¡¾Îó²îͨ¸æ¡¿Cisco ASA & FTD¾Ü¾øÐ§ÀÍÎó²î£¨CVE-2024-20353£©
Ðû²¼Ê±¼ä 2024-04-25Ò»¡¢Îó²î¸ÅÊö
Îó²îÃû³Æ | Cisco ASA & FTD¾Ü¾øÐ§ÀÍÎó²î | ||
CVE ID | CVE-2024-20353 | ||
Îó²îÀàÐÍ | Dos | ·¢Ã÷ʱ¼ä | 2024-04-25 |
Îó²îÆÀ·Ö | 8.6 | Îó²îÆ·¼¶ | ¸ßΣ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | ÎÞ |
ʹÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ÎÞ |
PoC/EXP | δ֪ | ÔÚҰʹÓà | ÒÑ·¢Ã÷ |
Cisco Adaptive Security Appliance£¨ASA£©ÊÇCisco Systems ÌṩµÄһϵÁм¯³ÉÇå¾²½â¾ö¼Æ»®£¬£¬£¬²úÆ·Ïß°üÀ¨Â·ÓÉÆ÷¡¢Ð§ÀÍÆ÷¡¢·À»ðǽ¡¢VPN Íø¹ØºÍ IDS/IPS ×°±¸¡£¡£¡£¡£¡£Cisco Firepower Threat Defense£¨FTD£©ÊÇÒ»¸öͳһµÄÇå¾²½â¾ö¼Æ»®£¬£¬£¬ÌṩÕë¶ÔÖØ´óÍþвµÄÖÜÈ«±£»£»¤¡£¡£¡£¡£¡£
2024Äê4ÔÂ25ÈÕ£¬£¬£¬¿Ðý¹ú¼ÊÓÎÏ·VSRC¼à²âµ½CiscoÐû²¼Õë¶ÔÆä·À»ðǽƽ̨µÄ¹¥»÷ÊÂÎñÏìӦͨ¸æ£¬£¬£¬ÍþвÕßͨ¹ýʹÓÃCisco ASA ºÍ FTDÈí¼þÖеĶà¸öÎó²î¾ÙÐй¥»÷£¬£¬£¬ÒÔÖ²Èë¶ñÒâÈí¼þ¡¢Ö´ÐÐÏÂÁî¡¢²¢¿ÉÄÜ´ÓÊÜѬȾµÄ×°±¸ÖÐÇÔÈ¡Êý¾Ý¡£¡£¡£¡£¡£
CVE-2024-20353£ºCisco ASA & FTD¾Ü¾øÐ§ÀÍÎó²î£¨¸ßΣ£©
Cisco ASA ºÍ FTDÈí¼þµÄÖÎÀíºÍVPN WebЧÀÍÆ÷Öб£´æ¾Ü¾øÐ§ÀÍÎó²î£¬£¬£¬ÓÉÓÚÆÊÎöHTTP±êͷʱ¹ýʧ¼ì²é²»ÍêÕû£¬£¬£¬Î´¾Éí·ÝÑéÖ¤µÄÔ¶³ÌÍþвÕß¿ÉÒÔͨ¹ýÏòÄ¿µÄwebЧÀÍÆ÷·¢ËͶñÒâµÄHTTPÇëÇóÀ´Ê¹ÓøÃÎó²î£¬£¬£¬ÀÖ³ÉʹÓÿÉÄܵ¼ÖÂ×°±¸ÖØÐ¼ÓÔØ£¬£¬£¬´Ó¶øµ¼Ö¾ܾøÐ§ÀÍ¡£¡£¡£¡£¡£¸ÃÎó²îµÄCVSSÆÀ·ÖΪ8.6£¬£¬£¬ÏÖÔÚÒÑ·¢Ã÷±»Ê¹Óᣡ£¡£¡£¡£
CVE-2024-20359£ºCisco ASA & FTD´úÂëÖ´ÐÐÎó²î£¨¸ßΣ£©
