Cisco Jabber¿Í»§¶Ë¶à¸öÇå¾²Îó²î

Ðû²¼Ê±¼ä 2021-03-25

0x00 Îó²î¸Å

Cisco JabberÊÇÒ»¸ö¼´Ê±ÐÂÎźÍweb¾Û»á×ÀÃæÓ¦ÓóÌÐò£¬£¬£¬ËüʹÓÿÉÀ©Õ¹ÐÂÎźÍ״̬ЭÒ飨XMPP£©ÔÚÓû§Ö®¼äת´ïÐÂÎÅ¡£¡£¡£ ¡£¡£¡£¸ÃÓ¦ÓóÌÐò»ùÓÚChromium Embedded Framework£¨CEF£©¹¹½¨£¬£¬£¬ÆäUIʹÓÃHTML¡¢CSSºÍJavaScriptµÈwebÊÖÒÕ¡£¡£¡£ ¡£¡£¡£

2021Äê03ÔÂ24ÈÕ£¬£¬£¬CiscoÐû²¼Ç徲ͨ¸æ£¬£¬£¬ÐÞ¸´ÁËCisco JabberÖеĶà¸öÇå¾²Îó²î¡£¡£¡£ ¡£¡£¡£¹¥»÷ÕßÄܹ»Ê¹ÓÃÕâЩÎó²îÔÚϵͳÉÏÖ´ÐÐí§Òâ´úÂë¡¢»á¼ûÃô¸ÐÐÅÏ¢¡¢×èµ²Êܱ£»£»£»£» £»£»¤µÄÍøÂçÁ÷Á¿»òµ¼Ö¾ܾøÐ§ÀÍ£¨DoS£©¡£¡£¡£ ¡£¡£¡£

 

0x01 Îó²îÏêÇé

image.png

 

³ýÁËCVE-2021-1471Í⣬£¬£¬ÕâЩÎó²î²»»áÓ°ÏìΪPhone-only ģʽºÍTeam Messaging ģʽµÄCisco Jabber¿Í»§¶ËÈí¼þ¡£¡£¡£ ¡£¡£¡£±¾´Î¹ûÕæµÄÎó²îÈçÏ£º

Cisco Jabberƽ̨

CVE ID

Windows

CVE-2021-1411¡¢CVE-2021-1417¡¢CVE-2021-1418¡¢CVE-2021-1469¡¢ CVE-2021-1471

MacOS

CVE-2021-1418 ¡¢CVE-2021-1471

Android ºÍ iOS

CVE-2021-1418 ¡¢ CVE-2021-1471

 

Îó²îÏêÇéÈçÏ£º

Cisco Jabberí§Òâ´úÂëÖ´ÐÐÎó²î£¨CVE-2021-1411£©

ÓÉÓÚÓʼþÄÚÈÝÑéÖ¤²»×¼È·£¬£¬£¬Cisco Jabber for WindowsÖб£´æÒ»¸öí§Òâ´úÂëÖ´ÐÐÎó²î£¬£¬£¬ÆäCVSSÆÀ·ÖΪ9.9¡£¡£¡£ ¡£¡£¡£¹¥»÷Õß¿ÉÒÔͨ¹ýÏòÊÜÓ°ÏìµÄJabber¿Í»§¶ËÈí¼þ·¢ËͶñÒâµÄXMPPÐÂÎÅÀ´Ê¹ÓôËÎó²î£¬£¬£¬ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷ÕßÄܹ»ÒÔÔËÐÐCisco Jabber¿Í»§¶ËÈí¼þµÄÓû§ÕÊ»§µÄȨÏÞʹӦÓóÌÐòÔÚÄ¿µÄϵͳÉÏÖ´ÐÐí§Òâ³ÌÐò£¬£¬£¬Õâ¿ÉÄܵ¼ÖÂí§Òâ´úÂëÖ´ÐС£¡£¡£ ¡£¡£¡£

µ«ÒªÊ¹ÓôËÎó²î£¬£¬£¬¹¥»÷ÕßÐèҪͨ¹ýÊÜÓ°ÏìÈí¼þʹÓõÄXMPPЧÀÍÆ÷¾ÙÐÐÉí·ÝÑéÖ¤£¬£¬£¬²Å»ª½«¶ñÒâÖÆ×÷µÄXMPPÐÂÎÅ·¢Ë͵½Ä¿µÄ×°±¸¡£¡£¡£ ¡£¡£¡£

 

Cisco Jabberí§Òâ´úÂëÖ´ÐÐÎó²î£¨CVE-2021-1469£©

ÓÉÓÚÓʼþÄÚÈÝÑéÖ¤²»×¼È·£¬£¬£¬Cisco Jabber for WindowsÖб£´æÒ»¸öí§Òâ´úÂëÖ´ÐÐÎó²î£¬£¬£¬ÆäCVSSÆÀ·ÖΪ7.2¡£¡£¡£ ¡£¡£¡£ÓµÓÐÌØÊâÉèÖõÄXMPPЧÀÍÆ÷ÕÊ»§µÄ¹¥»÷Õß¿ÉÒÔͨ¹ýÏòÊÜÓ°ÏìµÄÈí¼þ·¢ËͶñÒâµÄXMPPÐÂÎÅÀ´Ê¹ÓôËÎó²î¡£¡£¡£ ¡£¡£¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷ÕßÄܹ»ÒÔÔËÐÐCisco Jabber¿Í»§¶ËÈí¼þµÄÓû§ÕÊ»§µÄȨÏÞʹӦÓóÌÐòÔÚÄ¿µÄϵͳÉÏÖ´ÐÐí§Òâ³ÌÐò£¬£¬£¬Õâ¿ÉÄܵ¼ÖÂí§Òâ´úÂëÖ´ÐС£¡£¡£ ¡£¡£¡£

