{"id":10791,"date":"2021-04-30T15:19:41","date_gmt":"2021-04-30T06:19:41","guid":{"rendered":"https:\/\/www.csirt.dendai.ac.jp\/csirt\/?p=10791"},"modified":"2023-10-17T11:51:42","modified_gmt":"2023-10-17T02:51:42","slug":"pulse-connect-secure%e3%81%ae%e8%84%86%e5%bc%b1%e6%80%a7%ef%bc%88cve-2021-22893%ef%bc%89%e3%81%ab%e9%96%a2%e3%81%99%e3%82%8b%e6%b3%a8%e6%84%8f%e5%96%9a%e8%b5%b7","status":"publish","type":"post","link":"https:\/\/www.csirt.dendai.ac.jp\/csirt\/public\/heads-up\/pulse-connect-secure%e3%81%ae%e8%84%86%e5%bc%b1%e6%80%a7%ef%bc%88cve-2021-22893%ef%bc%89%e3%81%ab%e9%96%a2%e3%81%99%e3%82%8b%e6%b3%a8%e6%84%8f%e5%96%9a%e8%b5%b7\/","title":{"rendered":"Pulse Connect Secure\u306e\u8106\u5f31\u6027\uff08CVE-2021-22893\uff09\u306b\u95a2\u3059\u308b\u6ce8\u610f\u559a\u8d77"},"content":{"rendered":"\n<p>I. \u6982\u8981<br \/>2021\u5e744\u670820\u65e5\uff08\u7c73\u56fd\u6642\u9593\uff09\u3001Pulse Secure\u304b\u3089Pulse Connect Secure\u306e\u8106\u5f31\u6027\uff08CVE-2021-22893\uff09\u306b\u95a2\u3059\u308b\u30a2\u30c9\u30d0\u30a4\u30b6\u30ea\u304c\u516c\u958b\u3055\u308c\u307e\u3057\u305f\u3002<br \/>\u8106\u5f31\u6027\u304c\u60aa\u7528\u3055\u308c\u305f\u5834\u5408\u3001\u9060\u9694\u306e\u7b2c\u4e09\u8005\u304c\u8a8d\u8a3c\u3092\u56de\u907f\u3057\u3001\u4efb\u610f\u306e\u30b3\u30fc\u30c9\u3092\u5b9f\u884c\u3059\u308b\u306a\u3069\u306e\u53ef\u80fd\u6027\u304c\u3042\u308a\u307e\u3059\u3002<br \/>\u540c\u65e5\u3001FireEye\u304c\u30d6\u30ed\u30b0\u3092\u516c\u958b\u3057\u3001\u672c\u8106\u5f31\u6027\u3084\u65e2\u77e5\u306ePulseConnect Secure\u306e\u8106\u5f31\u6027\u3092\u60aa\u7528\u3057\u305f\u653b\u6483\u3092\u78ba\u8a8d\u3057\u3066\u3044\u308b\u3068\u660e\u3089\u304b\u306b\u3057\u3066\u3044\u307e\u3059\u3002<\/p>\n<p>2021\u5e744\u670821\u65e5\u73fe\u5728\u3001\u8106\u5f31\u6027\u3092\u4fee\u6b63\u3059\u308b\u30d0\u30fc\u30b8\u30e7\u30f3\u3084\u30d1\u30c3\u30c1\u306f\u516c\u958b\u3055\u308c\u3066\u3044\u307e\u305b\u3093\u304c\u3001\u3059\u3067\u306b\u8106\u5f31\u6027\u3092\u60aa\u7528\u3057\u305f\u653b\u6483\u304c\u78ba\u8a8d\u3055\u308c\u3066\u3044\u308b\u305f\u3081\u3001\u540c\u88fd\u54c1\u3092\u5229\u7528\u3057\u3066\u3044\u308b\u5834\u5408\u306f\u3001\u56de\u907f\u7b56\u306e\u9069\u7528\u3084\u4fb5\u5bb3\u78ba\u8a8d\u30c4\u30fc\u30eb\u3092\u7528\u3044\u305f\u8abf\u67fb\u3092\u63a8\u5968\u3057\u307e\u3059\u3002<br \/>\u8a73\u7d30\u306f\u3001Pulse Secure\u304c\u63d0\u4f9b\u3059\u308b\u60c5\u5831\u3092\u53c2\u7167\u3057\u3066\u304f\u3060\u3055\u3044\u3002<br \/>\u53c2\u8003\uff1a<a href=\"https:\/\/www.jpcert.or.jp\/at\/2021\/at210019.html\" target=\"_blank\" rel=\"noopener\">https:\/\/www.jpcert.or.jp\/at\/2021\/at210019.html<\/a><\/p>\n<p>Pulse Secure<br \/>SA44784 &#8211; 2021-04: Out-of-Cycle Advisory: Pulse Connect Secure RCE Vulnerability (CVE-2021-22893)<br \/><a href=\"https:\/\/kb.pulsesecure.net\/articles\/Pulse_Security_Advisories\/SA44784\/\" target=\"_blank\" rel=\"noopener\">https:\/\/kb.pulsesecure.net\/articles\/Pulse_Security_Advisories\/SA44784\/<\/a><\/p>\n<p>FireEye<br \/>Check Your Pulse: Suspected APT Actors Leverage Authentication Bypass Techniques and Pulse Secure Zero-Day<br \/><a href=\"https:\/\/www.fireeye.com\/blog\/threat-research\/2021\/04\/suspected-apt-actors-leverage-bypass-techniques-pulse-secure-zero-day.html\" target=\"_blank\" rel=\"noopener\">https:\/\/www.fireeye.com\/blog\/threat-research\/2021\/04\/suspected-apt-actors-leverage-bypass-techniques-pulse-secure-zero-day.html<\/a><\/p>\n<p>** \u66f4\u65b0: 2021\u5e744\u670822\u65e5\u8ffd\u8a18 **********************************************************<br \/>Pulse Secure\u3092\u5098\u4e0b\u306b\u7f6e\u304fIvanti\u793e\u304c\u3001\u672c\u8106\u5f31\u6027\u306b\u3064\u3044\u3066\u65e5\u672c\u8a9e\u3067\u60c5\u5831\u3092\u516c\u958b\u3057\u3066\u3044\u307e\u3059\u3002<br \/>\u5bfe\u5fdc\u3092\u9032\u3081\u308b\u4e0a\u3067\u306e\u53c2\u8003\u306b\u3057\u3066\u304f\u3060\u3055\u3044\u3002<\/p>\n<p>Ivanti<br \/>Pulse Connect Secure\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u30a2\u30c3\u30d7\u30c7\u30fc\u30c8<br \/><a href=\"https:\/\/www.ivanti.co.jp\/blog\/pulse-connect-secure-security-update\" target=\"_blank\" rel=\"noopener\">https:\/\/www.ivanti.co.jp\/blog\/pulse-connect-secure-security-update<\/a><br \/>***************************************************************************************<\/p>\n<p><br \/>II. \u5bfe\u8c61<br \/>\u5bfe\u8c61\u3068\u306a\u308b\u88fd\u54c1\u304a\u3088\u3073\u30d0\u30fc\u30b8\u30e7\u30f3\u306f\u6b21\u306e\u3068\u304a\u308a\u3067\u3059\u3002<\/p>\n<p>&#8211; Pulse Connect Secure 9.0R3\u304a\u3088\u3073\u305d\u308c\u4ee5\u964d<\/p>\n<p><br \/>III. \u5bfe\u7b56<br \/>2021\u5e744\u670821\u65e5\u73fe\u5728\u3001\u8106\u5f31\u6027\u3092\u4fee\u6b63\u3059\u308b\u30d0\u30fc\u30b8\u30e7\u30f3\u306f\u516c\u958b\u3055\u308c\u3066\u3044\u307e\u305b\u3093\u3002<br \/>FireEye\u306e\u30d6\u30ed\u30b0\u306a\u3069\u306b\u306f\u3001\u8106\u5f31\u6027\u3092\u4fee\u6b63\u3059\u308b\u30d1\u30c3\u30c1\u306f5\u6708\u4e0a\u65ec\u306b\u516c\u958b\u3055\u308c\u308b\u898b\u8fbc\u307f\u3067\u3042\u308b\u3068\u306e\u60c5\u5831\u304c\u3042\u308a\u307e\u3059\u3002<\/p>\n<p>** \u66f4\u65b0: 2021\u5e745\u67086\u65e5\u8ffd\u8a18 *******************************************<br \/>2021\u5e745\u67083\u65e5\uff08\u7c73\u56fd\u6642\u9593\uff09\u3001Pulse Secure\u304b\u3089\u4fee\u6b63\u30d0\u30fc\u30b8\u30e7\u30f3\u304c\u516c\u958b\u3055\u308c\u307e\u3057<br \/>\u305f\u3002CVE-2021-22893\u306b\u52a0\u3048\u3066\u3001\u5225\u306e3\u3064\u306e\u8106\u5f31\u6027\uff08CVE-2021-22894\u3001<br \/>CVE-2021-22899\u3001CVE-2021-22900\uff09\u306e\u4fee\u6b63\u3082\u542b\u307e\u308c\u3066\u3044\u307e\u3059\u3002Pulse Secure\u304b<br \/>\u3089\u516c\u958b\u3055\u308c\u305f\u60c5\u5831\u3092\u53c2\u7167\u306e\u3046\u3048\u3001\u4fee\u6b63\u30d0\u30fc\u30b8\u30e7\u30f3\u306e\u9069\u7528\u3092\u3054\u691c\u8a0e\u304f\u3060\u3055\u3044\u3002<\/p>\n<p>Pulse Secure<br \/>Pulse Connect Secure Patch Availability &#8211; SA44784<br \/><a