CVE-2020-3280 | Cisco Unified CCXÔ¶³Ì´úÂëÖ´ÐÐÎó²îͨ¸æ

Ðû²¼Ê±¼ä 2020-05-22

0x00 Îó²î¸ÅÊö


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


0x01 Îó²îÏêÇé

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨



Cisco Unified Contact Center Express£¨Unified CCX£©ÊÇÃÀ¹ú˼¿Æ£¨Cisco£©¹«Ë¾µÄÒ»¿îͳһͨѶ½â¾ö¼Æ»®ÖеĿͻ§¹ØÏµÖÎÀí×é¼þ¡£¡£ ¡£¡£¡£¡£¡£¸Ã×é¼þÖ§³Ö×ÔÖúÓïÒôЧÀÍ¡¢ºô½Ð·ÖÅɺͿͻ§»á¼û¿ØÖƵȹ¦Ð§¡£¡£ ¡£¡£¡£¡£¡£

2020Äê5ÔÂ20ÈÕ˼¿Æ£¨Cisco£©¹Ù·½Ðû²¼Í¨¸æ£¬£¬£¬£¬ÐÞ¸´ÁËÒ»¸öUnified Contact Center Express£¨Unified CCX£©ÖеÄÑÏÖØÎó²î£¨CVE-2020-3280£©¡£¡£ ¡£¡£¡£¡£¡£¸ÃÎó²îÔ´ÓÚCisco Unified CCX ÔÚÖ´Ðз´ÐòÁл¯²Ù×÷ʱ£¬£¬£¬£¬JavaÔ¶³ÌÖÎÀí½çÃæÃ»ÓжÔÓû§ÊäÈë¾ÙÐÐÑéÖ¤£¬£¬£¬£¬µ¼Ö¹¥»÷Õß¿ÉÒÔÔÚδÊÚȨµÄÇéÐÎÏ·¢ËÍÒ»¸ö¶ñÒâµÄJava¹¤¾ß£¬£¬£¬£¬²¢ÔÚÊÜÓ°Ïì×°±¸ÉÏÒÔrootȨÏÞÖ´ÐÐí§Òâ´úÂë¡£¡£ ¡£¡£¡£¡£¡£


0x02 ´¦Öóͷ£½¨Òé


˼¿Æ¹Ù·½ÒѾ­Ðû²¼Ð°汾ÐÞ¸´ÁËÕâЩÎó²î£¬£¬£¬£¬ÇëÏà¹ØÓû§¾¡¿ìÉý¼¶¾ÙÐзÀ»¤£¬£¬£¬£¬ÆäÖÐCiscoUnified CCX 12.0(1)ES03ºÍCisco Unified CCX 12.5°æ±¾²»ÊܸÃÎó²îÓ°Ïì¡£¡£ ¡£¡£¡£¡£¡£

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-uccx-rce-GMSC6RKN


0x03 Ïà¹ØÐÂÎÅ


https://www.zdnet.com/article/cisco-critical-java-flaw-strikes-call-center-in-a-box-patch-urgently/#ftag=RSSbaffb68


0x04 ²Î¿¼Á´½Ó


https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-uccx-rce-GMSC6RKN


0x05 ʱ¼äÏß


2020-05-20 Cisco¹Ù·½Ðû²¼Í¨¸æ

2020-05-22 VSRCÐû²¼Îó²îͨ¸æ


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