 

Cisco JabberÐÅϢй¶Îó²î£¨CVE-2021-1417£©

ÓÉÓÚÓʼþÄÚÈÝÑéÖ¤²»×¼È·£¬£¬£¬Cisco Jabber for WindowsÖб£´æÒ»¸öÐÅϢй¶Îó²î£¬£¬£¬ÆäCVSSÆÀ·ÖΪ6.5¡£¡£¡£ ¡£¡£¡£¹¥»÷Õß¿ÉÒÔͨ¹ý½«¶ñÒâµÄXMPPÐÂÎÅ·¢Ë͵½Ä¿µÄϵͳÀ´Ê¹ÓôËÎó²î£¬£¬£¬ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔʹӦÓóÌÐò½«Ãô¸ÐµÄÉí·ÝÑéÖ¤ÐÅÏ¢·µ»Ø¸øÁíÒ»¸öϵͳ£¬£¬£¬ÒÔ½«ÆäÓÃÓÚ½øÒ»²½µÄ¹¥»÷¡£¡£¡£ ¡£¡£¡£

 

Cisco JabberÖ¤ÊéÑéÖ¤Îó²î£¨CVE-2021-1471£©

ÓÉÓÚÖ¤ÊéÑéÖ¤²»×¼È·£¬£¬£¬ ÊÊÓÃÓÚWindows¡¢ MacOSºÍÒÆ¶¯Æ½Ì¨µÄCisco JabberÖб£´æÖ¤ÊéÑéÖ¤Îó²î£¬£¬£¬ÆäCVSSÆÀ·ÖΪ5.6¡£¡£¡£ ¡£¡£¡£¹¥»÷Õß¿ÉÒÔͨ¹ýʹÓÃȨÏÞÍøÂçλÖÃÀ´×èµ²À´×ÔÊÜÓ°ÏìÈí¼þµÄÍøÂçÇëÇó²¢³öʾ¶ñÒâÖÆ×÷µÄÖ¤ÊéÀ´Ê¹ÓôËÎó²î£¬£¬£¬ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷ÕßÄܹ»¼ì²é»òÐÞ¸ÄCisco Jabber¿Í»§¶ËÓëЧÀÍÆ÷Ö®¼äµÄÅþÁ¬¡£¡£¡£ ¡£¡£¡£

 

Cisco Jabber¾Ü¾øÐ§ÀÍÎó²î£¨CVE-2021-1418£©

ÓÉÓÚÓʼþÄÚÈÝÑéÖ¤²»×¼È·£¬£¬£¬ÊÊÓÃÓÚWindows¡¢ MacOSºÍÒÆ¶¯Æ½Ì¨µÄCisco JabberÖб£´æ¾Ü¾øÐ§ÀÍÎó²î£¬£¬£¬ÆäCVSSÆÀ·ÖΪ4.3¡£¡£¡£ ¡£¡£¡£¹¥»÷Õß¿ÉÒÔͨ¹ýÏòÄ¿µÄϵͳ·¢ËͶñÒâµÄXMPPÐÂÎÅÀ´Ê¹ÓôËÎó²î£¬£¬£¬ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷ÕßÄܹ»Ê¹µÃÓ¦ÓóÌÐòÖÕÖ¹£¬£¬£¬´Ó¶øµ¼Ö¾ܾøÐ§ÀÍ¡£¡£¡£ ¡£¡£¡£

 

0x02 ´¦Öóͷ£½¨Òé

ÏÖÔÚÕâЩÎó²îÒѾ­ÐÞ¸´£¬£¬£¬½¨Òé²Î¿¼Ï±íʵʱ¸üУº

Cisco   Jabber for WindowsÊÜÓ°Ïì°æ±¾

ÐÞ¸´°æ±¾

12.1֮ǰ

Ǩáãµ½Àο¿°æ±¾¡£¡£¡£ ¡£¡£¡£

12.1

12.1.5

12.5

12.5.4

12.6

12.6.5

12.7

12.7.4

12.8

12.8.5

12.9

12.9.5

Cisco Jabber for MacOSÊÜÓ°Ïì°æ±¾

ÐÞ¸´°æ±¾

12.7 ¼°Ö®Ç°

Ǩáãµ½Àο¿°æ±¾¡£¡£¡£ ¡£¡£¡£

12.8

12.8.7

12.9

12.9.6

Cisco Jabber for Android ºÍ iOSÊÜÓ°Ïì°æ±¾

ÐÞ¸´°æ±¾

12.9 ¼°Ö®Ç°

Ǩáãµ½Àο¿°æ±¾¡£¡£¡£ ¡£¡£¡£

14.0

²»ÊÜÓ°Ïì¡£¡£¡£ ¡£¡£¡£

 

ÏÂÔØÁ´½Ó£º

https://software.cisco.com/download/find

 

 

0x03 ²Î¿¼Á´½Ó

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cisco-jabber-PWrTATTC

https://www.bleepingcomputer.com/news/security/cisco-addresses-critical-bug-in-windows-macos-jabber-clients/

https://securityaffairs.co/wordpress/115931/security/cisco-jabber-critical-flaw.html?

 

0x04 ʱ¼äÏß

2021-03-24  CiscoÐû²¼Ç徲ͨ¸æ

2021-03-25  VSRCÐû²¼Ç徲ͨ¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/

image.png