Citrix所有产品保存代码执行误差危害通告
宣布时间 2020-01-09误差编号和级别
CVE编号:CVE-2019-19781,危险级别:严重,CVSS分值:9.8
影响版本
Citrix ADC and Citrix Gateway version 13.0 all supported builds
Citrix ADC and NetScaler Gateway version 12.1 all supported builds
Citrix ADC and NetScaler Gateway version 12.0 all supported builds
Citrix ADC and NetScaler Gateway version 11.1 all supported builds
Citrix NetScaler ADC and NetScaler Gateway version 10.5 all supported builds
误差概述
Citrix Systems Citrix ADC and NetScaler Gateway等都是美国思杰系统(Citrix Systems)公司的产品。Citrix ADC and NetScaler Gateway是一款应用交付控制器。该产品具有应用交付控制和负载平衡等功效。
清静专家在Citrix Application Delivery Controller和Citrix Gateway产品中发明一个严重的代码执行误差,该误差使158个国家的凌驾8万家公司面临危害。由于使用该误差的攻击者无需身份验证即可会见公司的内部网络,因此该误差尤其危险。乐成使用该误差可导致恣意代码执行。
误差验证
POC:现在果真了部分POC,可在受影响的版本上通过未授权的GET请求执行目录遍历。
GET /vpn/../vpns/services.html
GET /vpn/../vpns/cfg/smb.conf
若是返回 HTTP/1.1 403 Forbidden 则已修复。
至于怎样造成远程代码执行,其只宣布了部分细节,现在并未发明果真的可以使用的POC。
修复建议
只管Citrix尚未宣布新固件来解决该问题,但该公司已宣布了一套针对自力系统和集群的缓解步伐,并强烈建议受影响的客户接纳它们:https://support.citrix.com/article/CTX267679。
参考链接
https://www.bleepingcomputer.com/news/security/critical-citrix-flaw-may-expose-thousands-of-firms-to-attacks/


京公网安备11010802024551号