¡¾Â©¶´Í¨¸æ¡¿Cisco ASA & FTD¾Ü¾ø·þÎñ©¶´£¨CVE-2024-20353£©
Ðû²¼Ê±¼ä 2024-04-25Ò»¡¢Â©¶´¸ÅÊö
©¶´Ãû³Æ | Cisco ASA & FTD¾Ü¾ø·þÎñ©¶´ | ||
CVE ID | CVE-2024-20353 | ||
©¶´ÀàÐÍ | Dos | ·¢ÏÖʱ¼ä | 2024-04-25 |
©¶´ÆÀ·Ö | 8.6 | ©¶´Æ·¼¶ | ¸ßΣ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | ÎÞ |
ÀûÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ÎÞ |
PoC/EXP | δ֪ | ÔÚÒ°ÀûÓà | ÒÑ·¢ÏÖ |
Cisco Adaptive Security Appliance£¨ASA£©ÊÇCisco Systems ÌṩµÄһϵÁм¯³ÉÄþ¾²½â¾ö·½°¸£¬²úÎïÏß°üÂÞ·ÓÉÆ÷¡¢·þÎñÆ÷¡¢·À»ðǽ¡¢VPN Íø¹ØºÍ IDS/IPS É豸¡£Cisco Firepower Threat Defense£¨FTD£©ÊÇÒ»¸öͳһµÄÄþ¾²½â¾ö·½°¸£¬ÌṩÕë¶ÔÅÓ´óÍþвµÄÈ«Ãæ±£»¤¡£
2024Äê4ÔÂ25ÈÕ£¬¶«Éƽ̨VSRC¼à²âµ½CiscoÐû²¼Õë¶ÔÆä·À»ðǽƽ̨µÄ¹¥»÷ʼþÏìӦͨ¸æ£¬ÍþвÕßͨ¹ýÀûÓÃCisco ASA ºÍ FTDÈí¼þÖеĶà¸ö©¶´½øÐй¥»÷£¬ÒÔÖ²Èë¶ñÒâÈí¼þ¡¢Ö´ÐÐÃüÁî¡¢²¢¿ÉÄÜ´ÓÊÜѬȾµÄÉ豸ÖÐÇÔÈ¡Êý¾Ý¡£
CVE-2024-20353£ºCisco ASA & FTD¾Ü¾ø·þÎñ©¶´£¨¸ßΣ£©
Cisco ASA ºÍ FTDÈí¼þµÄ¹ÜÀíºÍVPN Web·þÎñÆ÷ÖдæÔھܾø·þÎñ©¶´£¬ÓÉÓÚ½âÎöHTTP±êͷʱ´íÎó¼ì²é²»ÍêÕû£¬Î´¾Éí·ÝÑéÖ¤µÄÔ¶³ÌÍþвÕß¿ÉÒÔͨ¹ýÏòÄ¿±êweb·þÎñÆ÷·¢ËͶñÒâµÄHTTPÇëÇóÀ´ÀûÓø鶴£¬ÀÖ³ÉÀûÓÿÉÄܵ¼ÖÂÉ豸ÖØмÓÔØ£¬´Ó¶øµ¼Ö¾ܾø·þÎñ¡£¸Ã©¶´µÄCVSSÆÀ·ÖΪ8.6£¬Ä¿Ç°ÒÑ·¢ÏÖ±»ÀûÓá£
CVE-2024-20359£ºCisco ASA & FTD´úÂëÖ´ÐЩ¶´£¨¸ßΣ£©
Cisco ASA ºÍ FTDµÄijЩ¹¦Ð§ÖдæÔÚ©¶´£¬ÓÉÓÚ´ÓϵͳÉÁ´æ¶ÁÈ¡Îļþʱ¶ÔÎļþÑéÖ¤²»Í×£¬¾¹ýÉí·ÝÑéÖ¤ÇÒ¾ßÓйÜÀíԱȨÏ޵ĵ±µØÍþвÕß¿ÉÒÔͨ¹ý½«¶ñÒâÉè¼ÆµÄÎļþ¸´ÖƵ½ÊÜÓ°ÏìÉ豸µÄdisk0:ÎļþϵͳÀ´ÀûÓø鶴£¬ÀÖ³ÉÀûÓÿÉÄܵ¼ÖÂÍþвÕßÔÚÏ´ÎÖØмÓÔØÉ豸ºóÔÚÊÜÓ°ÏìµÄÉ豸ÉÏÖ´ÐÐÈÎÒâ´úÂ룬ÇÒ×¢ÈëµÄ´úÂë¿ÉÄÜ»áÔÚÉ豸ÖØÐÂÆô¶¯ºóÁ¬Ðø´æÔÚ£¬´Ó¶øµ¼Ö³־õ±µØ´úÂëÖ´ÐС£¸Ã©¶´µÄCVSSÆÀ·ÖΪ6.0£¬Ä¿Ç°ÒÑ·¢ÏÖ±»ÀûÓá£
CVE-2024-20358£ºCisco ASA & FTDÃüÁî×¢È멶´£¨ÖÐΣ£©
Cisco ASA ºÍFTDÖÐµÄ Cisco ASA»Ö¸´¹¦Ð§´æÔÚ©¶´£¬ÓÉÓÚ±¸·ÝÎļþµÄÄÚÈÝÔÚ»Ö¸´Ê±Î´ÕýÈ·ÇåÀí£¬¾¹ýÉí·ÝÑéÖ¤ÇÒ¾ßÓйÜÀíԱȨÏ޵ĵ±µØÍþвÕß¿ÉÒÔͨ¹ý½«¶ñÒâÉè¼ÆµÄ±¸·ÝÎļþ»Ö¸´µ½ÊÜÓ°ÏìµÄÉ豸À´ÀûÓø鶴£¬ÀÖ³ÉÀûÓÿÉÄܵ¼ÖÂÒÔrootȨÏÞÔڵײãϵͳÉÏÖ´ÐÐÈÎÒâÃüÁî¡£
¶þ¡¢Ó°Ï췶Χ
