¡¾Â©¶´Í¨¸æ¡¿Cisco Enterprise NFVISÉí·ÝÑéÖ¤ÈÆ¹ý©¶´ (CVE-2021-34746)
Ðû²¼Ê±¼ä 2021-09-020x00 ©¶´¸ÅÊö
CVE ID | CVE-2021-34746 | ʱ ¼ä | 2021-09-01 |
Àà ÐÍ | Éí·ÝÑéÖ¤ÈÆ¹ý | µÈ ¼¶ | ÑÏÖØ |
Ô¶³ÌÀûÓà | ÊÇ | Ó°Ï췶Χ | |
¹¥»÷ÅÓ´ó¶È | µÍ | ¿ÉÓÃÐÔ | ¸ß |
Óû§½»»¥ | ÎÞ | ËùÐèȨÏÞ | ÎÞ |
PoC/EXP | ÒѹûÈ» | ÔÚÒ°ÀûÓà | ·ñ |
0x01 ©¶´ÏêÇé
2021Äê9ÔÂ1ÈÕ£¬CiscoÐû²¼Äþ¾²Í¨¸æ£¬ÐÞ¸´ÁËÆäÆóÒµ NFV »ù´¡ÉèÊ©Èí¼þ (NFVIS) µÄ TACACS+ÈÏÖ¤¡¢ÊÚȨºÍ¼Æ·Ñ (AAA) ¹¦Ð§ÖеÄÒ»¸öÉí·ÝÑéÖ¤ÈÆ¹ý©¶´£¨CVE-2021-34746£©£¬¸Ã©¶´µÄCVSSv3ÆÀ·ÖΪ9.8¡£
ÓÉÓÚ¶Ôͨ±¨¸øÈÏÖ¤½Å±¾µÄÓû§ÊäÈëµÄÑéÖ¤²»ÍêÕû£¬Ô¶³Ì¹¥»÷Õß¿ÉÒÔͨ¹ýÔÚÈÏÖ¤ÇëÇóÖÐ×¢Èë²ÎÊýÀ´ÀûÓôË©¶´¡£ÀÖ³ÉÀûÓôË©¶´µÄ¹¥»÷Õß¿ÉÒÔÈÆ¹ýÈÏÖ¤£¬²¢ÒÔ¹ÜÀíÔ±Éí·ÝµÇ¼ÊÜÓ°ÏìµÄÉ豸¡£
˼¿Æ²úÎïÄþ¾²Ê¼þÏìÓ¦ÍŶÓÌåÏÖ£¬ÒÑÓÐÊÊÓÃÓÚ´Ë©¶´µÄPoC/EXP£¬Ä¿Ç°ÔÝδ·¢ÏÖ¶ñÒâÀûÓá£
Ó°Ï췶Χ
Èç¹ûÅäÖÃÁËTACACSÍⲿÈÏÖ¤ÒªÁ죬´Ë©¶´»áÓ°ÏìCisco Enterprise NFVIS °æ±¾4.5.1¡£
×¢£º½öʹÓÃRADIUS»òµ±µØÈÏÖ¤µÄÅäÖò»ÊÜÓ°Ïì¡£
0x02 ´¦Öý¨Òé
ĿǰCiscoÒѾÐÞ¸´ÁË´Ë©¶´£¬½¨ÒéÊÜÓ°ÏìÓû§¼°Ê±Éý¼¶¸üе½Cisco Enterprise NFVIS °æ±¾ 4.6.1 »ò¸ü¸ß°æ±¾¡£
ÏÂÔØÁ´½Ó£º
https://software.cisco.com/download/home
È·¶¨ÊÇ·ñÆôÓÃTACACSÍⲿÈÏÖ¤
1.Ҫȷ¶¨É豸ÉÏÊÇ·ñÆôÓÃÁË TACACS ÍⲿÈÏÖ¤¹¦Ð§£¬ÇëʹÓà show running-config tacacs-server ÃüÁî¡£ÒÔÏÂʾÀýÏÔʾÁ˵±TACACSÍⲿÈÏÖ¤±»ÆôÓÃʱ£¬Cisco Enterprise NFVISÉÏshow running-config tacacs-serverÃüÁîµÄÊä³ö£º
nfvis# show running-config tacacs-server
tacacs-server host 192.168.1.1
key 0
shared-secret "example!23"
admin-priv 15
oper-priv 1
!
nfvis#
Èç¹ûshow running-config tacacs-server ÃüÁîµÄÊä³öΪNo entries found£¬ÔòδÆôÓà TACACS ÍⲿÈÏÖ¤¹¦Ð§¡£
2.ͨ¹ýGUI¼ì²éÅäÖá£Ñ¡ÔñÅäÖà > Ö÷»ú > Äþ¾² > Óû§ºÍ½ÇÉ«¡£Èç¹ûÔÚÍⲿÈÏ֤Ͻç˵ÁËTACACS+Ö÷»ú£¬ÄÇô¸ÃÉ豸ÈÝÒ×Êܵ½´Ë©¶´µÄÓ°Ïì¡£
0x03 ²Î¿¼Á´½Ó
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-nfvis-g2DMVVh
https://www.cisco.com/
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-34746
0x04 ¸üа汾
°æ±¾ | ÈÕÆÚ | ÐÞ¸ÄÄÚÈÝ |
V1.0 | 2021-09-02 | Ê×´ÎÐû²¼ |
0x05 Îĵµ¸½Â¼
CNVD£ºwww.cnvd.org.cn
CNNVD£ºwww.cnnvd.org.cn
CVE£ºcve.mitre.org
CVSS£ºwww.first.org
NVD£ºnvd.nist.gov
0x06 ¹ØÓÚ¶¶È¦Îª¶Ä¶øÉú
¹Ø×¢ÒÔϹ«Öںţ¬»ñÈ¡¸ü¶à×ÊѶ£º