Citrix²úÆ·¶à¸öÇå¾²Îó²îͨ¸æ

Ðû²¼Ê±¼ä 2020-07-09

0x00 Îó²î¸ÅÊö


2020Äê7ÔÂ7ÈÕ£¬£¬Citrix¹Ù·½Ðû²¼Ç徲ͨ¸æ£¬£¬ÔÚCitrix ADC¡¢CitrixÍø¹ØºÍCitrix SD-WAN WANOP 4000-WO¡¢4100-WO¡¢5000-WOºÍ5100-WO°æ±¾Öз¢Ã÷Á˶à¸öÎó²î¡£¡£¡£¡£¡£ ¡£ÏêÇé¼ûÏÂ±í£º

CVE ID

Îó²îÀàÐÍ

Ó°Ïì²úÆ·

¹¥»÷ÕßȨÏÞ

Ìõ¼þÌõ¼þ

CVE-2019-18177

ID

Citrix ADC, Citrix Gateway 

¾­Éí·ÝÈÏÖ¤µÄVPNÓû§

ÐèÒªÒ»¸öÉèÖõÄSSL VPNÖÕ¶Ë

CVE-2020-8187

DOS

Citrix ADC, Citrix Gateway 12.0 and 11.1°æ±¾

δ¾­Éí·ÝÈÏÖ¤µÄÔ¶³ÌÓû§

ÐèÒªÒ»¸öÉèÖõÄSSL VPN»òAAAÖÕ¶Ë

CVE-2020-8190

EOP

Citrix ADC, Citrix Gateway 

λÓÚNSIPÉϾ­Éí·ÝÈÏÖ¤µÄÓû§

¸ÃÎó²îÎÞ·¨Ö±½Ó±»Ê¹Óᣡ£¡£¡£¡£ ¡£¹¥»÷Õß±ØÐèÊ×ÏÈʹÓÃÁíÒ»¸öÎó²î»ñÈ¡nobodyÕË»§È¨ÏÞ

CVE-2020-8191

XSS

Citrix ADC, Citrix Gateway, Citrix SDWAN WAN-OP 

δ¾­Éí·ÝÈÏÖ¤µÄÔ¶³ÌÓû§

ÐèÒªÊܺ¦ÕßÔÚä¯ÀÀÆ÷Öз­¿ªÓɹ¥»÷Õß¿ØÖƵÄÁ´½Ó£¬£¬Í¬Ê±´¦ÓÚÅþÁ¬NSIPµÄÍøÂçÉÏ

CVE-2020-8193

AB

Citrix ADC, Citrix Gateway, Citrix SDWAN WAN-OP 

¾ßÓÐNSIP»á¼ûȨÏ޵쬣¬Î´¾­Éí·ÝÈÏÖ¤µÄÓû§

¹¥»÷Õß±ØÐèÄܹ»»á¼û¸ÃNSIP

CVE-2020-8194

CI

Citrix ADC, Citrix Gateway, Citrix SDWAN WAN-OP 

δ¾­Éí·ÝÈÏÖ¤µÄÔ¶³ÌÓû§

ÐèÒªÊܺ¦Õß´Ó¸ÃNSIPÏÂÔØ²¢Ö´ÐжñÒâ¶þ½øÖÆÎļþ

CVE-2020-8195

ID

Citrix ADC, Citrix Gateway, Citrix SDWAN WAN-OP 

λÓÚNSIPÉϾ­Éí·ÝÈÏÖ¤µÄÓû§

CVE-2020-8196

ID

Citrix ADC, Citrix Gateway, Citrix SDWAN WAN-OP 

λÓÚNSIPÉϾ­Éí·ÝÈÏÖ¤µÄÓû§

CVE-2020-8197

EOP

Citrix ADC, Citrix Gateway 

λÓÚNSIPÉϾ­Éí·ÝÈÏÖ¤µÄÓû§

CVE-2020-8198

XSS

Citrix ADC, Citrix Gateway,Citrix SDWAN WAN-OP 

δ¾­Éí·ÝÈÏÖ¤µÄÔ¶³Ì¹¥»÷Õß

ÐèÒªÊܺ¦Õß±ØÐèÔÚNSIPÉÏÒÔÖÎÀíÔ±£¨nsroot£©Éí·ÝµÇ¼

CVE-2020-8199

EOP

Citrix Gateway Plug-in for Linux 

λÓÚLinuxÅÌËã»úÉÏÔËÐÐCitrix Gateway  Plug-inµÄÍâµØÓû§

±ØÐèÔËÐÐCitrix Gateway Plug-in for LinuxԤװ°æ±¾

´Ó±íÖпÉÒÔ¿´³ö£¬£¬¹¥»÷»¹ÐèҪijÖÖÐÎʽµÄ»á¼ûȨÏ޲ŻªÊ¹ÓÃÕâЩÎó²î£¬£¬ÕâÒâζ׏¥»÷ÕßÊ×ÏÈÐèÒª»á¼ûÄ¿µÄϵͳ²Å»ª¾ÙÐй¥»÷¡£¡£¡£¡£¡£ ¡£


