¡¾Â©¶´Í¨¸æ¡¿Juniper Networks Junos OSÔ¶³Ì´úÂëÖ´ÐЩ¶´
Ðû²¼Ê±¼ä 2023-08-29
Ò»¡¢Â©¶´¸ÅÊö
CVE ID | ·¢ÏÖʱ¼ä | 2023-08-26 | |
Àà ÐÍ | ´úÂëÖ´ÐÐ | µÈ ¼¶ | ¸ßΣ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | ÎÞ |
¹¥»÷ÅÓ´ó¶È | µÍ | Óû§½»»¥ | ÎÞ |
PoC/EXP | ÒѹûÈ» | ÔÚÒ°ÀûÓà | δ֪ |
Juniper Networks£¨Õ°²©ÍøÂ磩ÊÇÈ«ÇòÁìÏȵÄÍøÂçºÍÄþ¾²½â¾ö·½°¸ÌṩÉÌ£¬Æä¿Í»§°üÂÞÈ«Çò·¶Î§ÄÚµÄÍøÂçÔËÓªÉÌ¡¢ÆóÒµ¡¢Õþ¸®»ú¹¹ÒÔ¼°Ñо¿ºÍ½ÌÓý»ú¹¹µÈ¡£
8ÔÂ29ÈÕ£¬¶«Éƽ̨VSRC¼à²âµ½Juniper NetworksÅû¶ÁËÆäSRX ·À»ðǽϵÁÐºÍ EX ½»»»»úϵÁÐÉϵÄJunos OS µÄ J-Web ×é¼þÖеĶà¸ö©¶´£¬Î´¾Éí·ÝÑéÖ¤µÄÍþвÕß¿É×éºÏÀûÓÃÕâЩ©ÔÚÊÜÓ°ÏìÉ豸ÉÏÔ¶³ÌÖ´ÐдúÂë¡£
CVE-2023-36844£ºJunos OS J-Web PHPÍⲿ±äÁ¿Ð޸ĩ¶´£¨ÖÐΣ£©
Juniper Networks EXϵÁÐÉϵÄJunos OS µÄ J-Web×é¼þÖдæÔÚPHPÍⲿ±äÁ¿Ð޸ĩ¶´£¬Î´¾Éí·ÝÑéÖ¤µÄÔ¶³ÌÍþвÕß¿ÉÀûÓöñÒâÇëÇóÐÞ¸ÄijЩ PHP »·¾³±äÁ¿£¬µ¼Ö²¿ÃÅÍêÕûÐÔ¶ªÊ§»ò¿ÉÄܵ¼Ö©¶´ÀûÓÃÁ´¡£
CVE-2023-36845£ºJunos OS J-Web PHPÍⲿ±äÁ¿Ð޸ĩ¶´£¨ÖÐΣ£©
Juniper Networks EX ϵÁÐºÍ SRX ϵÁÐÉϵÄJunos OS µÄ J-Web×é¼þÖдæÔÚPHPÍⲿ±äÁ¿Ð޸ĩ¶´£¬Î´¾Éí·ÝÑéÖ¤µÄÔ¶³ÌÍþвÕß¿ÉÀûÓöñÒâÇëÇóÐÞ¸Äij¸ö PHP »·¾³±äÁ¿£¬µ¼Ö²¿ÃÅÍêÕûÐÔ¶ªÊ§»ò¿ÉÄܵ¼Ö©¶´ÀûÓÃÁ´¡£
CVE-2023-36846£ºJunos OS SRX ϵÁÐÒªº¦¹¦Ð§Ñé֤ȱʧ©¶´£¨ÖÐΣ£©
Juniper Networks SRX ϵÁÐÉϵÄJunos OSÖдæÔÚÒªº¦¹¦Ð§Ñé֤ȱʧ©¶´£¬Î´¾Éí·ÝÑéÖ¤µÄÔ¶³ÌÍþвÕ߿ɷ¢ËÍÌØ¶¨ÇëÇóͨ¹ý J-Web ÉÏ´«ÈÎÒâÎļþ£¬´Ó¶øµ¼ÖÂÎļþÏµÍ³ÌØ¶¨²¿ÃŵÄÍêÕûÐÔ¶ªÊ§»ò¿ÉÄܵ¼Ö©¶´ÀûÓÃÁ´¡£
CVE-2023-36847£ºJunos OS EX ϵÁÐÒªº¦¹¦Ð§Ñé֤ȱʧ©¶´£¨ÖÐΣ£©
Juniper Networks EX ϵÁÐÉϵÄJunos OSÖдæÔÚÒªº¦¹¦Ð§Ñé֤ȱʧ©¶´£¬Î´¾Éí·ÝÑéÖ¤µÄÔ¶³ÌÍþвÕ߿ɷ¢ËÍÌØ¶¨ÇëÇóͨ¹ý J-Web ÉÏ´«ÈÎÒâÎļþ£¬´Ó¶øµ¼ÖÂÎļþÏµÍ³ÌØ¶¨²¿ÃŵÄÍêÕûÐÔ¶ªÊ§»ò¿ÉÄܵ¼Ö©¶´ÀûÓÃÁ´¡£
