Cisco 6Ô¶à¸öÄþ¾²Â©¶´

Ðû²¼Ê±¼ä 2021-06-04

0x00 ©¶´¸ÅÊö

2021Äê06ÔÂ02ÈÕ£¬CiscoÐû²¼Äþ¾²Í¨¸æ£¬ÐÞ¸´Á˰üÂÞWebex Player¡¢SD-WAN Èí¼þºÍ ASR 5000 ϵÁÐÈí¼þÖеĶà¸öÄþ¾²Â©¶´£¬¹¥»÷Õß¿ÉÒÔͨ¹ýÀûÓÃÕâЩ©¶´ÌáÉýȨÏÞ»òÔÚÊÜÓ°ÏìµÄϵͳÉÏÖ´ÐÐÈÎÒâ´úÂë¡£

 

0x01 ©¶´ÏêÇé

image.png

 

ÔÚ±¾´ÎÐÞ¸´µÄ¸ßΣ©¶´ÖУ¬CVE-2021-1503¡¢CVE-2021-1526ºÍCVE-2021-1502¶¼ÊÇCisco WebexÖеÄÄÚ´æËð»µÂ©¶´£¬CVSSÆÀ·Ö¾ùΪ7.8¡£ÓÉÓڶԸ߼¶Â¼ÖƸñʽ (ARF) »ò Webex Â¼ÖÆ¸ñʽ (WRF) µÄ Webex Â¼ÖÆÎļþÖеÄÖµÑéÖ¤²»×㣬¹¥»÷Õß¿ÉÒÔͨ¹ýÁ´½Ó»òµç×ÓÓʼþ¸½¼þÏòÓû§·¢ËͶñÒâ ARF »ò WRF Îļþ²¢ÓÕµ¼Óû§´ò¿ª¸ÃÎļþÀ´ÀûÓÃÕâЩ©¶´£¬×îÖÕµ¼Ö¹¥»÷ÕßʹÓÃÄ¿±êÓû§µÄȨÏÞÔÚÊÜÓ°ÏìµÄϵͳÉÏÖ´ÐÐÈÎÒâ´úÂë¡£

CVE-2021-1528ÊÇCisco SD-WAN Èí¼þCLI ÖеÄÒ»¸öÌáȨ©¶´£¬CVSSÆÀ·ÖΪ7.8£¬ÓÉÓÚÊÜÓ°ÏìµÄÈí¼þûÓÐÕýÈ·ÏÞÖÆ¶ÔÌØÈ¨½ø³ÌµÄ·ÃÎÊ£¬¾­¹ýÉí·ÝÑéÖ¤µÄµ±µØ¹¥»÷Õß¿ÉÒÔͨ¹ýµ÷ÓÃÊÜÓ°ÏìϵͳÖеÄÌØÈ¨½ø³ÌÀ´ÀûÓôË©¶´£¬×îÖÕÄܹ»Ê¹ÓÃrootÓû§µÄȨÏÞÖ´ÐвÙ×÷¡£

CVE-2021-1539ºÍCVE-2021-1540ÊÇCisco ASR 5000 ϵÁÐÈí¼þ (StarOS) ÊÚȨ¹ý³ÌÖеÄ©¶´£¬CVSSÆÀ·Ö·Ö±ðΪ8.1ºÍ6.5¡£ÓÉÓڷǽ»»¥Ê½ CLI ÃüÁîµÄ´íÎóÊÚȨ£¬¹¥»÷Õß¿ÉÒÔͨ¹ýÏòÊÜÓ°ÏìµÄÉ豸·¢ËͶñÒâSSHÇëÇóÀ´ÀûÓôË©¶´£¬×îÖÕ¾­¹ýÉí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÄܹ»Èƹý TACACS ÊÚȨ»ònocli ÊÚȨ£¬²¢ÔÚÊÜÓ°ÏìµÄÉ豸ÉÏÖ´ÐÐ CLI ÃüÁî¡£

 

CVE-ID

ÀàÐÍ

Ó°Ïì

Ó°Ï췶Χ

CVE-2021-1502

ÑéÖ¤²»×ã¡¢ÄÚ´æËð»µ

ÈÎÒâ´úÂëÖ´ÐÐ

Windows   ºÍ macOS °æ£º Cisco Webex Network Recording Player¼°41.4°æ±¾Ö®Ç°µÄCisco Webex Player

CVE-2021-1503

Windows   ºÍ macOS °æ£º Cisco Webex Network Recording Player¼°41.2°æ±¾Ö®Ç°µÄCisco Webex Player

CVE-2021-1526

Windows   ºÍ MacOS °æ£º

41.5°æ±¾Ö®Ç°µÄ Cisco Webex Player

CVE-2021-1528

·ÃÎÊÏÞÖÆ²»Í×

ȨÏÞÌáÉý

ÔËÐÐCisco¡¡SD-WAN Èí¼þ°æ±¾20.4¡¢20.5µÄÒÔϲúÎ

SD-WAN   vBond Orchestrator Software

SD-WAN   vEdge Cloud Routers

SD-WAN   vEdge Routers

SD-WAN   vManage Software

SD-WAN   vSmart Controller Software

CVE-2021-1539

ÊÚȨ´íÎó

TACACS   ÊÚÈ¨ÈÆ¹ý

ÔËÐÐCisco¡¡StarOS °æ±¾£¨21.16֮ǰ°æ±¾¡¢21.16¡¢21.17¡¢21.18¡¢21.19¡¢21.19.n¡¢21.20£©µÄÒÔÏÂCisco²úÎ

ASR   5000 Series Aggregation Services Routers

Virtualized   Packet Core ¨C Distributed Instance (VPC-DI)

Virtualized   Packet Core ¨C Single Instance (VPC-SI)

CVE-2021-1540

nocli   ÊÚÈ¨ÈÆ¹ý

 

0x02 ´¦Öý¨Òé

ĿǰCiscoÒѾ­ÐÞ¸´ÁËÕâЩ©¶´£¬½¨Òé²Î¿¼¹Ù·½Äþ¾²Í¨¸æ¼°Ê±Éý¼¶¸üУº

²Î¿¼Á¬½Ó£º

https://tools.cisco.com/security/center/publicationListing.x

 

0x03 ²Î¿¼Á´½Ó

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asr5k-autho-bypass-mJDF5S7n

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-webex-player-kOf8zVT

https://securityaffairs.co/wordpress/118564/security/cisco-webex-player-sd-wan-asr-5000-flaws.html?

 

0x04 ʱ¼äÏß

2021-06-02  CiscoÐû²¼Äþ¾²Í¨¸æ

2021-06-04  VSRCÐû²¼Äþ¾²Í¨¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/

image.png