Cisco Small Business·ÓÉÆ÷Ô¶³ÌÏÂÁîÖ´ÐÐÎó²î£¨CVE-2021-1287£©

Ðû²¼Ê±¼ä 2021-03-18

0x00 Îó²î¸ÅÊö

CVE  ID

CVE-2021-1287

ʱ  ¼ä

2021-03-18

Àà   ÐÍ

 Ô¶³ÌÏÂÁîÖ´ÐÐ

µÈ  ¼¶

¸ßΣ

Ô¶³ÌʹÓÃ

ÊÇ

Ó°Ïì¹æÄ£


 

0x01 Îó²îÏêÇé

image.png

 

2021Äê03ÔÂ17ÈÕ £¬£¬£¬£¬£¬£¬CiscoÐû²¼Ç徲ͨ¸æ £¬£¬£¬£¬£¬£¬¹ûÕæÁËÆäСÐÍÆóÒµRV132WºÍRV134W·ÓÉÆ÷ÖеÄÒ»¸öÔ¶³ÌÏÂÁîÖ´ÐÐÎó²î £¬£¬£¬£¬£¬£¬Îó²î×·×ÙΪCVE-2021-1287 £¬£¬£¬£¬£¬£¬ÆäCVSSÆÀ·ÖΪ7.2¡£¡£¡£¡£¡£

¸ÃÎó²î±£´æÓÚWebµÄÖÎÀí½çÃæÖÐ £¬£¬£¬£¬£¬£¬ÓÉÓÚûÓÐ׼ȷÑéÖ¤Óû§µÄÊäÈë £¬£¬£¬£¬£¬£¬¾­ÓÉÉí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔͨ¹ýÏòÊÜÓ°ÏìµÄ×°±¸·¢ËͶñÒâµÄHTTPÇëÇóÀ´Ê¹ÓôËÎó²î¡£¡£¡£¡£¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷ÕßÄܹ»ÒÔrootÓû§µÄÉí·ÝÔÚϵͳÉÏÖ´ÐÐí§Òâ´úÂë¡¢µ¼ÖÂ×°±¸ÖØÐ¼ÓÔØ»ò¾Ü¾øÐ§ÀÍ£¨DoS£©¡£¡£¡£¡£¡£

½ñÄê2Ô £¬£¬£¬£¬£¬£¬Cisco»¹ÐÞ¸´ÁËÆäСÐÍÆóÒµVPN·ÓÉÆ÷²úƷϵÁУ¨RV160¡¢RV160W¡¢RV260¡¢RV260PºÍRV260W VPN·ÓÉÆ÷£©ÖеĶà¸öÑÏÖØÎó²î £¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔʹÓÃÕâЩÎó²îÀ´Éó²é¡¢¸Ä¶¯Êý¾Ý £¬£¬£¬£¬£¬£¬»òÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£

 

Ó°Ïì¹æÄ£

RV132W ADSL2 + Wireless-N VPN·ÓÉÆ÷£¨¹Ì¼þ°æ±¾ < 1.0.1.15£©

RV134W VDSL2 Wireless-AC VPN·ÓÉÆ÷£¨¹Ì¼þ°æ±¾ < 1.0.1.21£©

 

0x02 ´¦Öóͷ£½¨Òé

ÏÖÔÚ¹Ù·½ÒÑÐÞ¸´ÁË´ËÎó²î £¬£¬£¬£¬£¬£¬½¨ÒéÉý¼¶ÖÁÒÔϰ汾£º

RV132W ADSL2 + Wireless-N VPN·ÓÉÆ÷¹Ì¼þ°æ±¾ >= 1.0.1.15

RV134W VDSL2 Wireless-AC VPN·ÓÉÆ÷¹Ì¼þ°æ±¾ >= 1.0.1.21

ÏÂÔØÁ´½Ó£º

https://software.cisco.com/download/home

 

0x03 ²Î¿¼Á´½Ó

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-rv-132w134w-overflow-Pptt4H2p

https://threatpost.com/cisco-security-hole-small-business-routers/164859/

/new_type/aqtg/20210204/22362.html

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-1287

 

0x04 ʱ¼äÏß

2021-03-17  CiscoÐû²¼Ç徲ͨ¸æ

2021-03-18  VSRCÐû²¼Ç徲ͨ¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/

image.png