JPCERT¥³¡¼¥Ç¥£¥Í¡¼¥·¥ç¥ó¥»¥ó¥¿¡¼(JPCERT/CC: Japan Computer Emergency Response Team Coordination Center)¤Ï4·î13Æü(15Æü¹¹¿·)¡¢¡ÖPalo Alto Networks¼ÒÀ½PAN-OS GlobalProtect¤ÎOS¥³¥Þ¥ó¥É¥¤¥ó¥¸¥§¥¯¥·¥ç¥ó¤ÎÀȼåÀ­¡ÊCVE-2024-3400¡Ë¤Ë´Ø¤¹¤ëÃí°Õ´­µ¯¡×¤Ë¤ª¤¤¤Æ¡¢Palo Alto Networks¤ÎPAN-OS¤Ë¶ÛµÞ¤ÎÀȼåÀ­¤¬Â¸ºß¤¹¤ë¤È¤·¤Æ¡¢Ãí°Õ¤ò¸Æ¤Ó³Ý¤±¤¿¡£¤³¤ÎÀȼåÀ­¤òÍøÍѤµ¤ì¤ë¤È¡¢Ç§¾Ú¤µ¤ì¤Æ¤¤¤Ê¤¤¥ê¥â¡¼¥È¤Î¹¶·â¼Ô¤Ë±ó³Ö¤«¤é´ÉÍý¼Ô¸¢¸Â¤ÇǤ°Õ¤Î¥³¡¼¥É¤ò¼Â¹Ô¤µ¤ì¤ë²ÄǽÀ­¤¬¤¢¤ë¡£

Palo Alto Networks¼ÒÀ½PAN-OS GlobalProtect¤ÎOS¥³¥Þ¥ó¥É¥¤¥ó¥¸¥§¥¯¥·¥ç¥ó¤ÎÀȼåÀ­¡ÊCVE-2024-3400¡Ë¤Ë´Ø¤¹¤ëÃí°Õ´­µ¯

¡ûÀȼåÀ­¤Ë´Ø¤¹¤ë¾ðÊó

ÀȼåÀ­¤Ë´Ø¤¹¤ë¾ðÊó¤Ï¼¡¤Î¥Ú¡¼¥¸¤Ë¤Þ¤È¤Þ¤Ã¤Æ¤¤¤ë¡£

CVE-2024-3400 PAN-OS: OS Command Injection Vulnerability in GlobalProtect

ȯ¸«¤µ¤ì¤¿ÀȼåÀ­¤Î¾ðÊó(CVE)¤Ï¼¡¤Î¤È¤ª¤ê¡£

CVE-2024-3400 - PAN-OS¤ÎGlobalProtect¤Ë¥³¥Þ¥ó¥É¥¤¥ó¥¸¥§¥¯¥·¥ç¥ó¤ÎÀȼåÀ­¡£GlobalProtect¥²¡¼¥È¥¦¥§¥¤¤Þ¤¿¤ÏGlobalProtect¥Ý¡¼¥¿¥ë¡¢¤â¤·¤¯¤Ï¤½¤ÎξÊý¤È¥Ç¥Ð¥¤¥¹¥Æ¥ì¥á¥È¥ê¤òÍ­¸ú¤Ë¤·¤¿PAN-OS¤Î¥Õ¥¡¥¤¥¢¡¼¥¦¥©¡¼¥ë¤¬±Æ¶Á¤ò¼õ¤±¤ë¡£Cloud NGFW¡¢Panorama¥¢¥×¥é¥¤¥¢¥ó¥¹¡¢Prisma Access¤Ï±Æ¶Á¤ò¼õ¤±¤Ê¤¤

