¡¾Îó²îͨ¸æ¡¿ Cisco Jabber12Ô¶à¸öÇå¾²Îó²î
Ðû²¼Ê±¼ä 2020-12-110x00 Îó²î¸ÅÊö
²úÆ·Ãû³Æ | CVE ID | Àà ÐÍ | Îó²îÆ·¼¶ | Ô¶³ÌʹÓà |
Cisco Jabber | CVE-2020-26085 | RCE | ÑÏÖØ | ÊÇ |
CVE-2020-27127 | δÊÚȨ»á¼û | ÖÐΣ | ÊÇ | |
CVE-2020-27132 | ÐÅϢй¶ | ÖÐΣ | ÊÇ | |
CVE-2020-27133 | ÏÂÁî×¢Èë | ¸ßΣ | ÊÇ | |
CVE-2020-27134 | ¾ç±¾×¢Èë | ¸ßΣ | ÊÇ |
0x01 Îó²îÏêÇé
Cisco JabberÊÇÒ»¸ö¼´Ê±ÐÂÎźÍweb¾Û»á×ÀÃæÓ¦ÓóÌÐò£¬£¬£¬£¬£¬£¬ËüʹÓÿÉÀ©Õ¹ÐÂÎźÍ״̬ÐÒ飨XMPP£©ÔÚÓû§Ö®¼äת´ïÐÂÎÅ¡£¡£¡£¡£¡£¡£¡£¸ÃÓ¦ÓóÌÐò»ùÓÚChromium Embedded Framework£¨CEF£©¹¹½¨£¬£¬£¬£¬£¬£¬ÆäUIʹÓÃHTML¡¢CSSºÍJavaScriptµÈwebÊÖÒÕ¡£¡£¡£¡£¡£¡£¡£
2020Äê12ÔÂ10ÈÕ£¬£¬£¬£¬£¬£¬CiscoÐû²¼Ç徲ͨ¸æ£¬£¬£¬£¬£¬£¬JabberÖб£´æ¶à¸öÇå¾²Îó²î£¨CVE-2020-26085¡¢CVE-2020-27127¡¢CVE-2020-27132¡¢CVE-2020-27133ºÍCVE-2020-27134£©¡£¡£¡£¡£¡£¡£¡£ÕâЩÎó²î²¢²»Ï໥ÒÀÀµ£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÄܹ»Ê¹ÓÃËüÃÇÔÚϵͳÉÏÖ´ÐÐí§Òâ´úÂ룬£¬£¬£¬£¬£¬»òÇÔÈ¡Ãô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£
ҪʹÓÃCVE-2020-26085ºÍCVE-2020-27134ÕâÁ½¸öÐÂÎÅ´¦Öóͷ£Îó²î£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÐèÒª»á¼ûͳһXMPPÓò»òʹÓÃÆäËüÒªÁìÏòCisco Jabber¿Í»§¶Ë·¢ËÍ¿ÉÀ©Õ¹ÐÂÎźÍ״̬ÐÒ飨XMPP£©ÐÂÎÅ¡£¡£¡£¡£¡£¡£¡£´¦ÓÚphone-onlyģʽÏÂÇÒδÆôÓÃXMPPÐÂÎÅЧÀ͵ÄCisco Jabber½ûÖ¹Ò×Êܵ½¹¥»÷¡£¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬ÈôÊǽ«Cisco JabberÉèÖÃΪʹÓÃXMPPÐÂÎÅת´ïÒÔÍâµÄÆäËüÐÂÎÅת´ïЧÀÍ£¬£¬£¬£¬£¬£¬ÔòÎó²îÎÞ·¨Ê¹Óᣡ£¡£¡£¡£¡£¡£
Îó²îÏêÇéÈçÏ£º
Cisco JabberÐÂÎÅ´¦Öóͷ£ÖеÄí§Òâ´úÂëÖ´ÐÐÎó²î£¨CVE-2020-26085£©
¸ÃÎó²îÊÇÓʼþÄÚÈÝÑéÖ¤²»×¼È·µ¼Öµģ¬£¬£¬£¬£¬£¬ÆäCVSSÆÀ·Ö9.9¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔͨ¹ýÏòÊÜÓ°ÏìµÄJabber¿Í»§¶Ë·¢ËͶñÒâµÄXMPPÐÂÎÅÀ´Ê¹ÓôËÎó²î¡£¡£¡£¡£¡£¡£¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷ÕßÄܹ»ÒÔÔËÐÐCisco Jabber¿Í»§¶ËµÄÕË»§È¨ÏÞÔÚÄ¿µÄϵͳÉÏÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¡£
Ó°Ïì¹æÄ££º
Windows °æCisco Jabber
MacOS°æCisco Jabber
Cisco Jabber for Windows×Ô½ç˵ÐÒé´¦Öóͷ£³ÌÐòδÊÚȨ»á¼ûÎó²î£¨CVE-2020-27127£©
¸ÃÎó²îÊǶÔJabberÐÒé´¦Öóͷ£³ÌÐòµÄÊäÈë´¦Öóͷ£²»µ±µ¼Öµģ¬£¬£¬£¬£¬£¬ÆäCVSSÆÀ·Ö4.3¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔͨ¹ýÖ¸µ¼Ä¿µÄÓû§µ¥»÷µç×ÓÓʼþ»òÆäËüÐÂÎÅת´ïƽ̨·¢Ë͵ÄÐÂÎÅÖеÄÁ´½ÓÀ´Ê¹ÓôËÎó²î¡£¡£¡£¡£¡£¡£¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔÏòCisco Jabber¿Í»§¶Ë·¢ËÍí§ÒâÏÂÁ£¬£¬£¬£¬£¬´Ó¶ø¿ÉÄÜʹ¹¥»÷ÕßÐÞ¸ÄÓ¦ÓóÌÐòÉèÖᣡ£¡£¡£¡£¡£¡£
Ó°Ïì¹æÄ££º
Windows °æCisco Jabber
Cisco JabberÐÅϢй¶Îó²î£¨VE-2020-27132£©