Cisco ASA ºÍ FTDµÄijЩ¹¦Ð§Öб£´æÎó²î£¬£¬£¬ÓÉÓÚ´ÓϵͳÉÁ´æ¶ÁÈ¡Îļþʱ¶ÔÎļþÑéÖ¤²»µ±£¬£¬£¬¾ÓÉÉí·ÝÑéÖ¤ÇÒ¾ßÓÐÖÎÀíԱȨÏÞµÄÍâµØÍþвÕß¿ÉÒÔͨ¹ý½«¶ñÒâÉè¼ÆµÄÎļþ¸´ÖƵ½ÊÜÓ°Ïì×°±¸µÄdisk0:ÎļþϵͳÀ´Ê¹ÓøÃÎó²î£¬£¬£¬ÀÖ³ÉʹÓÿÉÄܵ¼ÖÂÍþвÕßÔÚÏ´ÎÖØÐ¼ÓÔØ×°±¸ºóÔÚÊÜÓ°ÏìµÄ×°±¸ÉÏÖ´ÐÐí§Òâ´úÂ룬£¬£¬ÇÒ×¢ÈëµÄ´úÂë¿ÉÄÜ»áÔÚ×°±¸ÖØÐÂÆô¶¯ºóÒ»Á¬±£´æ£¬£¬£¬´Ó¶øµ¼Ö³¤ÆÚÍâµØ´úÂëÖ´ÐС£¡£¡£¡£¡£¸ÃÎó²îµÄCVSSÆÀ·ÖΪ6.0£¬£¬£¬ÏÖÔÚÒÑ·¢Ã÷±»Ê¹Óᣡ£¡£¡£¡£
CVE-2024-20358£ºCisco ASA & FTDÏÂÁî×¢ÈëÎó²î£¨ÖÐΣ£©
Cisco ASA ºÍFTDÖÐµÄ Cisco ASA»Ö¸´¹¦Ð§±£´æÎó²î£¬£¬£¬ÓÉÓÚ±¸·ÝÎļþµÄÄÚÈÝÔÚ»Ö¸´Ê±Î´×¼È·ÕûÀí£¬£¬£¬¾ÓÉÉí·ÝÑéÖ¤ÇÒ¾ßÓÐÖÎÀíԱȨÏÞµÄÍâµØÍþвÕß¿ÉÒÔͨ¹ý½«¶ñÒâÉè¼ÆµÄ±¸·ÝÎļþ»Ö¸´µ½ÊÜÓ°ÏìµÄ×°±¸À´Ê¹ÓøÃÎó²î£¬£¬£¬ÀÖ³ÉʹÓÿÉÄܵ¼ÖÂÒÔrootȨÏÞÔڵײãϵͳÉÏÖ´ÐÐí§ÒâÏÂÁî¡£¡£¡£¡£¡£
¶þ¡¢Ó°Ïì¹æÄ£
Ϊ×ÊÖú¿Í»§È·¶¨Æä Cisco ASA¡¢FMC ºÍ FTD Èí¼þÖÐÊÇ·ñ±£´æÎó²î£¬£¬£¬Ë¼¿ÆÌṩÁË˼¿ÆÈí¼þ¼ì²éÆ÷¹¤¾ß£¬£¬£¬Óû§¿ÉʹÓøù¤¾ßÅжÏÄ¿½ñ×°±¸µÄÈí¼þ°æ±¾ÊÇ·ñÊÜÕâЩÎó²îÓ°Ï죬£¬£¬²¢¸üе½²»ÊÜÓ°Ïì°æ±¾¡£¡£¡£¡£¡£ÒªÊ¹Óøù¤¾ß£¬£¬£¬ÇëתÖÁCisco Software CheckerÒ³Ãæ²¢Æ¾Ìý˵Ã÷¾ÙÐвÙ×÷£ºhttps://sec.cloudapps.cisco.com/security/center/softwarechecker.x
Èý¡¢Çå¾²²½·¥
3.1 Éý¼¶°æ±¾
ÏÖÔÚÕâЩÎó²îÒѾÐÞ¸´£¬£¬£¬ÊÜÓ°ÏìÓû§¿ÉʹÓùٷ½ÌṩµÄ¹¤¾ß»ò²½·¥¾ÙÐÐÅŲ飬£¬£¬²¢Éý¼¶µ½²»ÊÜÓ°Ïì»ò×îеĹ̼þ°æ±¾£¬£¬£¬»ò¹Ø±Õ×°±¸Ò×Êܹ¥»÷µÄÉèÖú͹¦Ð§ÒÔ»º½â¸ÃÎó²î¡£¡£¡£¡£¡£
²Î¿¼Á´½Ó£º
https://sec.cloudapps.cisco.com/security/center/resources/asa_ftd_attacks_event_response?