Ϊ×ÊÖú¿Í»§È·¶¨Æä Cisco ASA¡¢FMC ºÍ FTD Èí¼þÖÐÊÇ·ñ´æÔÚ©¶´£¬Ë¼¿ÆÌṩÁË˼¿ÆÈí¼þ¼ì²éÆ÷¹¤¾ß£¬Óû§¿ÉʹÓøù¤¾ßÅжϵ±Ç°É豸µÄÈí¼þ°æ±¾ÊÇ·ñÊÜÕâЩ©¶´Ó°Ï죬²¢¸üе½²»ÊÜÓ°Ïì°æ±¾¡£ÒªÊ¹Óøù¤¾ß£¬ÇëתÖÁCisco Software CheckerÒ³Ã沢ƾ¾Ý˵Ã÷½øÐвÙ×÷£ºhttps://sec.cloudapps.cisco.com/security/center/softwarechecker.x
Èý¡¢Äþ¾²´ëÊ©
3.1 Éý¼¶°æ±¾
Ä¿Ç°ÕâЩ©¶´ÒѾÐÞ¸´£¬ÊÜÓ°ÏìÓû§¿ÉʹÓùٷ½ÌṩµÄ¹¤¾ß»ò´ëÊ©½øÐÐÅŲ飬²¢Éý¼¶µ½²»ÊÜÓ°Ïì»ò×îеĹ̼þ°æ±¾£¬»ò¹Ø±ÕÉ豸Ò×Êܹ¥»÷µÄÅäÖú͹¦Ð§ÒÔ»º½â¸Ã©¶´¡£
²Î¿¼Á´½Ó£º
https://sec.cloudapps.cisco.com/security/center/resources/asa_ftd_attacks_event_response?
3.2 ÁÙʱ´ëÊ©
Õë¶ÔCVE-2024-20353£¬¿É²Î¿¼ÒÔÏ´ëÊ©½øÐÐÊÖ¶¯ÅŲ飺
È·¶¨ASA»òFTDÉ豸ÊÇ·ñÊܵ½Ó°Ïì
Ҫȷ¶¨ÔËÐÐCisco ASAÈí¼þ»òFTDÈí¼þµÄÉ豸ÊÇ·ñÊܵ½Ó°Ï죬ÇëʹÓÃshow asp table socket | include SSLÃüÁîÔÚÈκÎTCP ¶Ë¿ÚÉϲéÕÒ SSL ÕìÌýÌ×½Ó×Ö¡£Èç¹ûÊä³öÖзºÆðsocket£¬ÔòÓ¦ÈÏΪ¸ÃÉ豸´æÔÚ©¶´¡£Cisco ASA É豸ʾÀýÈçÏ£º
ciscoasa# show asp table socket | include SSL
SSL 00185038 LISTEN 172.16.0.250:443 0.0.0.0:*
SSL 00188638 LISTEN 10.0.0.250:8443 0.0.0.0:*
Èç¹û Cisco ASA Èí¼þºÍ FTD Èí¼þ¾ßÓÐÒÔÏÂÁ½¸ö±íÖÐÁгöµÄÒ»Ïî»ò¶àÏîÒ×Êܹ¥»÷µÄÅäÖã¬Ôò´Ë©¶´»áÓ°ÏìËüÃÇ¡£ÕâЩ¹¦Ð§¿ÉÄܻᵼÖÂÆôÓÃSSLÕìÌýÌ×½Ó×Ö¡£
ASA Èí¼þÒ×Êܹ¥»÷µÄÅäÖÃ
Ò×Êܹ¥»÷µÄ˼¿ÆASAÈí¼þ¹¦Ð§ | ¿ÉÄÜ´æÔÚ©¶´µÄÅäÖã¨show running-config CLIÃüÁîÖеÄÅäÖã© |
AnyConnect IKEv2 Ô¶³Ì·ÃÎÊ£¨Ê¹Óÿͻ§¶Ë·þÎñ£© | crypto ikev2 enable [...] client-services port |
µ±µØÖ¤Êé·¢±í»ú¹¹ (CA) | crypto ca server no shutdown |
¹ÜÀí Web ·þÎñÆ÷·ÃÎÊ£¨°üÂÞ ASDM ºÍ CSM£© | http server enable http |
Mobile User Security (MUS) | webvpn mus password mus server enable port mus |
REST API | rest-api image disk0:/rest-api agent |
SSL VPN | webvpn enable |
FTD Èí¼þÒ×Êܹ¥»÷µÄÅäÖÃ
Ò×Êܹ¥»÷µÄ˼¿ÆFTDÈí¼þ¹¦Ð§ | ¿ÉÄÜ´æÔÚ©¶´µÄÅäÖã¨show running-config CLIÃüÁîÖеÄÅäÖã© |
AnyConnect IKEv2 Ô¶³Ì·ÃÎÊ£¨Ê¹Óÿͻ§¶Ë·þÎñ£© | crypto ikev2 enable [...] client-services port |
AnyConnect SSL VPN | webvpn enable |