Ŀǰ£¬Ñо¿ÈËÔ±ÒѾÐû²¼ÁËÕë¶ÔSRX·À»ðǽ©¶´µÄPoC/EXP£¬Í¨¹ý×éºÏÀûÓÃÒªº¦¹¦Ð§Ñé֤ȱʧ©¶´£¨CVE-2023-36846£©ºÍPHPÍⲿ±äÁ¿Ð޸ĩ¶´£¨CVE-2023-36845£©¡£CVE-2023-36846©¶´¿ÉÔÚδÊÚȨÇé¿öÏÂÉÏ´«PHPÎļþºÍÅäÖÃÎļþ£¬ÔÙÀûÓÃCVE-2023-36845©¶´Ð޸Ļ·¾³±äÁ¿¼ÓÔØÅäÖÃÎļþ£¬´Ó¶ø´¥·¢Ö´ÐÐPHPÎļþ¡£
¶þ¡¢Ó°Ï췶Χ
Juniper Networks Junos OS£¨SRX ϵÁУ©£º
20.4R3-S8֮ǰµÄËùÓа汾£»
21.1°æ±¾21.1R1¼°ÒÔÉϰ汾£»
21.2R3-S6֮ǰµÄ21.2°æ±¾£»
21.3R3-S5֮ǰµÄ21.3°æ±¾£»
21.4R3-S5֮ǰµÄ21.4°æ±¾£»
22.1R3-S3֮ǰµÄ22.1°æ±¾£»
22.2R3-S2֮ǰµÄ22.2°æ±¾£»
22.3R2-S2¡¢22.3R3֮ǰµÄ22.3°æ±¾£»
22.4R2-S1¡¢22.4R3֮ǰµÄ22.4°æ±¾£»
Juniper Networks Junos OS£¨EX ϵÁУ©£º
20.4R3-S8֮ǰµÄËùÓа汾£»
21.1°æ±¾21.1R1¼°ÒÔÉϰ汾£»
21.2R3-S6֮ǰµÄ21.2°æ±¾£»
21.3R3-S5֮ǰµÄ21.3°æ±¾£»
21.4R3-S4֮ǰµÄ21.4°æ±¾£»
22.1R3-S3֮ǰµÄ22.1°æ±¾£»
22.2R3-S1֮ǰµÄ22.2°æ±¾£»
22.3R2-S2¡¢22.3R3֮ǰµÄ22.3°æ±¾£»
22.4R2-S1¡¢22.4R3 ֮ǰµÄ 22.4 °æ±¾¡£
Èý¡¢Äþ¾²´ëÊ©
3.1 Éý¼¶°æ±¾
ĿǰJuniper NetworksÒѾÐÞ¸´ÁËÕâЩ©¶´£¬ÊÜÓ°ÏìÓû§¿ÉÔÚ°æ±¾¸üпÉÓÃʱÉý¼¶µ½ÒÔÏÂJunos OS°æ±¾£º
¶ÔÓÚ EX ϵÁУº¿ÉÉý¼¶µ½20.4R3-S8¡¢21.2R3-S6¡¢21.3R3-S5*¡¢21.4R3-S4¡¢22.1R3-S3¡¢22.2R3-S1¡¢22.3R2-S2¡¢22.3R3¡¢22.4R2-S1¡¢22.4R3*¡¢23.2R1 ºÍËùÓкóÐøÐû²¼µÄ¸üа汾¡£
¶ÔÓÚ SRX ϵÁУº¿ÉÉý¼¶µ½ 20.4R3-S8¡¢21.2R3-S6¡¢21.3R3-S5*¡¢21.4R3-S5*¡¢22.1R3-S3¡¢22.2R3-S2*¡¢22.3R2-S2¡¢22.3R3¡¢22.4R2-S1¡¢22.4R3*¡¢23.2R1ºÍËùÓкóÐøÐû²¼µÄ¸üа汾¡£
ÏÂÔØÁ´½Ó£º
https://supportportal.juniper.net
3.2 ÁÙʱ´ëÊ©
½ûÓÃÊÜÓ°ÏìÉè±¹ØÁ¬ÄJ-Web£¬»òÏÞÖÆ½öÔÊÐíÊÜÐÅÈεÄÖ÷»ú½øÐзÃÎÊ¡£
3.3 ͨÓý¨Òé
l ¶¨ÆÚ¸üÐÂϵͳ²¹¶¡£¬¼õÉÙϵͳ©¶´£¬ÌáÉý·þÎñÆ÷µÄÄþ¾²ÐÔ¡£
l ¼ÓǿϵͳºÍÍøÂçµÄ·ÃÎÊ¿ØÖÆ£¬Ð޸ķÀ»ðǽ¼ÆÄ±£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻò·þÎñ£¬¼õÉÙ½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬¼õÉÙ¹¥»÷Ãæ¡£
l ʹÓÃÆóÒµ¼¶Äþ¾²²úÎÌáÉýÆóÒµµÄÍøÂçÄþ¾²ÐÔÄÜ¡£
l ¼ÓǿϵͳÓû§ºÍȨÏÞ¹ÜÀí£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔÔò£¬Óû§ºÍÈí¼þȨÏÞÓ¦±£³ÖÔÚ×îµÍÏÞ¶È¡£
