¡¾Îó²îͨ¸æ¡¿Pulse Connect Secure 8Ô¶à¸öÇå¾²Îó²î
Ðû²¼Ê±¼ä 2021-08-090x00 Îó²î¸ÅÊö
2021Äê8ÔÂ2ÈÕ£¬£¬£¬£¬£¬£¬Ivanti Ðû²¼ÁË Pulse Connect Secure ϵͳÈí¼þ°æ±¾ 9.1R12£¬£¬£¬£¬£¬£¬ÐÞ¸´ÁËPulse Connect Secure VPN×°±¸ÖеĶà¸öÇå¾²Îó²î£¬£¬£¬£¬£¬£¬ÀÖ³ÉʹÓÃÕâЩÎó²îµÄ¹¥»÷Õß¿ÉÒÔʵÏÖRCE¡¢XSS¹¥»÷¡¢ÏÂÁî×¢Èë»òí§ÒâÎļþɾ³ý¡£¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬£¬£¬ÕâЩÎó²îÔÝδ·¢Ã÷ÔÚҰʹÓᣡ£¡£¡£¡£
0x01 Îó²îÏêÇé

±¾´Î¹ûÕæµÄ£¶¸öÎó²î¶¼¿ÉÒÔ±»Ô¶³ÌʹÓ㬣¬£¬£¬£¬£¬ÆäÖУ¬£¬£¬£¬£¬£¬CVE-2021-22937ºÍCVE-2021-22935×îΪÑÏÖØ¡£¡£¡£¡£¡£ÕâЩÎó²îµÄÏêÇéÈçÏ£º
Pulse Connect SecureÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-22937£©
¾ÓÉÉí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔʹÓôËÎó²îÔÚweb½çÃæÉÏ´«¶ñÒâÎļþÀ´ÊµÏÖÎļþдÈë»òÖ´ÐдúÂë¡£¡£¡£¡£¡£¸ÃÎó²îµÄCVSSv3ÆÀ·ÖΪ9.1¡£¡£¡£¡£¡£
Pulse Connect Secureí§ÒâÎļþɾ³ýÎó²î£¨CVE-2021-22933£©
¾ÓÉÉí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔͨ¹ý¶ñÒâÖÆ×÷µÄ Web ÇëÇóʵÏÖí§ÒâÎļþɾ³ý¡£¡£¡£¡£¡£¸ÃÎó²îµÄCVSSv3ÆÀ·ÖΪ7.6¡£¡£¡£¡£¡£
Pulse Connect Secure»º³åÇøÒç³öÎó²î£¨CVE-2021-22934£©
¾ÓÉÉí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔͨ¹ý¶ñÒâÖÆ×÷µÄWebÇëÇóÔì³ÉPulse Connect Secure ×°±¸»º³åÇøÒç³ö¡£¡£¡£¡£¡£¸ÃÎó²îµÄCVSSv3ÆÀ·ÖΪ8.0¡£¡£¡£¡£¡£
Pulse Connect SecureÏÂÁî×¢ÈëÎó²î£¨CVE-2021-22935£©
¾ÓÉÉí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔͨ¹ýδ´¦Öóͷ£µÄweb²ÎÊýÖ´ÐÐÏÂÁî×¢Èë¡£¡£¡£¡£¡£¸ÃÎó²îµÄCVSSv3ÆÀ·ÖΪ9.1¡£¡£¡£¡£¡£
Pulse Connect Secure XSSÎó²î£¨CVE-2021-22936£©
¹¥»÷Õß¿ÉÒÔͨ¹ýδ´¦Öóͷ£µÄweb²ÎÊý¶Ô¾ÓÉÉí·ÝÑéÖ¤µÄÖÎÀíÔ±¾ÙÐпçÕ¾¾ç±¾¹¥»÷¡£¡£¡£¡£¡£¸ÃÎó²îµÄCVSSv3ÆÀ·ÖΪ8.2¡£¡£¡£¡£¡£
Pulse Connect Secure ÏÂÁî×¢ÈëÎó²î£¨CVE-2021-22938£©
¾ÓÉÉí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔͨ¹ýÖÎÀíÔ± Web ¿ØÖÆÌ¨ÖÐδ´¦Öóͷ£µÄWeb ²ÎÊýÖ´ÐÐÏÂÁî×¢Èë¡£¡£¡£¡£¡£¸ÃÎó²îµÄCVSSv3ÆÀ·ÖΪ7.9¡£¡£¡£¡£¡£
Ó°Ïì¹æÄ£
Pulse Connect Secure < 9.1R12
0x02 ´¦Öóͷ£½¨Òé
ÏÖÔÚÕâЩÎó²îÒѾÐÞ¸´¡£¡£¡£¡£¡£½¨ÒéÊÜÓ°ÏìµÄ¿Í»§ÊµÊ±Éý¼¶¸üÐÂÖÁPCS 9.1R12°æ±¾£¨ÒÑÓÚ2021 Äê 8 Ô 2 ÈÕÐû²¼£©¡£¡£¡£¡£¡£
ÏÂÔØÁ´½Ó£º
https://www.ivanti.com/products/connect-secure-vpn?psredirect
0x03 ²Î¿¼Á´½Ó
https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44858
https://us-cert.cisa.gov/ncas/current-activity/2021/08/06/ivanti-releases-security-update-pulse-connect-secure
https://securityaffairs.co/wordpress/120880/security/pulse-connect-secure-vpn-flaw-2.html?
0x04 ¸üа汾
°æ±¾ | ÈÕÆÚ | ÐÞ¸ÄÄÚÈÝ |
V1.0 | 2021-08-09 | Ê×´ÎÐû²¼ |
0x05 Îĵµ¸½Â¼
CNVD£ºwww.cnvd.org.cn
CNNVD£ºwww.cnnvd.org.cn
CVE£ºcve.mitre.org
NVD£ºnvd.nist.gov
CVSS£ºwww.first.org
0x06 ¹ØÓÚÍòÀû¹ú¼Ê¹ÙÍø
¹Ø×¢ÒÔϹ«Öںţ¬£¬£¬£¬£¬£¬»ñÈ¡¸ü¶à×ÊѶ£º



¾©¹«Íø°²±¸11010802024551ºÅ