href=\"https:\/\/blog.pulsesecure.net\/pulse-connect-secure-patch-availability-sa44784\/\" target=\"_blank\" rel=\"noopener\">https:\/\/blog.pulsesecure.net\/pulse-connect-secure-patch-availability-sa44784\/<\/a><\/p>\n<p>\u306a\u304a\u3001\u3059\u3067\u306b\u56de\u907f\u7b56\u3092\u9069\u7528\u3057\u3066\u3044\u308b\u5834\u5408\u3001\u8106\u5f31\u6027\u3092\u4fee\u6b63\u3059\u308b\u30d0\u30fc\u30b8\u30e7\u30f3\u3092\u9069\u7528<br \/>\u3059\u308b\u524d\u306b\u3001\u56de\u907f\u7b56\u3067\u9069\u7528\u3057\u305f\u5909\u66f4\u3092\u5207\u308a\u623b\u3059\u3053\u3068\u304c\u63a8\u5968\u3055\u308c\u3066\u3044\u307e\u3059\u3002\u5b9f\u65bd\u624b<br \/>\u9806\u306a\u3069\u306e\u8a73\u7d30\u306fPulse Secure\u306e\u30a2\u30c9\u30d0\u30a4\u30b6\u30ea\u306e\u60c5\u5831\u3092\u3054\u78ba\u8a8d\u304f\u3060\u3055\u3044\u3002<br \/>**********************************************************************<\/p>\n<p><br \/>IV. \u56de\u907f\u7b56<br \/>\u8106\u5f31\u6027\u3092\u4fee\u6b63\u3059\u308b\u30d0\u30fc\u30b8\u30e7\u30f3\u304c\u516c\u958b\u3055\u308c\u308b\u307e\u3067\u306e\u9593\u3001\u8106\u5f31\u6027\u3092\u60aa\u7528\u3057\u305f\u653b\u6483\u306b\u3088\u308b\u5f71\u97ff\u3092\u8efd\u6e1b\u3059\u308b\u305f\u3081\u3001Pulse Secure\u306f\u6b21\u306e\u56de\u907f\u7b56\u306e\u9069\u7528\u3092\u63a8\u5968\u3057\u3066\u3044\u307e\u3059\u3002<\/p>\n<p>&#8211; Pulse Secure\u304c\u63d0\u4f9b\u3059\u308bWorkaround-2104.xml\u30d5\u30a1\u30a4\u30eb\u3092\u30a4\u30f3\u30dd\u30fc\u30c8\u3059\u308b<\/p>\n<p>xml\u30d5\u30a1\u30a4\u30eb\u3092\u30a4\u30f3\u30dd\u30fc\u30c8\u3059\u308b\u3068\u3001URL\u30d9\u30fc\u30b9\u306e\u653b\u6483\u306b\u3088\u308b\u5f71\u97ff\u304c\u8efd\u6e1b\u3055\u308c\u3001Windows File Share Browser\u3068Pulse Secure Collaboration\u304c\u7121\u52b9\u306b\u306a\u308a\u307e\u3059\u3002<br \/>\u30a4\u30f3\u30dd\u30fc\u30c8\u5f8c\u306b\u3001Windows File Browser\u304c\u7121\u52b9\u306b\u306a\u3063\u3066\u3044\u308b\u304b\u8a2d\u5b9a\u3092\u78ba\u8a8d\u3059\u308b\u3053\u3068\u304c\u63a8\u5968\u3055\u308c\u3066\u3044\u307e\u3059\u3002<br \/>\u8a73\u7d30\u306e\u5185\u5bb9\u3084\u5b9f\u65bd\u624b\u9806\u306b\u3064\u3044\u3066\u306f\u3001Pulse Secure\u306e\u30a2\u30c9\u30d0\u30a4\u30b6\u30ea\u3092\u3054\u53c2\u7167\u304f\u3060\u3055\u3044\u3002<\/p>\n<p><br \/>V. \u4fb5\u5bb3\u78ba\u8a8d\u30c4\u30fc\u30eb<br \/>Pulse Secure\u306f\u3001Pulse Secure Connect\u3067\u4e0d\u5be9\u306a\u30d5\u30a1\u30a4\u30eb\u8a2d\u7f6e\u3084\u30d5\u30a1\u30a4\u30eb\u306e\u6539\u3056\u3093\u304c\u884c\u308f\u308c\u3066\u3044\u306a\u3044\u304b\u78ba\u8a8d\u3059\u308b\u305f\u3081\u306e\u30c4\u30fc\u30eb\u300cPulse Connect Secure<br \/>Integrity Tool\u300d\u3092\u516c\u958b\u3057\u3066\u3044\u307e\u3059\u3002\u30c4\u30fc\u30eb\u306b\u3088\u308a\u8105\u5a01\u304c\u691c\u77e5\u3055\u308c\u305f\u5834\u5408\u306e\u5bfe\u5fdc\u65b9\u6cd5\u306a\u3069\u3092\u307e\u3068\u3081\u305fFAQ\u3084\u3001\u30c4\u30fc\u30eb\u306e\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u65b9\u6cd5\u3084\u5b9f\u884c\u65b9\u6cd5\u306b\u3064\u3044<br \/>\u3066\u306f\u3001Pulse Secure\u304c\u63d0\u4f9b\u3059\u308b\u60c5\u5831\u3092\u3054\u53c2\u7167\u304f\u3060\u3055\u3044\u3002<\/p>\n<p>Pulse