HTTP server enabled | http server enable http |
3.3 ͨÓý¨Òé
l ¶¨ÆÚ¸üÐÂϵͳ²¹¶¡£¬¼õÉÙϵͳ©¶´£¬ÌáÉý·þÎñÆ÷µÄÄþ¾²ÐÔ¡£
l ¼ÓǿϵͳºÍÍøÂçµÄ·ÃÎÊ¿ØÖÆ£¬Ð޸ķÀ»ðǽ¼Æı£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻò·þÎñ£¬¼õÉÙ½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬¼õÉÙ¹¥»÷Ãæ¡£
l ʹÓÃÆóÒµ¼¶Äþ¾²²úÎÌáÉýÆóÒµµÄÍøÂçÄþ¾²ÐÔÄÜ¡£
l ¼ÓǿϵͳÓû§ºÍȨÏÞ¹ÜÀí£¬ÆôÓöàÒòËØÈÏÖ¤»úÖƺÍ×îСȨÏÞÔÔò£¬Óû§ºÍÈí¼þȨÏÞÓ¦±£³ÖÔÚ×îµÍÏ޶ȡ£
l ÆôÓÃÇ¿ÃÜÂë¼Æı²¢ÉèÖÃΪ¶¨ÆÚÐ޸ġ£
3.4 ²Î¿¼Á´½Ó
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-websrvs-dos-X8gNucD2
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-persist-rce-FLsNXF4h#fs
https://blog.talosintelligence.com/arcanedoor-new-espionage-focused-campaign-found-targeting-perimeter-network-devices/
ËÄ¡¢°æ±¾ÐÅÏ¢
°æ±¾ | ÈÕÆÚ | ±¸×¢ |
V1.0 | 2024-04-25 | Ê×´ÎÐû²¼ |
Îå¡¢¸½Â¼
5.1 ¶«Éƽ̨¼ò½é
¶«Éƽ̨½¨Á¢ÓÚ1996Ä꣬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ´´½¨µÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢Äþ¾²¸ß¿Æ¼¼ÆóÒµ¡£ÊǹúÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Äþ¾²²úÎï¡¢Äþ¾²·þÎñ½â¾ö·½°¸µÄÁ캽ÆóÒµÖ®Ò»¡£
¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°¶«Éƽ̨´óÏ㬹«Ë¾Ô±¹¤6000ÓàÈË£¬Ñз¢ÍŶÓ1200ÓàÈË, ¼¼Êõ·þÎñÍŶÓ1300ÓàÈË¡£ÔÚÈ«¹ú¸÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬ÓµÓÐÁýÕÖÈ«¹úµÄÏúÊÛÌåϵ¡¢ÇþµÀÌåϵºÍ¼¼ÊõÖ§³ÖÌåϵ¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐС°å¹ÒÅÆÉÏÊС££¨¹ÉƱ´úÂ룺002439£©
¶àÄêÀ´£¬¶«Éƽ̨ÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷´´ÐµÄÄþ¾²²úÎïºÍ×î¼Ñʵ¼ù·þÎñ£¬×ÊÖú¿Í»§È«ÃæÌáÉýÆäIT»ù´¡ÉèÊ©µÄÄþ¾²ÐÔºÍÉú²úЧÄÜ£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Äþ¾²¹¤ÒµÁì¾üÆ·Åƶø²»Ð¸Å¬Á¦¡£
5.2 ¹ØÓÚ¶«Éƽ̨
¶«Éƽ̨Äþ¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÒÑÐû²¼1000¶à¸ö©¶´Í¨¸æºÍ·çÏÕÔ¤¾¯£¬ÎÒÃǽ«Á¬Ðø¸ú×ÙÈ«Çò×îеÄÍøÂçÄþ¾²Ê¼þºÍ©¶´£¬ÎªÆóÒµµÄÐÅÏ¢Äþ¾²±£¼Ý»¤º½¡£
¹Ø×¢ÎÒÃÇ£º