¡¾Îó²îͨ¸æ¡¿Juniper Networks SBRÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-0276£©
Ðû²¼Ê±¼ä 2021-07-190x00 Îó²î¸ÅÊö
CVE ID | CVE-2021-0276 | ʱ ¼ä | 2021-07-19 |
Àà ÐÍ | RCE | µÈ ¼¶ | ÑÏÖØ |
Ô¶³ÌʹÓà | ÊÇ | Ó°Ïì¹æÄ£ | |
¹¥»÷ÖØÆ¯ºó | µÍ | ¿ÉÓÃÐÔ | ¸ß |
Óû§½»»¥ | ÎÞ | ËùÐèȨÏÞ | ÎÞ |
PoC/EXP | ÔÚҰʹÓà | ·ñ |
0x01 Îó²îÏêÇé
2021Äê7ÔÂ14ÈÕ£¬£¬£¬£¬£¬Juniper NetworksÐû²¼Ç徲ͨ¸æ£¬£¬£¬£¬£¬ÆäSteel-Belted Radius Carrier Edition£¨SBRÔËÓªḚ́棩Öб£´æÒ»¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-0276£©£¬£¬£¬£¬£¬ÆäCVSSÆÀ·ÖΪ9.8¡£¡£¡£
µçÐÅÔËÓªÉÌͨ¹ýSBRÖÎÀíÓû§»á¼ûÆäÍøÂçµÄÕ½ÂÔ£¬£¬£¬£¬£¬Í¨¹ý¼¯ÖÐÓû§ÈÏÖ¤¡¢ÌṩÊʵ±µÄ»á¼û¼¶±ð²¢È·±£×ñÊØÇå¾²Õ½ÂÔ¡£¡£¡£ËüʹÔËÓªÉÌÄܹ»Ìṩ²î±ð»¯µÄЧÀÍˮƽ£¬£¬£¬£¬£¬²¢ÖÎÀíÍøÂç×ÊÔ´¡£¡£¡£
ÓÉÓÚÉèÖÃÁËEAP£¨¿ÉÀ©Õ¹ÈÏÖ¤ÐÒ飩Éí·ÝÈÏÖ¤µÄJuniper Networks SBRÖб£´æÒ»¸ö»ùÓÚ¿ÍÕ»µÄ»º³åÇøÒç³öÎó²î£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔʹÓôËÎó²î·¢ËÍÌØ¶¨µÄÊý¾Ý°ü£¬£¬£¬£¬£¬µ¼ÖÂradiusÊØ»¤Àú³ÌÍ߽⣬£¬£¬£¬£¬´Ó¶øÔì³É¾Ü¾øÐ§ÀÍ£¨DoS£©»òÔ¶³Ì´úÂëÖ´ÐУ¨RCE£©¡£¡£¡£
ÀÖ³ÉʹÓôËÎó²î½«µ¼ÖµçÐÅÌṩÉÌ£¨°üÀ¨ÎÞÏßÔËÓªÉÌ£©ÃæÁÙÍøÂçЧÀÍÖÐÖ¹»òÆäËüΣº¦¡£¡£¡£µ«¸ÃÎó²î½öÔÚʹÓÃÔöÇ¿ÐÍ EAP ÈÕÖ¾ºÍ TraceLevel ÉèÖÃΪ 2 ʱӰÏìÉèÖÃÁË EAP Éí·ÝÑéÖ¤µÄ SBR¡£¡£¡£
<SBR_Installed_Directory>/JNPRsbr/radius/radius.ini
[Logging]
LogLevel=2
TraceLevel=2
EnhancedEAPLogging = yes
Ó°Ïì¹æÄ£
8.4.1 °æ±¾£º< 8.4.1R19
8.5.0 °æ±¾£º< 8.5.0R10
8.6.0 °æ±¾£º< 8.6.0R4
0x02 ´¦Öóͷ£½¨Òé
ÏÖÔÚ´ËÎó²îÒѾÐÞ¸´£¬£¬£¬£¬£¬½¨Òéʵʱ¸üÐÂÖÁSBR Carrier 8.4.1R19¡¢8.5.0R10¡¢8.6.0R4»ò¸ü¸ß°æ±¾¡£¡£¡£
ÏÂÔØÁ´½Ó£º
https://support.juniper.net/support/downloads/
0x03 ²Î¿¼Á´½Ó
https://kb.juniper.net/InfoCenter/index?page=content&id=JSA11180&cat=SIRT_1&actp=LIST
https://threatpost.com/critical-juniper-bug-dos-rce-carrier/167869/
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-0276
0x04 ¸üа汾
°æ±¾ | ÈÕÆÚ | ÐÞ¸ÄÄÚÈÝ |
V1.0 | 2021-07-19 | Ê×´ÎÐû²¼ |
0x05 Îĵµ¸½Â¼
CNVD£ºwww.cnvd.org.cn
CNNVD£ºwww.cnnvd.org.cn
CVE£ºcve.mitre.org
NVD£ºnvd.nist.gov
CVSS£ºwww.first.org
0x06 ¹ØÓÚ¼øºÚµ£±£Íø
¹Ø×¢ÒÔϹ«Öںţ¬£¬£¬£¬£¬»ñÈ¡¸ü¶à×ÊѶ£º