¡¾Îó²îͨ¸æ¡¿ Cisco Jabber12Ô¶à¸öÇå¾²Îó²î

Ðû²¼Ê±¼ä 2020-12-11

0x00 Îó²î¸ÅÊö

²úÆ·Ãû³Æ

CVE ID

Àà ÐÍ

Îó²îÆ·¼¶

Ô¶³ÌʹÓÃ

 Cisco Jabber

CVE-2020-26085

RCE

ÑÏÖØ

ÊÇ

CVE-2020-27127

δÊÚȨ»á¼û

ÖÐΣ

ÊÇ

CVE-2020-27132

ÐÅϢй¶

ÖÐΣ

ÊÇ

CVE-2020-27133

ÏÂÁî×¢Èë

¸ßΣ

ÊÇ

CVE-2020-27134

¾ç±¾×¢Èë

¸ßΣ

ÊÇ

0x01 Îó²îÏêÇé

 

image.png

 

Cisco JabberÊÇÒ»¸ö¼´Ê±ÐÂÎźÍweb¾Û»á×ÀÃæÓ¦ÓóÌÐò£¬£¬£¬£¬£¬ £¬ËüʹÓÿÉÀ©Õ¹ÐÂÎźÍ״̬ЭÒ飨XMPP£©ÔÚÓû§Ö®¼äת´ïÐÂÎÅ¡£¡£¡£¡£¡£¡£¡£¸ÃÓ¦ÓóÌÐò»ùÓÚChromium Embedded Framework£¨CEF£©¹¹½¨£¬£¬£¬£¬£¬ £¬ÆäUIʹÓÃHTML¡¢CSSºÍJavaScriptµÈwebÊÖÒÕ¡£¡£¡£¡£¡£¡£¡£

2020Äê12ÔÂ10ÈÕ£¬£¬£¬£¬£¬ £¬CiscoÐû²¼Ç徲ͨ¸æ£¬£¬£¬£¬£¬ £¬JabberÖб£´æ¶à¸öÇå¾²Îó²î£¨CVE-2020-26085¡¢CVE-2020-27127¡¢CVE-2020-27132¡¢CVE-2020-27133ºÍCVE-2020-27134£©¡£¡£¡£¡£¡£¡£¡£ÕâЩÎó²î²¢²»Ï໥ÒÀÀµ£¬£¬£¬£¬£¬ £¬¹¥»÷ÕßÄܹ»Ê¹ÓÃËüÃÇÔÚϵͳÉÏÖ´ÐÐí§Òâ´úÂ룬£¬£¬£¬£¬ £¬»òÇÔÈ¡Ãô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£

ҪʹÓÃCVE-2020-26085ºÍCVE-2020-27134ÕâÁ½¸öÐÂÎÅ´¦Öóͷ£Îó²î£¬£¬£¬£¬£¬ £¬¹¥»÷ÕßÐèÒª»á¼ûͳһXMPPÓò»òʹÓÃÆäËüÒªÁìÏòCisco Jabber¿Í»§¶Ë·¢ËÍ¿ÉÀ©Õ¹ÐÂÎźÍ״̬ЭÒ飨XMPP£©ÐÂÎÅ¡£¡£¡£¡£¡£¡£¡£´¦ÓÚphone-onlyģʽÏÂÇÒδÆôÓÃXMPPÐÂÎÅЧÀ͵ÄCisco Jabber½ûÖ¹Ò×Êܵ½¹¥»÷¡£¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬ £¬ÈôÊǽ«Cisco JabberÉèÖÃΪʹÓÃXMPPÐÂÎÅת´ïÒÔÍâµÄÆäËüÐÂÎÅת´ïЧÀÍ£¬£¬£¬£¬£¬ £¬ÔòÎó²îÎÞ·¨Ê¹Óᣡ£¡£¡£¡£¡£¡£

