¡¾Îó²îͨ¸æ¡¿Citrix NetScaler ADC & GatewayÐÅϢй¶Îó²î£¨CVE-2023-4966£©
Ðû²¼Ê±¼ä 2023-10-24Ò»¡¢Îó²î¸ÅÊö
CVE ID | CVE-2023-4966 | ·¢Ã÷ʱ¼ä | 2023-10-13 |
Àà ÐÍ | ÐÅϢй¶ | µÈ ¼¶ | ¸ßΣ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | ÎÞ |
¹¥»÷ÖØƯºó | µÍ | Óû§½»»¥ | ÎÞ |
PoC/EXP | δ¹ûÕæ | ÔÚҰʹÓà | ÒÑ·¢Ã÷ |
NetScaler ADCºÍNetScaler Gateway£¨ÒÔÇ°³ÆΪCitrix ADCºÍCitrix Gateway£©¶¼ÊÇÃÀ¹ú˼½Ü£¨Citrix£©¹«Ë¾µÄ²úÆ·¡£Citrix GatewayÊÇÒ»Ì×Çå¾²µÄÔ¶³Ì½ÓÈë½â¾ö¼Æ»®£¬¿ÉÌṩӦÓü¶ºÍÊý¾Ý¼¶¹Ü¿Ø¹¦Ð§£¬ÒÔʵÏÖÓû§´ÓÈκÎËùÔÚÔ¶³Ì»á¼ûÓ¦ÓúÍÊý¾Ý£»Citrix ADCÊÇÒ»¸öÖÜÈ«µÄÓ¦ÓóÌÐò½»¸¶ºÍ¸ºÔØƽºâ½â¾ö¼Æ»®£¬ÓÃÓÚʵÏÖÓ¦ÓóÌÐòÇå¾²ÐÔ¡¢ÕûÌå¿É¼ûÐԺͿÉÓÃÐÔ¡£
10ÔÂ13ÈÕ£¬ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍøVSRC¼à²âµ½NetScaler ADCºÍNetScaler GatewayÖÐÐÞ¸´ÁËÒ»¸öÐÅϢй¶Îó²î£¨CVE-2023-4966£©£¬ÆäCVSSv3ÆÀ·ÖΪ9.4¡£µ±×°±¸ÉèÖÃΪÍø¹Ø£¨VPN ÐéÄâ·þÎñÆ÷¡¢ICA ÊðÀí¡¢CVPN¡¢RDP ÊðÀí£©»ò AAA ÐéÄâ·þÎñÆ÷ʱ£¬ÈÝÒ×Êܵ½»º³åÇøÒç³öÎó²îµÄÓ°Ï죬¿ÉÔÚδ¾Éí·ÝÑéÖ¤µÄÇéÐÎÏÂÔ¶³ÌʹÓøÃÎó²î»ñÈ¡Ãô¸ÐÐÅÏ¢¡£ÏÖÔÚ¸ÃÎó²îÒÑ·¢Ã÷±»Ê¹ÓÃÀ´ÇÔÈ¡Éí·ÝÑéÖ¤»á»°ºÍЮÖÆÕÊ»§£¬ÒÔÈƹý¶àÒòËØÉí·ÝÑéÖ¤»òÆäËûÇ¿Éí·ÝÑéÖ¤ÒªÇó¡£
±ðµÄ£¬NetScaler ADCºÍNetScaler GatewayÖл¹ÐÞ¸´ÁËÁíÒ»¸ö¾Ü¾ø·þÎñÎó²î£¨CVE-2023-4967£©£¬¸ÃÎó²îµÄCVSSv3ÆÀ·ÖΪ8.2£¬µ±ÊÜÓ°Ïì×°±¸ÉèÖÃΪÍø¹Ø£¨VPN ÐéÄâ·þÎñÆ÷¡¢ICA ÊðÀí¡¢CVPN¡¢RDP ÊðÀí£©»ò AAA ÐéÄâ·þÎñÆ÷£¬¿ÉÔÚδ¾Éí·ÝÑéÖ¤µÄÇéÐÎÏÂÔ¶³ÌʹÓøÃÎó²îµ¼Ö¾ܾø·þÎñ¡£
¶þ¡¢Ó°Ïì¹æÄ£
ÒÔÏÂÊÜÖ§³ÖµÄ NetScaler ADC ºÍ NetScaler Gateway °æ±¾£º
NetScaler ADC ºÍ NetScaler Gateway 14.1 < 14.1-8.50
NetScaler ADC ºÍ NetScaler Gateway 13.1 < 13.1-49.15
NetScaler ADC ºÍ NetScaler Gateway 13.0 < 13.0-92.19
NetScaler ADC 13.1-FIPS < 13.1-37.164
NetScaler ADC 12.1-FIPS < 12.1-55.300
NetScaler ADC 12.1-NDcPP < 12.1-55.300
×¢£ºNetScaler ADC ºÍ NetScaler Gateway °æ±¾12.1Ò²Ò×ÊÜÓ°Ï죬µ«¸Ã°æ±¾ÏÖÒÑ×èÖ¹Ö§³Ö¡£
Èý¡¢Çå¾²²½·¥
3.1 Éý¼¶°æ±¾
ÏÖÔÚÕâЩÎó²îÒѾÐÞ¸´£¬ÊÜÓ°ÏìÓû§¿ÉÉý¼¶µ½ÒÔÏ°汾£º
NetScaler ADC ºÍ NetScaler Gateway >= 14.1-8.50
NetScaler ADC ºÍ NetScaler Gateway 13.1 >= 13.1-49.15
NetScaler ADC ºÍ NetScaler Gateway 13.0 >= 13.0-92.19
NetScaler ADC 13.1-FIPS >= 13.1-37.164
NetScaler ADC 12.1-FIPS >= 12.1-55.300
NetScaler ADC 12.1-NDcPP >= 12.1-55.300
ÏÂÔØÁ´½Ó£º
https://www.citrix.com/downloads/
3.2 ÔÝʱ²½·¥
ÈôÊÇÕýÔÚʹÓÃÊÜÓ°ÏìµÄ°æ±¾²¢½«×°±¸ÉèÖÃΪÍø¹Ø£¨VPN ÐéÄâ·þÎñÆ÷¡¢ICA ÊðÀí¡¢CVPN¡¢RDP ÊðÀí£©»ò AAA ÐéÄâ·þÎñÆ÷£¬½¨ÒéÁ¬Ã¦Éý¼¶µ½ÐÞ¸´°æ±¾¡£ÈôÊÇÎÞ·¨È·¶¨ÊÇ·ñÒѱ»Ê¹Óã¨×ÝÈ»ÔÚ×°ÖÃÇå¾²¸üк󣬱»Ð®ÖƵĻỰÈÔÈ»±£´æ£©£¬Ò²¿ÉʹÓÃÒÔÏÂÏÂÁîÖÕÖ¹ËùÓÐÔ˶¯ºÍ³¤ÆڻỰ£º
kill icaconnection -all
kill rdp connection -all
kill pcoipConnection -all
