¡¾Â©¶´Í¨¸æ¡¿ThroughTek Kalay P2P SDKÔ¶³Ì´úÂëÖ´ÐЩ¶´ (CVE-2021-28372)
Ðû²¼Ê±¼ä 2021-08-180x00 ©¶´¸ÅÊö
CVE ID | CVE-2021-28372 | ʱ ¼ä | 2021-08-18 |
Àà ÐÍ | RCE | µÈ ¼¶ | ÑÏÖØ |
Ô¶³ÌÀûÓà | ÊÇ | Ó°Ï췶Χ | |
¹¥»÷ÅÓ´ó¶È | µÍ | ¿ÉÓÃÐÔ | ¸ß |
Óû§½»»¥ | ÊÇ | ËùÐèȨÏÞ | ÎÞ |
PoC/EXP | ÒѹûÈ» | ÔÚÒ°ÀûÓà |
0x01 ©¶´ÏêÇé
2021Äê8ÔÂ17ÈÕ£¬Mandiant(FireEye)ÓëÃÀ¹úÍøÂçÄþ¾²ºÍ»ù´¡ÉèÊ©Äþ¾²¾Ö(CISA) ºÏ×÷Åû¶ÁËÒ»¸öÑÏÖØµÄÎïÁªÍøÄþ¾²Â©¶´(CVE-2021-28372, CVSSv3ÆÀ·ÖΪ9.6) ¡£¸Ã©¶´ÎªThroughTek Kalay P2P SDKÖеÄÔ¶³Ì´úÂëÖ´ÐЩ¶´,Ó°ÏìÁËÊý°ÙÍòʹÓÃThroughTek Kalay IoT ÔÆÆ½Ì¨Á¬½ÓµÄÎïÁªÍøÉ豸¡£
¸Ã©¶´ÓÉ Mandiant ºì¶ÓµÄÑо¿ÈËÔ±ÓÚ 2020 ÄêÄ©·¢ÏÖ£¬Ô¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓôË©¶´ÈëÇÖÎïÁªÍøÉ豸¡£ThroughTekÌåÏÖ,Æäƽ̨ÉÏÓÐÁè¼Ý8300Íò¸ö»îÔ¾É豸ºÍÁè¼Ý11ÒÚµÄÔÂÁ¬½Ó,Æä¿Í»§°üÂÞÎïÁªÍøÉãÏñÍ·ÖÆÔìÉÌ¡¢ÖÇÄÜÓ¤¶ù¼àÊÓÆ÷ºÍÊý×ÖÊÓÆµÂ¼Ïñ»ú£¨DVR£©²úÎï¡£
ÀÖ³ÉÀûÓôË©¶´µÄÔ¶³Ì¹¥»÷ÕßÄܹ»ÊÕÌýʵʱÒôƵ¡¢Ô¢Ä¿ÊµÊ±ÊÓÆµÊý¾Ý¡¢ÆÆ»µÉ豸ƾ¾Ý¡¢Ô¶³Ì¿ØÖÆÊÜÓ°ÏìÉ豸²¢Ö´ÐÐÆäËü²Ù×÷¡£¹¥»÷ËùÐèµÄΨһÐÅÏ¢ÊÇÄ¿±êÓû§µÄKalayΨһ±êʶ·û£¨UID£©,¸Ã±êʶ·û¿ÉÒÔͨ¹ýÉç»á¹¤³Ì»ñµÃ¡£´ËÍâ,¹¥»÷Õß»¹¿ÉÒÔʹÓà RPC£¨Ô¶³Ì¹ý³Ìµ÷Ó㩹¦Ð§À´ÍêÈ«½Ó¹ÜÉ豸¡£
KalayÐÒéÊÇÒÔÈí¼þ¿ª·¢¹¤¾ß°ü£¨SDK£©µÄÐÎʽʵÏֵģ¬Ëü±»ÄÚÖÃÓÚ¿Í»§¶ËÈí¼þ£¨ÈçÒÆ¶¯»ò×ÀÃæÓ¦Ó÷¨Ê½£©ºÍÁªÍøµÄÎïÁªÍøÉ豸£¬ÈçÖÇÄÜÏà»úÖС£ÓÉÓÚKalayÐÒéÊÇÓÉÔʼÉè±¸ÖÆÔìÉÌ£¨OEM£©ºÍ¾ÏúÉÌÔÚÉ豸µ½´ïÏû·ÑÕß֮ǰ¼¯³ÉµÄ£¬Òò´ËÔÝʱÎÞ·¨È·¶¨ÊÜ´Ë©¶´Ó°ÏìµÄ²úÎïºÍ¹«Ë¾µÄÍêÕûÃûµ¥¡£
Ó°Ï췶Χ
ÒÔϰ汾µÄ Kalay P2P SDKÊÜ´Ë©¶´Ó°Ï죺
