¡¾Â©¶´Í¨¸æ¡¿Sophos Firewall SQL×¢È멶´£¨CVE-2024-12727£©

Ðû²¼Ê±¼ä 2024-12-20

Ò»¡¢Â©¶´¸ÅÊö


©¶´Ãû³Æ

 Sophos Firewall SQL×¢È멶´

CVE   ID

CVE-2024-12727

©¶´ÀàÐÍ

SQL×¢Èë 

·¢ÏÖʱ¼ä

2024-12-20

©¶´ÆÀ·Ö

9.8

©¶´Æ·¼¶

¸ßΣ

¹¥»÷ÏòÁ¿

ÍøÂç

ËùÐèȨÏÞ

ÎÞ

ÀûÓÃÄѶÈ

µÍ

Óû§½»»¥

ÎÞ

PoC/EXP

δ¹ûÈ»

ÔÚÒ°ÀûÓÃ

δ·¢ÏÖ

 


Sophos ·À»ðǽÊÇÓÉSophos ¹«Ë¾ÌṩµÄÒ»¿î¹¦Ð§Ç¿´ó¡¢Ò×ÓÚ¹ÜÀíµÄÍøÂçÄþ¾²²úÎï £¬¼¯³ÉÁËNGFW¡¢VPN Ö§³Ö¡¢ATPµÈ¶àÖÖÄþ¾²¹¦Ð§ £¬Ö¼ÔÚΪÆóÒµºÍ×éÖ¯ÌṩȫÃæµÄÍøÂç± £»¤¡£


2024Äê12ÔÂ20ÈÕ £¬¶«É­Æ½Ì¨¼¯ÍÅVSRC¼à²âµ½Sophos ·À»ðǽÖдæÔÚÒ»¸öSQL×¢È멶´£¨CVE-2024-12727£© £¬¸Ã©¶´µÄCVSSÆÀ·ÖΪ9.8¡£


Sophos Firewall 21.0 MR1£¨21.0.1£©Ö®Ç°°æ±¾µÄµç×ÓÓʼþ± £»¤¹¦Ð§ÖдæÔÚSQL×¢È멶´ £¬ÓÉÓÚ·À»ðǽδÕýÈ·ÑéÖ¤»ò¹ýÂËÊäÈëÊý¾Ý £¬µ¼Ö¹¥»÷Õß¿Éͨ¹ý½á¹¹¶ñÒâ SQL ²éѯδÊÚȨ·ÃÎʳÂËßÊý¾Ý¿â £¬Èç¹û·À»ðǽÔËÐÐÔڸ߿ÉÓÃÐÔ (HA) ģʽ £¬ÇÒÆôÓÃÁË Secure PDF eXchange (SPX) µÄÌض¨ÅäÖà £¬¹¥»÷Õß¿ÉÄܽøÒ»²½ÀûÓø鶴µ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£


´ËÍâ £¬Sophos ·À»ðǽÖл¹´æÔÚÒ»¸öÈõƾ֤©¶´£¨CVE-2024-12728 £¬CVSSÆÀ·Ö9.8£© £¬ÓÉÓڸ߿ÉÓÃÐÔ (HA) ¼¯Èº³õʼ»¯Ê±Ëù½¨ÒéµÄ·ÇËæ»úSSH µÇ¼ÃÜÂëÔÚHA½¨Á¢¹ý³ÌÍê³ÉºóÈÔÈ»ÓÐЧ £¬Èç¹û·À»ðǽÆôÓÃÁË SSH ·þÎñ £¬¹¥»÷Õß¿ÉÄÜÀûÓÃÕâ¸öÒÑÖªµÄÈõÃÜÂëͨ¹ýSSH µÇ¼ £¬´Ó¶ø»ñµÃ¶ÔϵͳµÄÌØȨ·ÃÎÊ £»ÒÔ¼°ÔÚSophos ·À»ðǽÓû§ÃÅ»§£¨User Portal£©ÖдæÔÚÁíÒ»¸ö´úÂë×¢È멶´£¨CVE-2024-12729 £¬CVSSÆÀ·Ö8.8£© £¬¾­¹ýÉí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÀûÓø鶴µ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£


¶þ¡¢Ó°Ï췶Χ


Sophos Firewall <= v21.0 GA (21.0.0)


Èý¡¢Äþ¾²´ëÊ©


3.1 Éý¼¶°æ±¾


Ä¿Ç°ÕâЩ©¶´ÒѾ­ÐÞ¸´ £¬ÊÜÓ°ÏìÓû§¿ÉÉý¼¶µ½ÒÔÏ°汾£º


CVE-2024-12727

Sophos Firewall v21 GA¡¢v20 GA¡¢v20 MR1¡¢v20 MR2¡¢v20 MR3¡¢v19.5 MR3¡¢v19.5 MR4¡¢v19.0 MR2£ºÓ¦Óò¹¶¡»òÉý¼¶µ½ v21 MR1¼°¸ü¸ß°æ±¾¡£


CVE-2024-12728

Sophos Firewall v21 GA¡¢v20 GA¡¢v20 MR1¡¢v19.5 GA¡¢v19.5 MR1¡¢v19.5 MR2¡¢v19.5 MR3¡¢v19.5 MR4¡¢v19.0 MR2¡¢v20 MR2£ºÓ¦Óò¹¶¡»òÉý¼¶µ½v20 MR3¡¢v21 MR1 ¼°¸ü¸ß°æ±¾¡£


CVE-2024-12729

Sophos Firewall v21 GA¡¢v20 GA¡¢v20 MR1¡¢v20 MR2¡¢v19.5 GA¡¢v19.5 MR1¡¢v19.5 MR2¡¢v19.5 MR3¡¢v19.5 MR4¡¢v19.0 MR2¡¢v19.0 MR3¡¢v20 MR3£ºÓ¦Óò¹¶¡»òÉý¼¶µ½v21 MR1 ¼°¸ü¸ß°æ±¾¡£