0x01 Îó²îÏêÇé



ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


Citrix²úÆ·Ö÷ÒªÓÃÓÚÓ¦ÓóÌÐòµÄÁ÷Á¿ÖÎÀíºÍʵÏÖÇå¾²µÄÔ¶³Ì»á¼û£¬£¬²¢ÖÁÉÙÒÑÔÚ158¸ö¹ú¼ÒµÄ80000¼Ò¹«Ë¾ÖÐ×°Öᣡ£¡£¡£¡£ ¡£

ÈôÊÇÕâЩÎó²îÔ⵽ʹÓ㬣¬¿ÉÄܻᵼÖÂÐí¶àÇå¾²ÎÊÌ⣬£¬°üÀ¨±»ÓÃÓÚ»ñÊØÐÅÏ¢¡¢·¢¶¯ DoS ¹¥»÷¡¢ÊµÏÖÍâµØÌáȨ¡¢·¢¶¯ XSS ¹¥»÷ºÍÈÆ¹ýÈÏÖ¤²¢×¢Èë¶ñÒâ´úÂë¡£¡£¡£¡£¡£ ¡£

±ðµÄ£¬£¬ÔÚÓÃÓÚLinuxµÄCitrix Gateway²å¼þÖз¢Ã÷ÁËÒ»¸öÎó²î£¬£¬×°ÖÃÁ˸òå¼þµÄLinuxϵͳµÄÓû§¿ÉÒÔʹÓøÃÎó²î¾ÙÐÐÍâµØÌáȨ¡£¡£¡£¡£¡£ ¡£

ƾ֤CitrixÐû²¼µÄÐÅÏ¢£¬£¬ÕâЩÎó²îÓë¸Ã¹«Ë¾ÔÚ2020Äê1ÔÂÐÞ¸´µÄCVE-2019-19781Ô¶³Ì´úÂëÖ´ÐÐÎó²îÎ޹أ¬£¬²»Ó°ÏìCitrix×°±¸µÄÔÆ°æ±¾¡£¡£¡£¡£¡£ ¡£µ½ÏÖÔÚΪֹ»¹Ã»Óз¢Ã÷¶ÔÕâЩÎó²îµÄʹÓ㬣¬½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ìÉý¼¶¡£¡£¡£¡£¡£ ¡£


0x02 ´¦Öóͷ£½¨Òé


ÏÖÔÚ³§ÉÌÒÑÐû²¼²¹¶¡£¬£¬ÏÂÁа汾µÄCitrix ADC¡¢CitrixÍø¹ØºÍCitrix SD-WAN WANOPÐÞ¸´ÁËÎó²î£º?

Citrix ADC and Citrix Gateway >= 13.0-58.30°æ±¾

Citrix ADC and NetScaler Gateway > 12.1°æ±¾£¬£¬12.1-57.18°æ±¾

Citrix ADC and NetScaler Gateway > ?12.0°æ±¾£¬£¬12.0-63.21°æ±¾

Citrix ADC and NetScaler Gateway > 11.1°æ±¾£¬£¬11.1-64.14°æ±¾

NetScaler ADC and NetScaler Gateway > 10.5°æ±¾£¬£¬10.5-70.18°æ±¾

Citrix SD-WAN WANOP >= 11.1.1a°æ±¾

Citrix SD-WAN WANOP > 11.0°æ±¾£¬£¬11.0.3d°æ±¾

Citrix SD-WAN WANOP > 10.2°æ±¾£¬£¬10.2.7°æ±¾

Citrix Gateway Plug-in for Linux >= ?1.0.0.137°æ±¾

½¨ÒéÊÜÓ°ÏìµÄ¿Í»§ÊµÊ±¸üУ¬£¬ÏÂÔØÁ´½Ó£º

https://www.citrix.com/downloads/citrix-adc/

https://www.citrix.com/downloads/citrix-gateway/

https://www.citrix.com/downloads/citrix-sd-wan/

ÔÝʱ²½·¥£º

µ±Citrix ADC×°±¸°²Åŵ½Éú²úÇéÐÎʱ£¬£¬Citrix ½¨Òé¾ÙÐÐÒÔÏÂÉèÖøü¸Ä£º

? եȡCitrix ADC ÖÎÀíÔ±½Ó¿Ú(NSIP)»á¼ûInternet£»£»

? Ìæ»» Citrix ADC ĬÈÏSSLÖ¤Ê飻£»

? ʹÓÃHTTPS»á¼û GUI¡£¡£¡£¡£¡£ ¡£

¸ü¶àÏêϸÐÅÏ¢£¬£¬Çë²Î¿¼ÒÔÏÂÁ´½Ó£ºhttps://docs.citrix.com/zh-cn/citrix-adc/citrix-adc-secure-deployment/secure-deployment-guide.html


0x03 Ïà¹ØÐÂÎÅ


https://threatpost.com/citrix-bugs-allow-unauthenticated-code-injection-data-theft/157214/


0x04 ²Î¿¼Á´½Ó


https://support.citrix.com/article/CTX276688


0x05 ʱ¼äÏß


2020-07-07 Citrix¹Ù·½Ðû²¼Ç徲ͨ¸æ

2020-07-09 VSRCÐû²¼Îó²îͨ¸æ


ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø