CVE-2025-6978:Arista NG Firewall 中的任意代码执行漏洞
在这份TrendAI研究服务漏洞报告的节选中,TrendAI研究团队的Jonathan Lein和Simon Humbert详细介绍了Arista下一代防火墙中一个近期修复的命令注入漏洞。该漏洞最初由Gereon Huppertz发现,并通过TrendAI零日计划(ZDI)报告。成功利用此漏洞可能导致在root用户的安全上下文中执行任意命令。以下是他们关于CVE-2025-6798报告的部分内容,并进行了少量修改。
Arista下一代防火墙中报告了一个命令注入漏洞。该漏洞是由于诊断组件中对用户数据验证不当造成的。
远程认证攻击者可以通过向目标服务器发送特制请求来利用此漏洞。成功利用可能导致在root用户的安全上下文中执行任意命令。
漏洞详情
Arista下一代防火墙是一款开源防火墙设备。它最初以Untangle的名称开发。Arista防火墙的一些功能包括垃圾邮件拦截、带宽控制和IPS等。下一代防火墙可以通过Web用户界面或使用HTTP的JSON-RPC API进行管理。
HTTP是一种在RFC 7230-7237及其他RFC中描述的请求/响应协议。客户端向服务器发送请求,服务器随后向客户端发送响应。HTTP请求由请求行、各种头部、空行和可选的消息体组成。
Request = Request-Line headers CRLF [message-body]
Request-Line = Method SP Request-URI SP HTTP-Version CRLF
Headers = *[Header]
Header = Field-Name ":" Field-Value CRLF
其中CRLF表示换行序列回车(CR)后跟换行(LF)。SP表示空格字符。参数可以作为名称-值对从客户端传递到服务器,具体位置取决于使用的Method和Content-Type头部,可能在Request-URI中,也可能在消息体中。例如,使用GET方法传递名为"param"、值为"1"的参数的简单HTTP请求可能如下所示:
GET /my_webapp/mypaget.htm?param=1 HTTP/1.1
Host: www.myhost.com
使用POST方法的相应HTTP请求可能如下所示:
POST /my_webapp/mypage.htm HTTP/1.1
Host: www.myhost.com
Content-Type: application/x-www-form-urlencoded
Content-Length: 7
param=1
如果有多个参数/值对,它们会被编码为以'&'分隔的name=value对:
var1=value1&var2=value2&var3=value3...
与本报告相关的组件是JSON-RPC端点。JSON对象具有以下语法:
- 对象用花括号{}括起来。
- 对象由零个或多个以逗号(",")字符分隔的项组成。
- 一个项由键和值组成。键和值之间用冒号(":")字符分隔。
- 键必须是字符串(用引号括起来)。
- 值必须是有效类型。有效类型包括字符串、数字、JSON对象、数组、布尔值或null。
- 数组是用方括号[]括起来的对象。数组由零个或多个以逗号(",")字符分隔的字符串、数字、JSON对象、数组、布尔值或null类型对象组成。
JSON对象示例如下:
{"TMSR-key": "value", "Second-key": 1234,
"TMSR-array": [1,2,3], "TMSR-object":{"TMSR-key":"value"}}
以下是与本报告相关的对runTroubleshooting()方法的JSON-RPC请求示例:
POST /admin/JSON-RPC HTTP/1.1
Host: 172.16.9.46
Accept-Encoding: identity
Content-Length: 136
Cookie: auth-2d71f35e=d6556b54cb69d1daed40d20e3ea14602; path=/
Content-type: text/plain
{"id":1, "nonce":"pndq05bufqbj0sfp3balgusrf4",
"method":".obj#553810317.runTroubleshooting",
"params":["DNS",{"HOST":"trendmicro.com"}]}
Arista下一代防火墙中报告了一个命令注入漏洞。该漏洞是由于对用于命令行的用户数据验证不当造成的。NetworkManagerImpl类的runTroubleshooting()方法将用于处理对runTroubleshooting方法的JSON-RPC请求。传递给该方法的命令参数将是请求体中params JSON数组的第一个元素。该值必须是NetworkManager类中定义的TroubleshootingCommands enum中的字符串之一。该方法的第二个参数将包含传递给JSON-RPC调用的附加参数。
该方法将首先遍历每个附加参数,并将每个键值对组合成一个字符串,用"="字符分隔,该字符串稍后将用作环境变量。接下来,使用switch case语句确保提供的命令是TroubleshootingCommands中的值之一。每个命令值都将使用相同的代码进行处理。
接下来,该方法将遍历每个环境变量,并检查是否存在以下常见的命令注入字符串:
; & | > $(
如果发现任何此类字符串,请求将被拒绝,并抛出异常。如果每个环境变量都有效,则调用execEvil()方法来创建并执行network-troubleshooting.sh脚本的命令行,并将环境变量作为参数传递。execEvil()方法随后将调用Runtime.getRuntime().exec()来运行脚本,第二个参数传递脚本将使用的环境变量。每个命令值在network-troubleshooting.sh中都有一个对应的函数,例如"DNS"命令值对应run_dns()。每个函数都将遵循类似的结构,即使用exec()传递的环境变量创建CMD字符串,然后调用eval来执行它。
然而,传递给runTroubleshooting JSON-RPC方法的参数值在用于命令行之前并未完全清理。虽然传递给端点的参数会检查一些shell元字符,但该列表并不完整。例如,反引号字符() is not included in the check and may be used to inject a command.
For example:
PLACEHOLDER_5
The example above will write and execute a python script on the server to achieve code execution without using any restricted characters.
A remote, authenticated attacker could exploit this vulnerability by sending a JSON-RPC request to the runTroubleshooting method containing a crafted “HOST” or “URL” parameter containing shell metacharacters not present in the runTroubleshooting() check. Successful exploitation in the worst case will result in arbitrary command execution under the security context of the root user.
Detection Guidance
To detect an attack exploiting this vulnerability, the detection device must monitor and parse traffic on the following ports: - HTTP, over port 80/TCP - HTTPS, over port 443/TCP
Traffic to Arista NG Firewall may be encrypted and must be decrypted prior to applying this guidance.
The detection device must search for HTTP POST requests made to the request-URI /admin/JSON-RPC. If found, the body of the request must be parsed as JSON. The JSON object in the body must be inspected for a method key, and its value must be inspected to contain the substring runTroubleshooting. If found, the object must also be inspected for the JSON key "params", with a value containing a JSON array. The first entry in the JSON array must be inspected for any of the following strings:
PLACEHOLDER_6
If found, the second entry in the array must be inspected for a JSON object, and inspected for any of the following keys:
PLACEHOLDER_7
If either is found, the corresponding value to the key must be inspected for any of the following command injection characters:
PLACEHOLDER_8
If found, the traffic should be treated as suspicious; an attack exploiting this vulnerability is likely underway.
The following regular expression can be applied to find malicious requests:
/\x22(HOST|URL)\x22\s*:\s*\x22(?:[^\x22\]|\.)*?[\x60\x27\x24\x3c]/`
注意事项:
- 对请求URI和所有JSON字符串的字符串匹配应以区分大小写的方式进行。
- JSON字符串可能被编码,在应用此指导前必须进行解码。
- 请求URI可能经过URL编码,在应用此指导前必须进行解码。
结论
Arista已通过其安全公告0123解决了此漏洞。他们指出Arista边缘威胁管理 - Arista下一代防火墙(原Untangle)受此漏洞影响,但其他产品版本不受影响。他们还指出可以应用以下缓解措施:
不要允许未经授权的管理访问或对管理浏览器的访问。
然而,更合适的做法是通过升级到17.4或更高版本来应用供应商提供的安全补丁。
特别感谢TrendAI研究团队的Jonathan Lein和Simon Humbert对此漏洞提供了如此详尽的分析。有关TrendAI研究服务的概述,请访问https://go.trendmicro.com/tis/vulnerabilities.html。
威胁研究团队未来将带来其他优秀的漏洞分析报告。在此之前,请在Twitter、Mastodon、LinkedIn或Bluesky上关注该团队,以获取最新的漏洞利用技术和安全补丁信息。