ÏÂÔØÁ´½Ó£º

https://www.sophos.com/en-us/support/downloads


3.2 ÁÙʱ´ëÊ©


Õë¶ÔCVE-2024-12728£º

? È·±£ SSH ·ÃÎʽöÏÞÓÚרÓõġ¢ÎïÀíÉ϶ÀÁ¢µÄ HA Á´½Ó £¬¼´Í¨¹ýÒ»¸öרÃŵÄÍøÂçÁ¬½ÓÀ´½øÐÐ HA ÅäÖú͹ÜÀí £¬¶ø²»ÊÇͨ¹ý¹ã·ºµÄ SSH ·ÃÎÊ¡£

ÖØÐÂÅäÖà HA £¬Ê¹ÓÃÒ»¸ö×ã¹»³¤ÇÒËæ»úµÄ×Ô½ç˵ÃÜÂëÀ´Ìæ´úĬÈϵÄÈõÃÜÂë £¬´Ó¶ø½µµÍÃÜÂë±»ÆƽâµÄ·çÏÕ¡£

½ûÓÃͨ¹ýWAN¶Ë¿ÚµÄ SSH ·ÃÎÊ £¬²¢¸ÄÓà VPN »ò Sophos Central ½øÐÐÔ¶³Ì·ÃÎʺ͹ÜÀí¡£


Õë¶ÔCVE-2024-12729£º

½ûÓöÔÓû§ÃÅ»§ºÍ Webadmin µÄ WAN ·ÃÎÊ £¬²¢¸ÄÓà VPN »ò Sophos Central ½øÐÐÔ¶³Ì·ÃÎʺ͹ÜÀí¡£


3.3 ͨÓý¨Òé


¶¨ÆÚ¸üÐÂϵͳ²¹¶¡ £¬¼õÉÙϵͳ©¶´ £¬ÌáÉý·þÎñÆ÷µÄÄþ¾²ÐÔ¡£

¼ÓǿϵͳºÍÍøÂçµÄ·ÃÎÊ¿ØÖÆ £¬Ð޸ķÀ»ðǽ¼Æı £¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻò·þÎñ £¬¼õÉÙ½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø £¬¼õÉÙ¹¥»÷Ãæ¡£

ʹÓÃÆóÒµ¼¶Äþ¾²²úÎï £¬ÌáÉýÆóÒµµÄÍøÂçÄþ¾²ÐÔÄÜ¡£

¼ÓǿϵͳÓû§ºÍȨÏÞ¹ÜÀí £¬ÆôÓöàÒòËØÈÏÖ¤»úÖƺÍ×îСȨÏÞÔ­Ôò £¬Óû§ºÍÈí¼þȨÏÞÓ¦±£³ÖÔÚ×îµÍÏ޶ȡ£

ÆôÓÃÇ¿ÃÜÂë¼Æı²¢ÉèÖÃΪ¶¨ÆÚÐ޸ġ£


3.4 ²Î¿¼Á´½Ó


https://www.sophos.com/en-us/security-advisories/sophos-sa-20241219-sfos-rce

https://nvd.nist.gov/vuln/detail/CVE-2024-12727


ËÄ¡¢°æ±¾ÐÅÏ¢


°æ±¾

ÈÕÆÚ

±¸×¢

V1.0

2024-12-20

Ê×´ÎÐû²¼

 

Îå¡¢¸½Â¼


5.1 ¶«É­Æ½Ì¨¼ò½é


¶«É­Æ½Ì¨½¨Á¢ÓÚ1996Äê £¬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ´´½¨µÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢Äþ¾²¸ß¿Æ¼¼ÆóÒµ¡£ÊǹúÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Äþ¾²²úÎï¡¢Äþ¾²·þÎñ½â¾ö·½°¸µÄÁ캽ÆóÒµÖ®Ò»¡£


¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°¶«É­Æ½Ì¨´óÏà £¬¹«Ë¾Ô±¹¤6000ÓàÈË £¬Ñз¢ÍŶÓ1200ÓàÈË, ¼¼Êõ·þÎñÍŶÓ1300ÓàÈË¡£ÔÚÈ«¹ú¸÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö £¬ÓµÓÐÁýÕÖÈ«¹úµÄÏúÊÛÌåϵ¡¢ÇþµÀÌåϵºÍ¼¼ÊõÖ§³ÖÌåϵ¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐС°å¹ÒÅÆÉÏÊС££¨¹ÉƱ´úÂ룺002439£©


¶àÄêÀ´ £¬¶«É­Æ½Ì¨ÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷´´ÐµÄÄþ¾²²úÎïºÍ×î¼Ñʵ¼ù·þÎñ £¬×ÊÖú¿Í»§È«ÃæÌáÉýÆäIT»ù´¡ÉèÊ©µÄÄþ¾²ÐÔºÍÉú²úЧÄÜ £¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Äþ¾²¹¤ÒµÁì¾üÆ·Åƶø²»Ð¸Å¬Á¦¡£


5.2 ¹ØÓÚ¶«É­Æ½Ì¨


¶«É­Æ½Ì¨Äþ¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÒÑÐû²¼1000¶à¸ö©¶´Í¨¸æºÍ·çÏÕÔ¤¾¯ £¬ÎÒÃǽ«Á¬Ðø¸ú×ÙÈ«Çò×îеÄÍøÂçÄþ¾²Ê¼þºÍ©¶´ £¬ÎªÆóÒµµÄÐÅÏ¢Äþ¾²±£¼Ý»¤º½¡£


¹Ø×¢ÎÒÃÇ£º


Äþ¾²¼òѶ.jpg