3.2 ÔÝʱ²½·¥
Õë¶ÔCVE-2024-20353£¬£¬£¬¿É²Î¿¼ÒÔϲ½·¥¾ÙÐÐÊÖ¶¯ÅŲ飺
È·¶¨ASA»òFTD×°±¸ÊÇ·ñÊܵ½Ó°Ïì
Ҫȷ¶¨ÔËÐÐCisco ASAÈí¼þ»òFTDÈí¼þµÄ×°±¸ÊÇ·ñÊܵ½Ó°Ï죬£¬£¬ÇëʹÓÃshow asp table socket | include SSLÏÂÁîÔÚÈκÎTCP ¶Ë¿ÚÉϲéÕÒ SSL ÕìÌýÌ×½Ó×Ö¡£¡£¡£¡£¡£ÈôÊÇÊä³öÖзºÆðsocket£¬£¬£¬ÔòÓ¦ÒÔΪ¸Ã×°±¸±£´æÎó²î¡£¡£¡£¡£¡£Cisco ASA ×°±¸Ê¾ÀýÈçÏ£º
ciscoasa# show asp table socket | include SSL
SSL 00185038 LISTEN 172.16.0.250:443 0.0.0.0:*
SSL 00188638 LISTEN 10.0.0.250:8443 0.0.0.0:*
ÈôÊÇ Cisco ASA Èí¼þºÍ FTD Èí¼þ¾ßÓÐÒÔÏÂÁ½¸ö±íÖÐÁгöµÄÒ»Ïî»ò¶àÏîÒ×Êܹ¥»÷µÄÉèÖ㬣¬£¬Ôò´ËÎó²î»áÓ°ÏìËüÃÇ¡£¡£¡£¡£¡£ÕâЩ¹¦Ð§¿ÉÄܻᵼÖÂÆôÓÃSSLÕìÌýÌ×½Ó×Ö¡£¡£¡£¡£¡£
ASA Èí¼þÒ×Êܹ¥»÷µÄÉèÖÃ
Ò×Êܹ¥»÷µÄ˼¿ÆASAÈí¼þ¹¦Ð§ | ¿ÉÄܱ£´æÎó²îµÄÉèÖã¨show running-config CLIÏÂÁîÖеÄÉèÖã© |
AnyConnect IKEv2 Ô¶³Ì»á¼û£¨Ê¹Óÿͻ§¶ËЧÀÍ£© | crypto ikev2 enable [...] client-services port |
ÍâµØÖ¤Êé½ÒÏþ»ú¹¹ (CA) | crypto ca server no shutdown |
ÖÎÀí Web ЧÀÍÆ÷»á¼û£¨°üÀ¨ ASDM ºÍ CSM£© | http server enable http |
Mobile User Security (MUS) | webvpn mus password mus server enable port mus |
REST API | rest-api image disk0:/rest-api agent |
SSL VPN | webvpn enable |
FTD Èí¼þÒ×Êܹ¥»÷µÄÉèÖÃ
Ò×Êܹ¥»÷µÄ˼¿ÆFTDÈí¼þ¹¦Ð§ | ¿ÉÄܱ£´æÎó²îµÄÉèÖã¨show running-config CLIÏÂÁîÖеÄÉèÖã© |
AnyConnect IKEv2 Ô¶³Ì»á¼û£¨Ê¹Óÿͻ§¶ËЧÀÍ£© | crypto ikev2 enable [...] client-services port |
AnyConnect SSL VPN | webvpn enable |
HTTP server enabled | http server enable http |
3.3 ͨÓý¨Òé
l °´ÆÚ¸üÐÂϵͳ²¹¶¡£¡£¡£¡£¡£¬£¬£¬ïÔÌϵͳÎó²î£¬£¬£¬ÌáÉýЧÀÍÆ÷µÄÇå¾²ÐÔ¡£¡£¡£¡£¡£
l ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬£¬£¬Ð޸ķÀ»ðǽսÂÔ£¬£¬£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻòЧÀÍ£¬£¬£¬ïÔ̽«Î£ÏÕЧÀÍ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬£¬£¬ïÔ̹¥»÷Ãæ¡£¡£¡£¡£¡£
l ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬£¬£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£¡£¡£¡£¡£
l ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬£¬£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔÔò£¬£¬£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏÞ¶È¡£¡£¡£¡£¡£
l ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£¡£¡£¡£¡£
3.4 ²Î¿¼Á´½Ó
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-websrvs-dos-X8gNucD2
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-persist-rce-FLsNXF4h#fs
https://blog.talosintelligence.com/arcanedoor-new-espionage-focused-campaign-found-targeting-perimeter-network-devices/
ËÄ¡¢°æ±¾ÐÅÏ¢
°æ±¾ | ÈÕÆÚ | ±¸×¢ |
V1.0 | 2024-04-25 | Ê×´ÎÐû²¼ |
Îå¡¢¸½Â¼
5.1 ¿Ðý¹ú¼ÊÓÎÏ·¼ò½é
¿Ðý¹ú¼ÊÓÎÏ·½¨ÉèÓÚ1996Ä꣬£¬£¬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ½¨ÉèµÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢Çå¾²¸ß¿Æ¼¼ÆóÒµ¡£¡£¡£¡£¡£ÊǺ£ÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Çå¾²²úÆ·¡¢Ç徲ЧÀͽâ¾ö¼Æ»®µÄÁ캽ÆóÒµÖ®Ò»¡£¡£¡£¡£¡£
¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°¿Ðý¹ú¼ÊÓÎÏ·´óÏ㬣¬£¬¹«Ë¾Ô±¹¤6000ÓàÈË£¬£¬£¬Ñз¢ÍŶÓ1200ÓàÈË, ÊÖÒÕЧÀÍÍŶÓ1300ÓàÈË¡£¡£¡£¡£¡£ÔÚÌìϸ÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬£¬£¬ÓµÓÐÁýÕÖÌìϵÄÏúÊÛϵͳ¡¢ÇþµÀϵͳºÍÊÖÒÕÖ§³Öϵͳ¡£¡£¡£¡£¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐС°å¹ÒÅÆÉÏÊС£¡£¡£¡£¡££¨¹ÉƱ´úÂ룺002439£©
¶àÄêÀ´£¬£¬£¬¿Ðý¹ú¼ÊÓÎÏ·ÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷Á¢ÒìµÄÇå¾²²úÆ·ºÍ×î¼Ñʵ¼ùЧÀÍ£¬£¬£¬×ÊÖú¿Í»§ÖÜÈ«ÌáÉýÆäIT»ù´¡ÉèÊ©µÄÇå¾²ÐÔºÍÉú²úЧÄÜ£¬£¬£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Çå¾²¹¤ÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸Æð¾¢¡£¡£¡£¡£¡£
5.2 ¹ØÓÚ¿Ðý¹ú¼ÊÓÎÏ·
¿Ðý¹ú¼ÊÓÎÏ·Çå¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÒÑÐû²¼1000¶à¸öÎó²îͨ¸æºÍΣº¦Ô¤¾¯£¬£¬£¬ÎÒÃǽ«Ò»Á¬¸ú×ÙÈ«Çò×îеÄÍøÂçÇå¾²ÊÂÎñºÍÎó²î£¬£¬£¬ÎªÆóÒµµÄÐÅÏ¢Çå¾²±£¼Ý»¤º½¡£¡£¡£¡£¡£
¹Ø×¢ÎÒÃÇ£º