲéÕÒ SSL ÕìÌýÌ×½Ó×Ö¡£¡£¡£ÈôÊÇÊä³öÖзºÆðsocket£¬£¬£¬£¬£¬£¬£¬£¬ÔòÓ¦ÒÔΪ¸Ã×°±¸±£´æÎó²î¡£¡£¡£Cisco ASA ×°±¸Ê¾ÀýÈçÏ£º
ciscoasa# show asp table socket | include SSL
SSL 00185038 LISTEN 172.16.0.250:443 0.0.0.0:*
SSL 00188638 LISTEN 10.0.0.250:8443 0.0.0.0:*
ÈôÊÇ Cisco ASA Èí¼þºÍ FTD Èí¼þ¾ßÓÐÒÔÏÂÁ½¸ö±íÖÐÁгöµÄÒ»Ïî»ò¶àÏîÒ×Êܹ¥»÷µÄÉèÖ㬣¬£¬£¬£¬£¬£¬£¬Ôò´ËÎó²î»áÓ°ÏìËüÃÇ¡£¡£¡£ÕâЩ¹¦Ð§¿ÉÄܻᵼÖÂÆôÓÃSSLÕìÌýÌ×½Ó×Ö¡£¡£¡£
ASA Èí¼þÒ×Êܹ¥»÷µÄÉèÖÃ
Ò×Êܹ¥»÷µÄ˼¿ÆASAÈí¼þ¹¦Ð§ | ¿ÉÄܱ£´æÎó²îµÄÉèÖã¨show running-config CLIÏÂÁîÖеÄÉèÖã© |
AnyConnect IKEv2 Ô¶³Ì»á¼û£¨Ê¹Óÿͻ§¶ËЧÀÍ£© | crypto ikev2 enable [...] client-services port |
ÍâµØÖ¤Êé½ÒÏþ»ú¹¹ (CA) | crypto ca server no shutdown |
ÖÎÀí Web ЧÀÍÆ÷»á¼û£¨°üÀ¨ ASDM ºÍ CSM£© | http server enable http |
Mobile User Security (MUS) | webvpn mus password mus server enable port mus |
REST API | rest-api image disk0:/rest-api agent |
SSL VPN | webvpn enable |
FTD Èí¼þÒ×Êܹ¥»÷µÄÉèÖÃ
Ò×Êܹ¥»÷µÄ˼¿ÆFTDÈí¼þ¹¦Ð§ | ¿ÉÄܱ£´æÎó²îµÄÉèÖã¨show running-config CLIÏÂÁîÖеÄÉèÖã© |
AnyConnect IKEv2 Ô¶³Ì»á¼û£¨Ê¹Óÿͻ§¶ËЧÀÍ£© | crypto ikev2 enable [...] client-services port |
AnyConnect SSL VPN | webvpn enable |
HTTP server enabled | http server enable http |
3.3 ͨÓý¨Òé
l °´ÆÚ¸üÐÂϵͳ²¹¶¡£¡£¡£¬£¬£¬£¬£¬£¬£¬£¬ïÔÌϵͳÎó²î£¬£¬£¬£¬£¬£¬£¬£¬ÌáÉýЧÀÍÆ÷µÄÇå¾²ÐÔ¡£¡£¡£
l ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬£¬£¬£¬£¬£¬£¬£¬Ð޸ķÀ»ðǽսÂÔ£¬£¬£¬£¬£¬£¬£¬£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻòЧÀÍ£¬£¬£¬£¬£¬£¬£¬£¬ïÔ̽«Î£ÏÕЧÀÍ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬£¬£¬£¬£¬£¬£¬£¬ïÔ̹¥»÷Ãæ¡£¡£¡£
l ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬£¬£¬£¬£¬£¬£¬£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£¡£¡£
l ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬£¬£¬£¬£¬£¬£¬£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔÔò£¬£¬£¬£¬£¬£¬£¬£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏÞ¶È¡£¡£¡£
l ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£¡£¡£
3.4 ²Î¿¼Á´½Ó
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-websrvs-dos-X8gNucD2
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-persist-rce-FLsNXF4h#fs
https://blog.talosintelligence.com/arcanedoor-new-espionage-focused-campaign-found-targeting-perimeter-network-devices/
ËÄ¡¢°æ±¾ÐÅÏ¢
°æ±¾ | ÈÕÆÚ | ±¸×¢ |
V1.0 | 2024-04-25 | Ê×´ÎÐû²¼ |
Îå¡¢¸½Â¼
5.1 ÍòÀû¹ú¼Ê¹ÙÍø¼ò½é
ÍòÀû¹ú¼Ê¹ÙÍø½¨ÉèÓÚ1996Ä꣬£¬£¬£¬£¬£¬£¬£¬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ½¨ÉèµÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢Çå¾²¸ß¿Æ¼¼ÆóÒµ¡£¡£¡£ÊǺ£ÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Çå¾²²úÆ·¡¢Ç徲ЧÀͽâ¾ö¼Æ»®µÄÁ캽ÆóÒµÖ®Ò»¡£¡£¡£
¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°ÍòÀû¹ú¼Ê¹ÙÍø´óÏ㬣¬£¬£¬£¬£¬£¬£¬¹«Ë¾Ô±¹¤6000ÓàÈË£¬£¬£¬£¬£¬£¬£¬£¬Ñз¢ÍŶÓ1200ÓàÈË, ÊÖÒÕЧÀÍÍŶÓ1300ÓàÈË¡£¡£¡£ÔÚÌìϸ÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬£¬£¬£¬£¬£¬£¬£¬ÓµÓÐÁýÕÖÌìϵÄÏúÊÛϵͳ¡¢ÇþµÀϵͳºÍÊÖÒÕÖ§³Öϵͳ¡£¡£¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐС°å¹ÒÅÆÉÏÊС£¡£¡££¨¹ÉƱ´úÂ룺002439£©
¶àÄêÀ´£¬£¬£¬£¬£¬£¬£¬£¬ÍòÀû¹ú¼Ê¹ÙÍøÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷Á¢ÒìµÄÇå¾²²úÆ·ºÍ×î¼Ñʵ¼ùЧÀÍ£¬£¬£¬£¬£¬£¬£¬£¬×ÊÖú¿Í»§ÖÜÈ«ÌáÉýÆäIT»ù´¡ÉèÊ©µÄÇå¾²ÐÔºÍÉú²úЧÄÜ£¬£¬£¬£¬£¬£¬£¬£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Çå¾²¹¤ÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸Æð¾¢¡£¡£¡£
5.2 ¹ØÓÚÍòÀû¹ú¼Ê¹ÙÍø
ÍòÀû¹ú¼Ê¹ÙÍøÇå¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÒÑÐû²¼1000¶à¸öÎó²îͨ¸æºÍΣº¦Ô¤¾¯£¬£¬£¬£¬£¬£¬£¬£¬ÎÒÃǽ«Ò»Á¬¸ú×ÙÈ«Çò×îеÄÍøÂçÇå¾²ÊÂÎñºÍÎó²î£¬£¬£¬£¬£¬£¬£¬£¬ÎªÆóÒµµÄÐÅÏ¢Çå¾²±£¼Ý»¤º½¡£¡£¡£
¹Ø×¢ÎÒÃÇ£º



¾©¹«Íø°²±¸11010802024551ºÅ