Îó²îÏêÇéÈçÏ£º

Cisco JabberÐÂÎÅ´¦Öóͷ£ÖеÄí§Òâ´úÂëÖ´ÐÐÎó²î£¨CVE-2020-26085£©

¸ÃÎó²îÊÇÓʼþÄÚÈÝÑéÖ¤²»×¼È·µ¼Öµģ¬£¬£¬£¬£¬ £¬ÆäCVSSÆÀ·Ö9.9¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔͨ¹ýÏòÊÜÓ°ÏìµÄJabber¿Í»§¶Ë·¢ËͶñÒâµÄXMPPÐÂÎÅÀ´Ê¹ÓôËÎó²î¡£¡£¡£¡£¡£¡£¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷ÕßÄܹ»ÒÔÔËÐÐCisco Jabber¿Í»§¶ËµÄÕË»§È¨ÏÞÔÚÄ¿µÄϵͳÉÏÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¡£

Ó°Ïì¹æÄ££º

Windows °æCisco Jabber

MacOS°æCisco Jabber

 

Cisco Jabber for Windows×Ô½ç˵ЭÒé´¦Öóͷ£³ÌÐòδÊÚȨ»á¼ûÎó²î£¨CVE-2020-27127£©

¸ÃÎó²îÊǶÔJabberЭÒé´¦Öóͷ£³ÌÐòµÄÊäÈë´¦Öóͷ£²»µ±µ¼Öµģ¬£¬£¬£¬£¬ £¬ÆäCVSSÆÀ·Ö4.3¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔͨ¹ýÖ¸µ¼Ä¿µÄÓû§µ¥»÷µç×ÓÓʼþ»òÆäËüÐÂÎÅת´ïƽ̨·¢Ë͵ÄÐÂÎÅÖеÄÁ´½ÓÀ´Ê¹ÓôËÎó²î¡£¡£¡£¡£¡£¡£¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔÏòCisco Jabber¿Í»§¶Ë·¢ËÍí§ÒâÏÂÁ£¬£¬£¬£¬ £¬´Ó¶ø¿ÉÄÜʹ¹¥»÷ÕßÐÞ¸ÄÓ¦ÓóÌÐòÉèÖᣡ£¡£¡£¡£¡£¡£

Ó°Ïì¹æÄ££º

Windows °æCisco Jabber

 

Cisco JabberÐÅϢй¶Îó²î£¨VE-2020-27132£©

¸ÃÎó²îÊÇÓʼþÄÚÈÝÑéÖ¤²»×¼È·µ¼Öµģ¬£¬£¬£¬£¬ £¬ÆäCVSSÆÀ·Ö6.5¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔͨ¹ýÏòÄ¿µÄϵͳ·¢ËͶñÒâÐÂÎÅÀ´Ê¹ÓôËÎó²î¡£¡£¡£¡£¡£¡£¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔʹJabber½«Éí·ÝÑéÖ¤µÈÃô¸ÐÐÅÏ¢·µ»Ø¸øÁíÒ»¸öϵͳ£¬£¬£¬£¬£¬ £¬ÒÔ±ãÓÚ½øÒ»²½¹¥»÷¡£¡£¡£¡£¡£¡£¡£

Ó°Ïì¹æÄ££º

Windows °æCisco Jabber

MacOS°æCisco Jabber

 

Cisco Jabber for Windows×Ô½ç˵ЭÒé´¦Öóͷ£³ÌÐòÏÂÁî×¢ÈëÎó²î£¨CVE-2020-27133£©

¸ÃÎó²îÊǶÔJabberЭÒé´¦Öóͷ£³ÌÐòµÄÊäÈë´¦Öóͷ£²»µ±µ¼Öµģ¬£¬£¬£¬£¬ £¬ÆäCVSSÆÀ·Ö8.8¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔͨ¹ýÖ¸µ¼Ä¿µÄÓû§µ¥»÷µç×ÓÓʼþ»òÆäËüÐÂÎÅת´ïƽ̨·¢Ë͵ÄÐÂÎÅÖеÄÁ´½ÓÀ´Ê¹ÓôËÎó²î¡£¡£¡£¡£¡£¡£¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷ÕßÄܹ»ÒÔÔËÐÐCisco Jabber¿Í»§¶ËµÄÕË»§È¨ÏÞÔÚÄ¿µÄϵͳÉÏÖ´ÐÐí§ÒâÏÂÁî¡£¡£¡£¡£¡£¡£¡£

