Cisco 6Ô¶à¸öÇå¾²Îó²î

Ðû²¼Ê±¼ä 2021-06-04

0x00 Îó²î¸ÅÊö

2021Äê06ÔÂ02ÈÕ£¬£¬£¬£¬£¬CiscoÐû²¼Ç徲ͨ¸æ£¬£¬£¬£¬£¬ÐÞ¸´Á˰üÀ¨Webex Player¡¢SD-WAN Èí¼þºÍ ASR 5000 ϵÁÐÈí¼þÖеĶà¸öÇå¾²Îó²î£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔͨ¹ýʹÓÃÕâЩÎó²îÌáÉýȨÏÞ»òÔÚÊÜÓ°ÏìµÄϵͳÉÏÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£

 

0x01 Îó²îÏêÇé

image.png

 

ÔÚ±¾´ÎÐÞ¸´µÄ¸ßΣÎó²îÖУ¬£¬£¬£¬£¬CVE-2021-1503¡¢CVE-2021-1526ºÍCVE-2021-1502¶¼ÊÇCisco WebexÖеÄÄÚ´æËð»µÎó²î£¬£¬£¬£¬£¬CVSSÆÀ·Ö¾ùΪ7.8¡£¡£¡£¡£¡£¡£ÓÉÓڶԸ߼¶Â¼ÖÆÃûÌà (ARF) »ò Webex Â¼ÖÆÃûÌà (WRF) µÄ Webex Â¼ÖÆÎļþÖеÄÖµÑé֤ȱ·¦£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔͨ¹ýÁ´½Ó»òµç×ÓÓʼþ¸½¼þÏòÓû§·¢ËͶñÒâ ARF »ò WRF Îļþ²¢ÓÕµ¼Óû§·­¿ª¸ÃÎļþÀ´Ê¹ÓÃÕâЩÎó²î£¬£¬£¬£¬£¬×îÖÕµ¼Ö¹¥»÷ÕßʹÓÃÄ¿µÄÓû§µÄȨÏÞÔÚÊÜÓ°ÏìµÄϵͳÉÏÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£

CVE-2021-1528ÊÇCisco SD-WAN Èí¼þCLI ÖеÄÒ»¸öÌáȨÎó²î£¬£¬£¬£¬£¬CVSSÆÀ·ÖΪ7.8£¬£¬£¬£¬£¬ÓÉÓÚÊÜÓ°ÏìµÄÈí¼þûÓÐ׼ȷÏÞÖÆ¶ÔÌØÈ¨Àú³ÌµÄ»á¼û£¬£¬£¬£¬£¬¾­ÓÉÉí·ÝÑéÖ¤µÄÍâµØ¹¥»÷Õß¿ÉÒÔͨ¹ýŲÓÃÊÜÓ°ÏìϵͳÖеÄÌØÈ¨Àú³ÌÀ´Ê¹ÓôËÎó²î£¬£¬£¬£¬£¬×îÖÕÄܹ»Ê¹ÓÃrootÓû§µÄȨÏÞÖ´ÐвÙ×÷¡£¡£¡£¡£¡£¡£

CVE-2021-1539ºÍCVE-2021-1540ÊÇCisco ASR 5000 ϵÁÐÈí¼þ (StarOS) ÊÚȨÀú³ÌÖеÄÎó²î£¬£¬£¬£¬£¬CVSSÆÀ·Ö»®·ÖΪ8.1ºÍ6.5¡£¡£¡£¡£¡£¡£ÓÉÓڷǽ»»¥Ê½ CLI ÏÂÁîµÄ¹ýʧÊÚȨ£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔͨ¹ýÏòÊÜÓ°ÏìµÄ×°±¸·¢ËͶñÒâSSHÇëÇóÀ´Ê¹ÓôËÎó²î£¬£¬£¬£¬£¬×îÖÕ¾­ÓÉÉí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÄܹ»Èƹý TACACS ÊÚȨ»ònocli ÊÚȨ£¬£¬£¬£¬£¬²¢ÔÚÊÜÓ°ÏìµÄ×°±¸ÉÏÖ´ÐÐ CLI ÏÂÁî¡£¡£¡£¡£¡£¡£

 

CVE-ID

ÀàÐÍ

Ó°Ïì

Ó°Ïì¹æÄ£

CVE-2021-1502

Ñé֤ȱ·¦¡¢ÄÚ´æËð»µ

í§Òâ´úÂëÖ´ÐÐ

Windows   ºÍ macOS °æ£º Cisco Webex Network Recording Player¼°41.4°æ±¾Ö®Ç°µÄCisco Webex Player

CVE-2021-1503

Windows   ºÍ macOS °æ£º Cisco Webex Network Recording Player¼°41.2°æ±¾Ö®Ç°µÄCisco Webex Player

CVE-2021-1526

Windows   ºÍ MacOS °æ£º

41.5°æ±¾Ö®Ç°µÄ Cisco Webex Player

CVE-2021-1528

»á¼ûÏÞÖÆ²»µ±

ȨÏÞÌáÉý

ÔËÐÐCisco¡¡SD-WAN Èí¼þ°æ±¾20.4¡¢20.5µÄÒÔϲúÆ·£º

SD-WAN   vBond Orchestrator Software

SD-WAN   vEdge Cloud Routers

SD-WAN   vEdge Routers

SD-WAN   vManage Software

SD-WAN   vSmart Controller Software

CVE-2021-1539

ÊÚȨ¹ýʧ

TACACS   ÊÚÈ¨ÈÆ¹ý

ÔËÐÐCisco¡¡StarOS °æ±¾£¨21.16֮ǰ°æ±¾¡¢21.16¡¢21.17¡¢21.18¡¢21.19¡¢21.19.n¡¢21.20£©µÄÒÔÏÂCisco²úÆ·£º

ASR   5000 Series Aggregation Services Routers

Virtualized   Packet Core ¨C Distributed Instance (VPC-DI)

Virtualized   Packet Core ¨C Single Instance (VPC-SI)

CVE-2021-1540

nocli   ÊÚÈ¨ÈÆ¹ý

 

0x02 ´¦Öóͷ£½¨Òé

ÏÖÔÚCiscoÒѾ­ÐÞ¸´ÁËÕâЩÎó²î£¬£¬£¬£¬£¬½¨Òé²Î¿¼¹Ù·½Ç徲ͨ¸æÊµÊ±Éý¼¶¸üУº

²Î¿¼ÅþÁ¬£º

https://tools.cisco.com/security/center/publicationListing.x

 

0x03 ²Î¿¼Á´½Ó

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asr5k-autho-bypass-mJDF5S7n

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-webex-player-kOf8zVT

https://securityaffairs.co/wordpress/118564/security/cisco-webex-player-sd-wan-asr-5000-flaws.html?

 

0x04 ʱ¼äÏß

2021-06-02  CiscoÐû²¼Ç徲ͨ¸æ

2021-06-04  VSRCÐû²¼Ç徲ͨ¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/

image.png