CVE-2020-3280 | Cisco Unified CCXÔ¶³Ì´úÂëÖ´ÐÐÎó²îͨ¸æ
Ðû²¼Ê±¼ä 2020-05-220x00 Îó²î¸ÅÊö
0x01 Îó²îÏêÇé
Cisco Unified Contact Center Express£¨Unified CCX£©ÊÇÃÀ¹ú˼¿Æ£¨Cisco£©¹«Ë¾µÄÒ»¿îͳһͨѶ½â¾ö¼Æ»®ÖеĿͻ§¹ØÏµÖÎÀí×é¼þ¡£¡£¡£¡£¡£¡£¡£¸Ã×é¼þÖ§³Ö×ÔÖúÓïÒôЧÀÍ¡¢ºô½Ð·ÖÅɺͿͻ§»á¼û¿ØÖƵȹ¦Ð§¡£¡£¡£¡£¡£¡£¡£
2020Äê5ÔÂ20ÈÕ˼¿Æ£¨Cisco£©¹Ù·½Ðû²¼Í¨¸æ£¬£¬£¬£¬ÐÞ¸´ÁËÒ»¸öUnified Contact Center Express£¨Unified CCX£©ÖеÄÑÏÖØÎó²î£¨CVE-2020-3280£©¡£¡£¡£¡£¡£¡£¡£¸ÃÎó²îÔ´ÓÚCisco Unified CCX ÔÚÖ´Ðз´ÐòÁл¯²Ù×÷ʱ£¬£¬£¬£¬JavaÔ¶³ÌÖÎÀí½çÃæÃ»ÓжÔÓû§ÊäÈë¾ÙÐÐÑéÖ¤£¬£¬£¬£¬µ¼Ö¹¥»÷Õß¿ÉÒÔÔÚδÊÚȨµÄÇéÐÎÏ·¢ËÍÒ»¸ö¶ñÒâµÄJava¹¤¾ß£¬£¬£¬£¬²¢ÔÚÊÜÓ°Ïì×°±¸ÉÏÒÔrootȨÏÞÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¡£
0x02 ´¦Öóͷ£½¨Òé
˼¿Æ¹Ù·½ÒѾÐû²¼Ð°汾ÐÞ¸´ÁËÕâЩÎó²î£¬£¬£¬£¬ÇëÏà¹ØÓû§¾¡¿ìÉý¼¶¾ÙÐзÀ»¤£¬£¬£¬£¬ÆäÖÐCiscoUnified CCX 12.0(1)ES03ºÍCisco Unified CCX 12.5°æ±¾²»ÊܸÃÎó²îÓ°Ïì¡£¡£¡£¡£¡£¡£¡£
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-uccx-rce-GMSC6RKN
0x03 Ïà¹ØÐÂÎÅ
https://www.zdnet.com/article/cisco-critical-java-flaw-strikes-call-center-in-a-box-patch-urgently/#ftag=RSSbaffb68
0x04 ²Î¿¼Á´½Ó
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-uccx-rce-GMSC6RKN
0x05 ʱ¼äÏß
2020-05-20 Cisco¹Ù·½Ðû²¼Í¨¸æ
2020-05-22 VSRCÐû²¼Îó²îͨ¸æ