Ó°Ïì¹æÄ££º

Windows °æCisco Jabber

 

Cisco JabberÐÂÎÅ´¦Öóͷ£¾ç±¾×¢ÈëÎó²î£¨CVE-2020-27134£©

¸ÃÎó²îÊÇÓʼþÄÚÈÝÑéÖ¤²»×¼È·µ¼Öµģ¬£¬£¬£¬£¬ £¬ÆäCVSSÆÀ·Ö8.0¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔͨ¹ýÏòÊÜÓ°ÏìµÄJabber¿Í»§¶Ë·¢ËͶñÒâµÄXMPPÐÂÎÅÀ´Ê¹ÓôËÎó²î¡£¡£¡£¡£¡£¡£¡£Í¨¹ýÖ¸µ¼Ä¿µÄÓû§¾ÙÐÐÐÂÎŽ»»¥£¬£¬£¬£¬£¬ £¬¹¥»÷Õß¿ÉÒÔÔÚJabberÐÂÎÅ´°¿Ú½çÃæÄÚ×¢Èëí§Òâ¾ç±¾´úÂë¡£¡£¡£¡£¡£¡£¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷ÕßÄܹ»ÒÔÔËÐÐCisco Jabber¿Í»§¶ËµÄÕË»§È¨ÏÞÔÚMacOS»òWindowsÄ¿µÄϵͳÉÏÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¡£ÔÚÒÆ¶¯Æ½Ì¨ÉÏÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔÔËÐнÅÔ­À´ÐÞ¸ÄÓ¦ÓóÌÐò½çÃæ»ò´ÓJabberÓ¦ÓóÌÐò»ñÈ¡Ãô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£

Ó°Ïì¹æÄ££º

Windows °æCisco Jabber

MacOS°æCisco Jabber

mobile platforms°æCisco Jabber

 

0x02 ´¦Öóͷ£½¨Òé

ÏÖÔÚCiscoÒѾ­ÐÞ¸´ÁËÏà¹ØÎó²î£¬£¬£¬£¬£¬ £¬½¨Òé²Î¿¼Ï±íʵʱ¸üС£¡£¡£¡£¡£¡£¡£

Windows°æCisco Jabber

ÊÜÓ°Ïì°æ±¾

ÐÞ¸´°æ±¾

12.1֮ǰ°æ±¾

Ǩáãµ½Àο¿°æ±¾

12.1

12.1.4

12.5

12.5.3

12.6

12.6.4

12.7

12.7.3

12.8

12.8.4

12.9

12.9.3

MacOS°æCisco Jabber

12.7¼°Ö®Ç°°æ±¾

Ǩáãµ½Àο¿°æ±¾

12.8

12.8.5

12.9

12.9.4

AndroidºÍiOS°æCisco Jabber

12.8¼°Ö®Ç°°æ±¾

Ǩáãµ½Àο¿°æ±¾

12.9

12.9.4

 

ÏÂÔØÁ´½Ó£º

https://software.cisco.com/download/find

 

0x03 ²Î¿¼Á´½Ó

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-jabber-ZktzjpgO

https://threatpost.com/critical-cisco-jabber-bug-get-updated-fix/162143/

https://securityaffairs.co/wordpress/112163/hacking/cisco-jabber-rce.html?

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-26085

 

0x04 ʱ¼äÏß

2020-12-10  CiscoÐû²¼Îó²îͨ¸æ

2020-12-11  VSRCÐû²¼Ç徲ͨ¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/

image.png