¸ÃÎó²îÊÇÓʼþÄÚÈÝÑéÖ¤²»×¼È·µ¼Öµģ¬£¬£¬£¬£¬£¬ÆäCVSSÆÀ·Ö6.5¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔͨ¹ýÏòÄ¿µÄϵͳ·¢ËͶñÒâÐÂÎÅÀ´Ê¹ÓôËÎó²î¡£¡£¡£¡£¡£¡£¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔʹJabber½«Éí·ÝÑéÖ¤µÈÃô¸ÐÐÅÏ¢·µ»Ø¸øÁíÒ»¸öϵͳ£¬£¬£¬£¬£¬£¬ÒÔ±ãÓÚ½øÒ»²½¹¥»÷¡£¡£¡£¡£¡£¡£¡£
Ó°Ïì¹æÄ££º
Windows °æCisco Jabber
MacOS°æCisco Jabber
Cisco Jabber for Windows×Ô½ç˵ÐÒé´¦Öóͷ£³ÌÐòÏÂÁî×¢ÈëÎó²î£¨CVE-2020-27133£©
¸ÃÎó²îÊǶÔJabberÐÒé´¦Öóͷ£³ÌÐòµÄÊäÈë´¦Öóͷ£²»µ±µ¼Öµģ¬£¬£¬£¬£¬£¬ÆäCVSSÆÀ·Ö8.8¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔͨ¹ýÖ¸µ¼Ä¿µÄÓû§µ¥»÷µç×ÓÓʼþ»òÆäËüÐÂÎÅת´ïƽ̨·¢Ë͵ÄÐÂÎÅÖеÄÁ´½ÓÀ´Ê¹ÓôËÎó²î¡£¡£¡£¡£¡£¡£¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷ÕßÄܹ»ÒÔÔËÐÐCisco Jabber¿Í»§¶ËµÄÕË»§È¨ÏÞÔÚÄ¿µÄϵͳÉÏÖ´ÐÐí§ÒâÏÂÁî¡£¡£¡£¡£¡£¡£¡£
Ó°Ïì¹æÄ££º
Windows °æCisco Jabber
Cisco JabberÐÂÎÅ´¦Öóͷ£¾ç±¾×¢ÈëÎó²î£¨CVE-2020-27134£©
¸ÃÎó²îÊÇÓʼþÄÚÈÝÑéÖ¤²»×¼È·µ¼Öµģ¬£¬£¬£¬£¬£¬ÆäCVSSÆÀ·Ö8.0¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔͨ¹ýÏòÊÜÓ°ÏìµÄJabber¿Í»§¶Ë·¢ËͶñÒâµÄXMPPÐÂÎÅÀ´Ê¹ÓôËÎó²î¡£¡£¡£¡£¡£¡£¡£Í¨¹ýÖ¸µ¼Ä¿µÄÓû§¾ÙÐÐÐÂÎŽ»»¥£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔÔÚJabberÐÂÎÅ´°¿Ú½çÃæÄÚ×¢Èëí§Òâ¾ç±¾´úÂë¡£¡£¡£¡£¡£¡£¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷ÕßÄܹ»ÒÔÔËÐÐCisco Jabber¿Í»§¶ËµÄÕË»§È¨ÏÞÔÚMacOS»òWindowsÄ¿µÄϵͳÉÏÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¡£ÔÚÒÆ¶¯Æ½Ì¨ÉÏÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔÔËÐнÅÔÀ´ÐÞ¸ÄÓ¦ÓóÌÐò½çÃæ»ò´ÓJabberÓ¦ÓóÌÐò»ñÈ¡Ãô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£
Ó°Ïì¹æÄ££º
Windows °æCisco Jabber
MacOS°æCisco Jabber
mobile platforms°æCisco Jabber
0x02 ´¦Öóͷ£½¨Òé
ÏÖÔÚCiscoÒѾÐÞ¸´ÁËÏà¹ØÎó²î£¬£¬£¬£¬£¬£¬½¨Òé²Î¿¼Ï±íʵʱ¸üС£¡£¡£¡£¡£¡£¡£
Windows°æCisco Jabber | ÊÜÓ°Ïì°æ±¾ | ÐÞ¸´°æ±¾ |
12.1֮ǰ°æ±¾ | Ǩáãµ½Àο¿°æ±¾ | |
12.1 | 12.1.4 | |
12.5 | 12.5.3 | |
12.6 | 12.6.4 | |
12.7 | 12.7.3 | |
12.8 | 12.8.4 | |
12.9 | 12.9.3 | |
MacOS°æCisco Jabber | 12.7¼°Ö®Ç°°æ±¾ | Ǩáãµ½Àο¿°æ±¾ |
12.8 | 12.8.5 | |
12.9 | 12.9.4 | |
AndroidºÍiOS°æCisco Jabber | 12.8¼°Ö®Ç°°æ±¾ | Ǩáãµ½Àο¿°æ±¾ |
12.9 | 12.9.4 |
ÏÂÔØÁ´½Ó£º
https://software.cisco.com/download/find
0x03 ²Î¿¼Á´½Ó
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-jabber-ZktzjpgO
https://threatpost.com/critical-cisco-jabber-bug-get-updated-fix/162143/
https://securityaffairs.co/wordpress/112163/hacking/cisco-jabber-rce.html?
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-26085
0x04 ʱ¼äÏß
2020-12-10 CiscoÐû²¼Îó²îͨ¸æ
2020-12-11 VSRCÐû²¼Ç徲ͨ¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/