Cisco SD-WAN vManage & Small Business Routers¶à¸öÄþ¾²Â©¶´

Ðû²¼Ê±¼ä 2021-04-08

0x00 ©¶´¸ÅÊö

2021Äê04ÔÂ07ÈÕ£¬CiscoÐû²¼Äþ¾²Í¨¸æ£¬ÐÞ¸´ÁËCisco SD-WAN vManageÈí¼þÖеÄ3¸öÄþ¾²Â©¶´ÒÔ¼°CiscoСÐÍÆóÒµRV110W¡¢RV130¡¢RV130WºÍRV215W·ÓÉÆ÷ÖеÄ1¸öÔ¶³Ì´úÂëÖ´ÐЩ¶´£¬¾­¹ýÉí·ÝÑéÖ¤»òδ¾­ÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔͨ¹ýÀûÓÃÕâЩ©¶´ÌáÉýȨÏÞ»òÔÚϵͳÉÏÖ´ÐÐÈÎÒâ´úÂë¡£

 

0x01 ©¶´ÏêÇé

image.png

 

©¶´ÏêÇéÈçÏ£º

Cisco SD-WAN vManage»º³åÇøÒç³ö©¶´£¨CVE-2021-1479£©

¸Ã©¶´´æÔÚÓÚCisco SD-WAN vManageÈí¼þµÄÔ¶³Ì¹ÜÀí×é¼þÖУ¬ÆäCVSSÆÀ·Ö9.8¡£

ÓÉÓÚ¶ÔÓû§µÄÊäÈëÑéÖ¤²»ÕýÈ·£¬Î´¾­ÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔͨ¹ýÏòÒ×Êܹ¥»÷µÄ×é¼þ·¢ËͶñÒâµÄÁ¬½ÓÇëÇóÀ´ÀûÓôË©¶´£¬Õâ¿ÉÄܵ¼Ö»º³åÇøÒç³ö£¬ÀÖ³ÉÀûÓôË©¶´µÄ¹¥»÷ÕßÄܹ»ÒÔrootȨÏÞÔÚϵͳÉÏÖ´ÐÐÈÎÒâ´úÂë¡£

 

Cisco SD-WAN vManageȨÏÞÌáÉý©¶´£¨CVE-2021-1137£©

¸Ã©¶´´æÔÚÓÚCisco SD-WANÈí¼þµÄÓû§¹ÜÀí¹¦Ð§ÖУ¬ÆäCVSSÆÀ·Ö7.8¡£

ÓÉÓÚÊäÈëÑéÖ¤²»×㣬ӵÓÐÔÚvManageϵͳÉÏÌí¼ÓÐÂÓû§»ò×éµÄȨÏ޵ľ­¹ýÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔͨ¹ýÐÞ¸ÄÓû§ÕË»§À´ÀûÓôË©¶´¡£ÀÖ³ÉÀûÓôË©¶´µÄ¹¥»÷Õß¿ÉÒÔ»ñµÃϵͳµÄrootȨÏÞ¡£

 

Cisco SD-WAN vManageȨÏÞÌáÉý©¶´£¨CVE-2021-1480£©

¸Ã©¶´´æÔÚÓÚCisco SD-WANÈí¼þµÄϵͳÎļþ´«Ê书ЧÖУ¬ÆäCVSSÆÀ·Ö7.8¡£

ÓÉÓÚ¶ÔϵͳÎļþ´«Ê书ЧµÄÊäÈëÑéÖ¤²»ÕýÈ·£¬¾­¹ýÉí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔͨ¹ýÏòÒ×Êܹ¥»÷µÄϵͳ·¢ËͶñÒâÇëÇóÀ´ÀûÓôË©¶´£¬ÀÖ³ÉÀûÓôË©¶´µÄ¹¥»÷Õß¿ÉÒÔÁýÕÖÈÎÒâÎļþ²¢ÒÔrootÓû§È¨ÏÞÐÞ¸Äϵͳ¡£

 

Cisco Small Business routersÔ¶³Ì´úÂëÖ´ÐЩ¶´£¨CVE-2021-1459£©

¸Ã©¶´´æÔÚÓÚCisco Small Business RV110W¡¢RV130¡¢RV130WºÍRV215W·ÓÉÆ÷»ùÓÚWebµÄ¹ÜÀí½çÃæÖУ¬ÆäCVSSÆÀ·ÖΪ9.8¡£

ÓÉÓÚδÕýÈ·ÑéÖ¤Óû§ÌṩµÄÊäÈ룬¹¥»÷Õß¿ÉÒÔͨ¹ýÏòÄ¿±êÉ豸·¢ËͶñÒâµÄHTTPÇëÇóÀ´ÀûÓôË©¶´£¬ÀÖ³ÉÀûÓôË©¶´µÄ¹¥»÷ÕßÄܹ»ÒÔroot Óû§Éí·ÝÔÚÊÜÓ°ÏìÉ豸ϵͳÉÏÖ´ÐÐÈÎÒâ´úÂë ¡£


Ó°Ï췶Χ

´Ë©¶´Ó°ÏìÒÔÏÂCisco Small Business RVϵÁзÓÉÆ÷£º

RV110W Wireless-N VPN Firewall

RV130 VPN Router

RV130W Wireless-N Multifunction VPN Router

RV215W Wireless-N VPN Router

 

 

0x02 ´¦Öý¨Òé

ĿǰCisco Small Business RV110W¡¢RV130¡¢RV130WºÍRV215W·ÓÉÆ÷ÒÑÍ£Ö¹Ö§³Ö£¬¹Ù·½½«²»»áÔÙÐû²¼Äþ¾²¸üУ¬½¨ÒéÇ¨ÒÆµ½Cisco Small Business RV132W¡¢RV160»òRV160W·ÓÉÆ÷¡£Cisco SD-WAN vManage ÖеÄ3¸ö©¶´ÒѾ­ÐÞ¸´£¬½¨Òé²Î¿¼ÏÂ±í¼°Ê±¸üУº

Cisco SD-WAN vManageÊÜÓ°Ïì°æ±¾

ÐÞ¸´°æ±¾

ËùÓЩ¶´µÄµÚÒ»¸öÐÞ¸´°æ±¾

18.4¼°¸üÔç°æ±¾

Ç¨ÒÆµ½Àι̰汾¡£

Ç¨ÒÆµ½Àι̰汾¡£

19.2

19.2.4

19.2.4

19.3

Ç¨ÒÆµ½Àι̰汾¡£

Ç¨ÒÆµ½Àι̰汾¡£

20.1

Ç¨ÒÆµ½Àι̰汾¡£

Ç¨ÒÆµ½Àι̰汾¡£

20.3

20.3.3

20.3.3

20.4

20.4.1

20.4.1

 

ÏÂÔØÁ´½Ó£º

https://software.cisco.com/download/find

 

 

0x03 ²Î¿¼Á´½Ó

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-vmanage-YuTVWqy

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-rv-rce-q3rxHnvm

https://www.bleepingcomputer.com/news/security/cisco-fixes-bug-allowing-remote-code-execution-with-root-privileges/

 

0x04 ʱ¼äÏß

2021-04-07  CiscoÐû²¼Äþ¾²Í¨¸æ

2021-04-08  VSRCÐû²¼Äþ¾²Í¨¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/

image.png