kill aaa session -all
clear lb persistentSessions
δÉèÖÃΪÍø¹Ø£¨VPN ÐéÄâ·þÎñÆ÷¡¢ICA ÊðÀí¡¢CVPN »ò RDP ÊðÀí£©»ò AAA ÐéÄâ·þÎñÆ÷µÄ NetScaler ADC ºÍNetScaler Gateway×°±¸ÒÔ¼° NetScalerÓ¦ÓóÌÐò½»¸¶ÖÎÀí£¨ADM£©¡¢Citrix SD-WANµÈ²úÆ·²»ÊÜÓ°Ïì¡£
3.3 ͨÓý¨Òé
l °´ÆÚ¸üÐÂϵͳ²¹¶¡£¬ïÔÌϵͳÎó²î£¬ÌáÉý·þÎñÆ÷µÄÇå¾²ÐÔ¡£
l ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬Ð޸ķÀ»ðǽսÂÔ£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻò·þÎñ£¬ïÔ̽«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬ïÔ̹¥»÷Ãæ¡£
l ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£
l ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬ÆôÓöàÒòËØÈÏÖ¤»úÖƺÍ×îСȨÏÞÔÔò£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏ޶ȡ£
l ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£
3.4 ²Î¿¼Á´½Ó
https://support.citrix.com/article/CTX579459/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve20234966-and-cve20234967
https://www.netscaler.com/blog/news/cve-2023-4966-critical-security-update-now-available-for-netscaler-adc-and-netscaler-gateway/
https://www.mandiant.com/resources/blog/remediation-netscaler-adc-gateway-cve-2023-4966
ËÄ¡¢°æ±¾ÐÅÏ¢
°æ±¾ | ÈÕÆÚ | ±¸×¢ |
V1.0 | 2023-10-24 | Ê×´ÎÐû²¼ |
Îå¡¢¸½Â¼
5.1 ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍø¼ò½é
ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍø½¨ÉèÓÚ1996Ä꣬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ½¨ÉèµÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢Çå¾²¸ß¿Æ¼¼ÆóÒµ¡£ÊǺ£ÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Çå¾²²úÆ·¡¢Çå¾²·þÎñ½â¾ö¼Æ»®µÄÁ캽ÆóÒµÖ®Ò»¡£
¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍø´óÏ㬹«Ë¾Ô±¹¤6000ÓàÈË£¬Ñз¢ÍŶÓ1200ÓàÈË, ÊÖÒÕ·þÎñÍŶÓ1300ÓàÈË¡£ÔÚÌìϸ÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬ÓµÓÐÁýÕÖÌìϵÄÏúÊÛϵͳ¡¢ÇþµÀϵͳºÍÊÖÒÕÖ§³Öϵͳ¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐС°å¹ÒÅÆÉÏÊС££¨¹ÉƱ´úÂ룺002439£©
¶àÄêÀ´£¬ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍøÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷Á¢ÒìµÄÇå¾²²úÆ·ºÍ×î¼Ñʵ¼ù·þÎñ£¬×ÊÖú¿Í»§ÖÜÈ«ÌáÉýÆäIT»ù´¡ÉèÊ©µÄÇå¾²ÐÔºÍÉú²úЧÄÜ£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Çå¾²¹¤ÒµÁì¾üÆ·Åƶø²»Ð¸Æ𾢡£
5.2 ¹ØÓÚÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍø
ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍøÇå¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÒÑÐû²¼1000¶à¸öÎó²îͨ¸æºÍΣº¦Ô¤¾¯£¬ÎÒÃǽ«Ò»Á¬¸ú×ÙÈ«Çò×îеÄÍøÂçÇå¾²ÊÂÎñºÍÎó²î£¬ÎªÆóÒµµÄÐÅÏ¢Çå¾²±£¼Ý»¤º½¡£
¹Ø×¢ÎÒÃÇ£º