Cisco Jabber¿Í»§¶Ë¶à¸öÇå¾²Îó²î
Ðû²¼Ê±¼ä 2021-03-250x00 Îó²î¸Å
Cisco JabberÊÇÒ»¸ö¼´Ê±ÐÂÎźÍweb¾Û»á×ÀÃæÓ¦ÓóÌÐò£¬£¬£¬ËüʹÓÿÉÀ©Õ¹ÐÂÎźÍ״̬ÐÒ飨XMPP£©ÔÚÓû§Ö®¼äת´ïÐÂÎÅ¡£¡£¡£¡£¡£¡£¸ÃÓ¦ÓóÌÐò»ùÓÚChromium Embedded Framework£¨CEF£©¹¹½¨£¬£¬£¬ÆäUIʹÓÃHTML¡¢CSSºÍJavaScriptµÈwebÊÖÒÕ¡£¡£¡£¡£¡£¡£
2021Äê03ÔÂ24ÈÕ£¬£¬£¬CiscoÐû²¼Ç徲ͨ¸æ£¬£¬£¬ÐÞ¸´ÁËCisco JabberÖеĶà¸öÇå¾²Îó²î¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÄܹ»Ê¹ÓÃÕâЩÎó²îÔÚϵͳÉÏÖ´ÐÐí§Òâ´úÂë¡¢»á¼ûÃô¸ÐÐÅÏ¢¡¢×èµ²Êܱ£»£»£»£»£»£»¤µÄÍøÂçÁ÷Á¿»òµ¼Ö¾ܾøÐ§ÀÍ£¨DoS£©¡£¡£¡£¡£¡£¡£
0x01 Îó²îÏêÇé
³ýÁËCVE-2021-1471Í⣬£¬£¬ÕâЩÎó²î²»»áÓ°ÏìΪPhone-only ģʽºÍTeam Messaging ģʽµÄCisco Jabber¿Í»§¶ËÈí¼þ¡£¡£¡£¡£¡£¡£±¾´Î¹ûÕæµÄÎó²îÈçÏ£º
Cisco Jabberƽ̨ | CVE ID |
Windows | CVE-2021-1411¡¢CVE-2021-1417¡¢CVE-2021-1418¡¢CVE-2021-1469¡¢ CVE-2021-1471 |
MacOS | CVE-2021-1418 ¡¢CVE-2021-1471 |
Android ºÍ iOS | CVE-2021-1418 ¡¢ CVE-2021-1471 |
Îó²îÏêÇéÈçÏ£º
Cisco Jabberí§Òâ´úÂëÖ´ÐÐÎó²î£¨CVE-2021-1411£©
ÓÉÓÚÓʼþÄÚÈÝÑéÖ¤²»×¼È·£¬£¬£¬Cisco Jabber for WindowsÖб£´æÒ»¸öí§Òâ´úÂëÖ´ÐÐÎó²î£¬£¬£¬ÆäCVSSÆÀ·ÖΪ9.9¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔͨ¹ýÏòÊÜÓ°ÏìµÄJabber¿Í»§¶ËÈí¼þ·¢ËͶñÒâµÄXMPPÐÂÎÅÀ´Ê¹ÓôËÎó²î£¬£¬£¬ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷ÕßÄܹ»ÒÔÔËÐÐCisco Jabber¿Í»§¶ËÈí¼þµÄÓû§ÕÊ»§µÄȨÏÞʹӦÓóÌÐòÔÚÄ¿µÄϵͳÉÏÖ´ÐÐí§Òâ³ÌÐò£¬£¬£¬Õâ¿ÉÄܵ¼ÖÂí§Òâ´úÂëÖ´ÐС£¡£¡£¡£¡£¡£
µ«ÒªÊ¹ÓôËÎó²î£¬£¬£¬¹¥»÷ÕßÐèҪͨ¹ýÊÜÓ°ÏìÈí¼þʹÓõÄXMPPЧÀÍÆ÷¾ÙÐÐÉí·ÝÑéÖ¤£¬£¬£¬²Å»ª½«¶ñÒâÖÆ×÷µÄXMPPÐÂÎÅ·¢Ë͵½Ä¿µÄ×°±¸¡£¡£¡£¡£¡£¡£
Cisco Jabberí§Òâ´úÂëÖ´ÐÐÎó²î£¨CVE-2021-1469£©
ÓÉÓÚÓʼþÄÚÈÝÑéÖ¤²»×¼È·£¬£¬£¬Cisco Jabber for WindowsÖб£´æÒ»¸öí§Òâ´úÂëÖ´ÐÐÎó²î£¬£¬£¬ÆäCVSSÆÀ·ÖΪ7.2¡£¡£¡£¡£¡£¡£ÓµÓÐÌØÊâÉèÖõÄXMPPЧÀÍÆ÷ÕÊ»§µÄ¹¥»÷Õß¿ÉÒÔͨ¹ýÏòÊÜÓ°ÏìµÄÈí¼þ·¢ËͶñÒâµÄXMPPÐÂÎÅÀ´Ê¹ÓôËÎó²î¡£¡£¡£¡£¡£¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷ÕßÄܹ»ÒÔÔËÐÐCisco Jabber¿Í»§¶ËÈí¼þµÄÓû§ÕÊ»§µÄȨÏÞʹӦÓóÌÐòÔÚÄ¿µÄϵͳÉÏÖ´ÐÐí§Òâ³ÌÐò£¬£¬£¬Õâ¿ÉÄܵ¼ÖÂí§Òâ´úÂëÖ´ÐС£¡£¡£¡£¡£¡£
Cisco JabberÐÅϢй¶Îó²î£¨CVE-2021-1417£©