¡ûÀȼåÀ­¤Î±Æ¶Á¤ò¼õ¤±¤ëÀ½Éʤª¤è¤Ó¥Ð¡¼¥¸¥ç¥ó

ÀȼåÀ­¤Î±Æ¶Á¤ò¼õ¤±¤ë¤È¤µ¤ì¤ë¥×¥í¥À¥¯¥È¤ª¤è¤Ó¥Ð¡¼¥¸¥ç¥ó¤Ï¼¡¤Î¤È¤ª¤ê¡£

PAN-OS 11.1 ¥Ð¡¼¥¸¥ç¥ó11.1.2-h3¤è¤êÁ°¤Î¥Ð¡¼¥¸¥ç¥ó

PAN-OS 11.0 ¥Ð¡¼¥¸¥ç¥ó11.0.4-h1¤è¤êÁ°¤Î¥Ð¡¼¥¸¥ç¥ó

PAN-OS 10.2 ¥Ð¡¼¥¸¥ç¥ó10.2.9-h1¤è¤êÁ°¤Î¥Ð¡¼¥¸¥ç¥ó

¡ûÀȼåÀ­¤¬½¤Àµ¤µ¤ì¤¿À½Éʤª¤è¤Ó¥Ð¡¼¥¸¥ç¥ó

ÀȼåÀ­¤¬½¤Àµ¤µ¤ì¤¿À½Éʤª¤è¤Ó¥Ð¡¼¥¸¥ç¥ó¤Ï¼¡¤Î¤È¤ª¤ê¡£

PAN-OS 11.1 ¥Ð¡¼¥¸¥ç¥ó11.1.2-h3¤ª¤è¤Ó¤³¤ì°Ê¹ß¤Î¥Ð¡¼¥¸¥ç¥ó

PAN-OS 11.0 ¥Ð¡¼¥¸¥ç¥ó11.0.4-h1¤ª¤è¤Ó¤³¤ì°Ê¹ß¤Î¥Ð¡¼¥¸¥ç¥ó

PAN-OS 10.2 ¥Ð¡¼¥¸¥ç¥ó10.2.9-h1¤ª¤è¤Ó¤³¤ì°Ê¹ß¤Î¥Ð¡¼¥¸¥ç¥ó

Palo Alto Networks¤Ï¤³¤ÎÀȼåÀ­¤ò°­ÍѤ·¤¿¹¶·â¤ò¤¹¤Ç¤Ë³Îǧ¤·¤¿¤È¤·¤Æ¤ª¤êÃí°Õ¤¬É¬Íס£¤³¤ÎÀȼåÀ­¤Î¿¼¹ïÅ٤϶۵Þ(Critical)¤Èɾ²Á¤µ¤ì¤Æ¤¤¤ë¡£Palo Alto Networks¤Î¶¼°ÒÂкö(Threat Prevention)¥µ¥Ö¥¹¥¯¥ê¥×¥·¥ç¥ó¤ò»ÈÍѤ·¤Æ¤¤¤ë¥æ¡¼¥¶¡¼¤Ï¶¼°Ò ID 95187(¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤È¶¼°Ò¤Î¥³¥ó¥Æ¥ó¥Ä¥Ð¡¼¥¸¥ç¥ó8833-8682°Ê¹ß¤ÇÍøÍѲÄǽ)¤ò»ÈÍѤ¹¤ë¤³¤È¤Ç¹¶·â¤ò¥Ö¥í¥Ã¥¯¤Ç¤­¤ë(»²¹Í¡§¡ÖApplying Vulnerability Protection to GlobalProtect Interfaces | Palo Alto Networks¡×)¡£

¥µ¥Ö¥¹¥¯¥ê¥×¥·¥ç¥ó¤ò»ÈÍѤ·¤Æ¤ª¤é¤º¡¢Â¨ºÂ¤Ë¥¢¥Ã¥×¥Ç¡¼¥È¤Ç¤­¤Ê¤¤¥æ¡¼¥¶¡¼¤Ï¥Ç¥Ð¥¤¥¹¥Æ¥ì¥á¥È¥ê¤ò°ì»þŪ¤Ë̵¸ú¤Ë¤¹¤ë¤³¤È¤Ç±Æ¶Á¤ò·Ú¸º¤Ç¤­¤ë¡£¤³¤Î·Ú¸ººö¤ò¼Â»Ü¤·¤¿¾ì¹ç¡¢¥¢¥Ã¥×¥Ç¡¼¥È¸å¤Ë¥Ç¥Ð¥¤¥¹¥Æ¥ì¥á¥È¥ê¤òºÆÅÙÍ­¸ú¤Ë¤¹¤ëɬÍפ¬¤¢¤ë¡£