Palo Alto Networks Cortex XSOARδÊÚȨ·ÃÎÊ©¶´£¨CVE-2021-3044£©

Ðû²¼Ê±¼ä 2021-06-23

0x00 ©¶´¸ÅÊö

CVE   ID

CVE-2021-3044

ʱ    ¼ä

2021-06-23

Àà    ÐÍ

δÊÚȨ·ÃÎÊ

µÈ    ¼¶

ÑÏÖØ

Ô¶³ÌÀûÓÃ

ÊÇ

Ó°Ï췶Χ


¹¥»÷ÅÓ´ó¶È

µÍ

¿ÉÓÃÐÔ

¸ß

Óû§½»»¥

ÎÞ

ËùÐèȨÏÞ

ÎÞ

PoC/EXP

δ¹ûÈ»

ÔÚÒ°ÀûÓÃ

·ñ

 

0x01 ©¶´ÏêÇé

image.png

Cortex? XSOARÊÇÈ«ÇòÍøÂçÄþ¾²Áìµ¼ÆóÒµPalo Alto NetworksÍÆ³öµÄÒ»¸öÈ«ÐÂÀ©Õ¹µÄÄþ¾²±àÅÅ¡¢×Ô¶¯»¯ÓëÏìӦƽ̨£¬²¢¼¯³ÉÁËÍþвÇ鱨¹ÜÀí¹¦Ð§£¬´Ó¶øÎªÆóÒµÄþ¾²Ìṩ¼´Ê±¡¢È«ÃæµÄÍþв·ÀÓù¡£

2021Äê06ÔÂ22ÈÕ£¬Palo Alto NetworksÐû²¼Äþ¾²Í¨¸æ£¬ÐÞ¸´ÁËCortex XSOARÖеÄÒ»¸öδÊÚȨ·ÃÎÊ©¶´£¨CVE-2021-3044£©£¬¸Ã©¶´µÄCVSSv3ÆÀ·ÖΪ9.8¡£Î´¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓôË©¶´Í¨¹ýREST APIÖ´ÐÐδ¾­ÊÚȨµÄ·ÃÎÊ¡£

¸Ã©¶´½ö´æÔÚÓÚÅäÖÃÁ˻µÄ¼¯³ÉAPI KeyµÄCortex XSOAR¡ £¿ÉÒÔ´ÓCortex XSOAR Web ¿Í»§¶ËÑ¡Ôñ¡®Settings > Integration > API Keys¡¯ À´¼ì²ìÅäÖÃÊÇ·ñÊܵ½Ó°Ïì¡£


Ó°Ï췶Χ

Cortex XSOAR 6.1.0£ºbuilds >= 1016923 and < 1271064

Cortex XSOAR 6.2.0£ºbuilds < 1271065

 

0x02 ´¦Öý¨Òé

Ŀǰ´Ë©¶´ÒѾ­ÐÞ¸´£¬½¨Òé²Î¿¼ÏÂ±í¼°Ê±Éý¼¶¸üС£´ËÍ⣬ÓÉPalo Alto NetworksÍйܵÄËùÓÐCortex XSOARʵÀý¶¼ÒÑÉý¼¶£¬²»ÐèÒªÔÙÖ´ÐÐÆäËü²Ù×÷¡£

°æ±¾

ÊÜÓ°Ïì°æ±¾

²»ÊÜÓ°Ïì°æ±¾

Cortex XSOAR 6.2.0

< 1271065

>= 1271065

Cortex XSOAR 6.1.0

>= 1016923 and < 1271064

< 1016923£¬ >= 1271064

Cortex XSOAR 6.0.2

None

all

Cortex XSOAR 6.0.1

None

all

Cortex XSOAR 6.0.0

None

all

Cortex XSOAR 5.5.0

None

all

 

ÏÂÔØÁ´½Ó£º

https://support.paloaltonetworks.com/support

 

»º½â´ëÊ©

È¡ÏûËùÓлµÄ¼¯³É API Key£¬´ÓCortex XSOAR web ¿Í»§¶ËµÄSettings > Integration > API Keys£¬È»ºóÈ¡Ïûÿ¸öAPI Key¡ £¿ÉÒÔ½«Cortex XSOARÉý¼¶µ½Àι̰汾ºó´´½¨ÐµÄAPI Key¡£

ÏÞÖÆ¶ÔCortex XSOAR·þÎñÆ÷µÄÍøÂç·ÃÎÊ£¬Ö»ÔÊÐíÊÜÐÅÈεÄÓû§·ÃÎÊ¡£

 

0x03 ²Î¿¼Á´½Ó

https://security.paloaltonetworks.com/CVE-2021-3044

https://security.paloaltonetworks.com/

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3044

 

0x04 ʱ¼äÏß

2021-06-22  Palo Alto NetworksÐû²¼Äþ¾²Í¨¸æ

2021-06-23  VSRCÐû²¼Äþ¾²Í¨¸æ

 

0x05 ¸½Â¼

CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/

image.png