ÓÉÓÚÓʼþÄÚÈÝÑéÖ¤²»×¼È·£¬£¬£¬Cisco Jabber for WindowsÖб£´æÒ»¸öÐÅϢй¶Îó²î£¬£¬£¬ÆäCVSSÆÀ·ÖΪ6.5¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔͨ¹ý½«¶ñÒâµÄXMPPÐÂÎÅ·¢Ë͵½Ä¿µÄϵͳÀ´Ê¹ÓôËÎó²î£¬£¬£¬ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔʹӦÓóÌÐò½«Ãô¸ÐµÄÉí·ÝÑéÖ¤ÐÅÏ¢·µ»Ø¸øÁíÒ»¸öϵͳ£¬£¬£¬ÒÔ½«ÆäÓÃÓÚ½øÒ»²½µÄ¹¥»÷¡£¡£¡£¡£¡£¡£
Cisco JabberÖ¤ÊéÑéÖ¤Îó²î£¨CVE-2021-1471£©
ÓÉÓÚÖ¤ÊéÑéÖ¤²»×¼È·£¬£¬£¬ ÊÊÓÃÓÚWindows¡¢ MacOSºÍÒÆ¶¯Æ½Ì¨µÄCisco JabberÖб£´æÖ¤ÊéÑéÖ¤Îó²î£¬£¬£¬ÆäCVSSÆÀ·ÖΪ5.6¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔͨ¹ýʹÓÃȨÏÞÍøÂçλÖÃÀ´×èµ²À´×ÔÊÜÓ°ÏìÈí¼þµÄÍøÂçÇëÇó²¢³öʾ¶ñÒâÖÆ×÷µÄÖ¤ÊéÀ´Ê¹ÓôËÎó²î£¬£¬£¬ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷ÕßÄܹ»¼ì²é»òÐÞ¸ÄCisco Jabber¿Í»§¶ËÓëЧÀÍÆ÷Ö®¼äµÄÅþÁ¬¡£¡£¡£¡£¡£¡£
Cisco Jabber¾Ü¾øÐ§ÀÍÎó²î£¨CVE-2021-1418£©
ÓÉÓÚÓʼþÄÚÈÝÑéÖ¤²»×¼È·£¬£¬£¬ÊÊÓÃÓÚWindows¡¢ MacOSºÍÒÆ¶¯Æ½Ì¨µÄCisco JabberÖб£´æ¾Ü¾øÐ§ÀÍÎó²î£¬£¬£¬ÆäCVSSÆÀ·ÖΪ4.3¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔͨ¹ýÏòÄ¿µÄϵͳ·¢ËͶñÒâµÄXMPPÐÂÎÅÀ´Ê¹ÓôËÎó²î£¬£¬£¬ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷ÕßÄܹ»Ê¹µÃÓ¦ÓóÌÐòÖÕÖ¹£¬£¬£¬´Ó¶øµ¼Ö¾ܾøÐ§ÀÍ¡£¡£¡£¡£¡£¡£
0x02 ´¦Öóͷ£½¨Òé
ÏÖÔÚÕâЩÎó²îÒѾÐÞ¸´£¬£¬£¬½¨Òé²Î¿¼Ï±íʵʱ¸üУº
Cisco Jabber for WindowsÊÜÓ°Ïì°æ±¾ | ÐÞ¸´°æ±¾ |
12.1֮ǰ | Ǩáãµ½Àο¿°æ±¾¡£¡£¡£¡£¡£¡£ |
12.1 | 12.1.5 |
12.5 | 12.5.4 |
12.6 | 12.6.5 |
12.7 | 12.7.4 |
12.8 | 12.8.5 |
12.9 | 12.9.5 |
Cisco Jabber for MacOSÊÜÓ°Ïì°æ±¾ | ÐÞ¸´°æ±¾ |
12.7 ¼°Ö®Ç° | Ǩáãµ½Àο¿°æ±¾¡£¡£¡£¡£¡£¡£ |
12.8 | 12.8.7 |
12.9 | 12.9.6 |
Cisco Jabber for Android ºÍ iOSÊÜÓ°Ïì°æ±¾ | ÐÞ¸´°æ±¾ |
12.9 ¼°Ö®Ç° | Ǩáãµ½Àο¿°æ±¾¡£¡£¡£¡£¡£¡£ |
14.0 | ²»ÊÜÓ°Ïì¡£¡£¡£¡£¡£¡£ |
ÏÂÔØÁ´½Ó£º
https://software.cisco.com/download/find
0x03 ²Î¿¼Á´½Ó
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cisco-jabber-PWrTATTC
https://www.bleepingcomputer.com/news/security/cisco-addresses-critical-bug-in-windows-macos-jabber-clients/
https://securityaffairs.co/wordpress/115931/security/cisco-jabber-critical-flaw.html?
0x04 ʱ¼äÏß
2021-03-24 CiscoÐû²¼Ç徲ͨ¸æ
2021-03-25 VSRCÐû²¼Ç徲ͨ¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/