l ÆôÓÃÇ¿ÃÜÂë¼ÆÄ±²¢ÉèÖÃΪ¶¨ÆÚÐ޸ġ£
3.4 ²Î¿¼Á´½Ó
https://supportportal.juniper.net/s/article/2023-08-Out-of-Cycle-Security-Bulletin-Junos-OS-SRX-Series-and-EX-Series-Multiple-vulnerabilities-in-J-Web-can-be-combined-to-allow-a-preAuth-Remote-Code-Execution
https://labs.watchtowr.com/cve-2023-36844-and-friends-rce-in-juniper-firewalls/
https://www.bleepingcomputer.com/news/security/exploit-released-for-juniper-firewall-bugs-allowing-rce-attacks/
ËÄ¡¢°æ±¾ÐÅÏ¢
°æ±¾ | ÈÕÆÚ | ±¸×¢ |
V1.0 | 2023-08-29 | Ê×´ÎÐû²¼ |
Îå¡¢¸½Â¼
5.1 ¶«Éƽ̨¼ò½é
¶«Éƽ̨½¨Á¢ÓÚ1996Ä꣬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ´´½¨µÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢Äþ¾²¸ß¿Æ¼¼ÆóÒµ¡£ÊǹúÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Äþ¾²²úÎï¡¢Äþ¾²·þÎñ½â¾ö·½°¸µÄÁ캽ÆóÒµÖ®Ò»¡£
¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°¶«Éƽ̨´óÏ㬹«Ë¾Ô±¹¤6000ÓàÈË£¬Ñз¢ÍŶÓ1200ÓàÈË, ¼¼Êõ·þÎñÍŶÓ1300ÓàÈË¡£ÔÚÈ«¹ú¸÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬ÓµÓÐÁýÕÖÈ«¹úµÄÏúÊÛÌåϵ¡¢ÇþµÀÌåϵºÍ¼¼ÊõÖ§³ÖÌåϵ¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐС°å¹ÒÅÆÉÏÊС££¨¹ÉƱ´úÂ룺002439£©
¶àÄêÀ´£¬¶«Éƽ̨ÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷´´ÐµÄÄþ¾²²úÎïºÍ×î¼Ñʵ¼ù·þÎñ£¬×ÊÖú¿Í»§È«ÃæÌáÉýÆäIT»ù´¡ÉèÊ©µÄÄþ¾²ÐÔºÍÉú²úЧÄÜ£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Äþ¾²¹¤ÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸Å¬Á¦¡£
5.2 ¹ØÓÚ¶«Éƽ̨
¶«Éƽ̨Äþ¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÒÑÐû²¼1000¶à¸ö©¶´Í¨¸æºÍ·çÏÕÔ¤¾¯£¬ÎÒÃǽ«Á¬Ðø¸ú×ÙÈ«Çò×îеÄÍøÂçÄþ¾²Ê¼þºÍ©¶´£¬ÎªÆóÒµµÄÐÅÏ¢Äþ¾²±£¼Ý»¤º½¡£
¹Ø×¢ÎÒÃÇ£º