l 3.1.5 ¼°¸üÔç°æ±¾
l ´øÓÐ nossl ±êÇ©µÄ SDK °æ±¾
l ²»Ê¹Óà AuthKey ½øÐÐ IOTC Á¬½ÓµÄÉ豸¹Ì¼þ
l ʹÓà AVAPI Ä£¿é¶ø²»ÆôÓà DTLS »úÖÆµÄÉ豸¹Ì¼þ
l ʹÓà P2PTunnel »ò RDT Ä£¿éµÄÉ豸¹Ì¼þ
0x02 ´¦Öý¨Òé
ĿǰThroughTek ÒÑÐû²¼ÁË SDK ¸üÐÂ,½¨Òé²Î¿¼ÒÔÏ·½Ê½¼°Ê±ÐÞ¸´»òÉý¼¶:
l Èç¹ûʹÓÃThroughTek SDK v3.1.10¼°ÒÔÉϰ汾£¬Ç뿪ÆôAuthKeyºÍDTLS£»
l Èç¹ûʹÓÃv3.1.10֮ǰµÄ¾É°æ±¾ThroughTek SDK£¬Ç뽫¿âÉý¼¶µ½v3.3.1.0»òv3.4.2.0£¬²¢ÆôÓÃAuthKeyºÍDTLS¡£
ͨÓÃÄþ¾²½¨Òé
l ¾¡Á¿¼õÉÙËùÓпØÖÆÏµÍ³É豸»òϵͳµÄÍøÂç̻¶Çé¿ö£¬²¢È·±£ËüÃDz»ÄÜ´Ó»¥ÁªÍø·ÃÎÊ¡£
l ½«¿ØÖÆÏµÍ³ÍøÂçºÍÔ¶³ÌÉ豸ÖÃÓÚ·À»ðǽ֮ºó£¬²¢½«ÆäÓëÉÌÒµÍøÂç¸ôÀë¡£
l µ±ÐèÒªÔ¶³Ì·ÃÎÊʱʹÓÃÄþ¾²µÄÒªÁ죬ÈçÐéÄâרÓÃÍøÂ磨VPN£©£¬²¢È·±£VPNÊÇ×îа汾¡£
ÏÂÔØÁ´½Ó£º
https://www.throughtek.com/please-update-the-sdk-version-to-minimize-the-risk-of-sensitive-information-being-accessed-by-unauthorized-third-party/
0x03 ²Î¿¼Á´½Ó
https://www.fireeye.com/blog/threat-research/2021/08/mandiant-discloses-critical-vulnerability-affecting-iot-devices.html
https://us-cert.cisa.gov/ics/advisories/icsa-21-229-01
https://securityaffairs.co/wordpress/121226/hacking/kalay-cloud-platform-critical-flaw.html?
0x04 ¸üа汾
°æ±¾ | ÈÕÆÚ | ÐÞ¸ÄÄÚÈÝ |
V1.0 | 2021-08-18 | Ê×´ÎÐû²¼ |
0x05 Îĵµ¸½Â¼
CNVD£ºwww.cnvd.org.cn
CNNVD£ºwww.cnnvd.org.cn
CVE£ºcve.mitre.org
NVD£ºnvd.nist.gov
CVSS£ºwww.first.org
0x06 ¹ØÓÚ¶¶È¦Îª¶Ä¶øÉú
¹Ø×¢ÒÔϹ«Öںţ¬»ñÈ¡¸ü¶à×ÊѶ£º