Secure<br \/>KB44755 &#8211; Pulse Connect Secure (PCS) Integrity Assurance<br \/><a href=\"https:\/\/kb.pulsesecure.net\/articles\/Pulse_Secure_Article\/KB44755\" target=\"_blank\" rel=\"noopener\">https:\/\/kb.pulsesecure.net\/articles\/Pulse_Secure_Article\/KB44755<\/a><\/p>\n<p>Pulse Secure<br \/>KB44764 &#8211; Customer FAQ: PCS Security Integrity Tool Enhancements<br \/><a href=\"https:\/\/kb.pulsesecure.net\/articles\/Pulse_Secure_Article\/KB44764\" target=\"_blank\" rel=\"noopener\">https:\/\/kb.pulsesecure.net\/articles\/Pulse_Secure_Article\/KB44764<\/a><\/p>\n<p><br \/>VI. \u53c2\u8003\u60c5\u5831<br \/>CISA<br \/>CISA Releases Alert on Exploitation of Pulse Connect Secure Vulnerabilities<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ncas\/current-activity\/2021\/04\/20\/cisa-releases-alert-exploitation-pulse-connect-secure\" target=\"_blank\" rel=\"noopener\">https:\/\/us-cert.cisa.gov\/ncas\/current-activity\/2021\/04\/20\/cisa-releases-alert-exploitation-pulse-connect-secure<\/a><\/p>\n<p>CISA<br \/>CISA Issues Emergency Directive on Pulse Connect Secure<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ncas\/current-activity\/2021\/04\/20\/cisa-issues-emergency-directive-pulse-connect-secure\" target=\"_blank\" rel=\"noopener\">https:\/\/us-cert.cisa.gov\/ncas\/current-activity\/2021\/04\/20\/cisa-issues-emergency-directive-pulse-connect-secure<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>I. \u6982\u89812021\u5e744\u670820\u65e5\uff08\u7c73\u56fd\u6642\u9593\uff09\u3001Pulse Secure\u304b\u3089Pulse Connect Secure\u306e\u8106\u5f31\u6027\uff08CVE-2021-22893\uff09\u306b\u95a2\u3059\u308b\u30a2\u30c9\u30d0\u30a4\u30b6\u30ea\u304c\u516c\u958b\u3055\u308c\u307e\u3057\u305f\u3002\u8106\u5f31\u6027\u304c\u60aa\u7528\u3055\u308c\u305f\u5834\u5408\u3001\u9060\u9694\u306e [&hellip;]<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[5],"tags":[45],"_links":{"self":[{"href":"https:\/\/www.csirt.dendai.ac.jp\/csirt\/wp-json\/wp\/v2\/posts\/10791"}],"collection":[{"href":"https:\/\/www.csirt.dendai.ac.jp\/csirt\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.csirt.dendai.ac.jp\/csirt\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.csirt.dendai.ac.jp\/csirt\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.csirt.dendai.ac.jp\/csirt\/wp-json\/wp\/v2\/comments?post=10791"}],"version-history":[{"count":3,"href":"https:\/\/www.csirt.dendai.ac.jp\/csirt\/wp-json\/wp\/v2\/posts\/10791\/revisions"}],"predecessor-version":[{"id":10867,"href":"https:\/\/www.csirt.dendai.ac.jp\/csirt\/wp-json\/wp\/v2\/posts\/10791\/revisions\/10867"}],"wp:attachment":[{"href":"https:\/\/www.csirt.dendai.ac.jp\/csirt\/wp-json\/wp\/v2\/media?parent=10791"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.csirt.dendai.ac.jp\/csirt\/wp-json\/wp\/v2\/categories?post=10791"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.csirt.dendai.ac.jp\/csirt\/wp-json\/wp\/v2\/tags?post=10791"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}