Cisco Small Business·ÓÉÆ÷Ô¶³ÌÏÂÁîÖ´ÐÐÎó²î£¨CVE-2021-1287£©
Ðû²¼Ê±¼ä 2021-03-180x00 Îó²î¸ÅÊö
CVE ID | CVE-2021-1287 | ʱ ¼ä | 2021-03-18 |
Àà ÐÍ | Ô¶³ÌÏÂÁîÖ´ÐÐ | µÈ ¼¶ | ¸ßΣ |
Ô¶³ÌʹÓà | ÊÇ | Ó°Ïì¹æÄ£ |
0x01 Îó²îÏêÇé
2021Äê03ÔÂ17ÈÕ£¬£¬£¬£¬£¬£¬CiscoÐû²¼Ç徲ͨ¸æ£¬£¬£¬£¬£¬£¬¹ûÕæÁËÆäСÐÍÆóÒµRV132WºÍRV134W·ÓÉÆ÷ÖеÄÒ»¸öÔ¶³ÌÏÂÁîÖ´ÐÐÎó²î£¬£¬£¬£¬£¬£¬Îó²î×·×ÙΪCVE-2021-1287£¬£¬£¬£¬£¬£¬ÆäCVSSÆÀ·ÖΪ7.2¡£¡£¡£¡£¡£
¸ÃÎó²î±£´æÓÚWebµÄÖÎÀí½çÃæÖУ¬£¬£¬£¬£¬£¬ÓÉÓÚûÓÐ׼ȷÑéÖ¤Óû§µÄÊäÈ룬£¬£¬£¬£¬£¬¾ÓÉÉí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔͨ¹ýÏòÊÜÓ°ÏìµÄ×°±¸·¢ËͶñÒâµÄHTTPÇëÇóÀ´Ê¹ÓôËÎó²î¡£¡£¡£¡£¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷ÕßÄܹ»ÒÔrootÓû§µÄÉí·ÝÔÚϵͳÉÏÖ´ÐÐí§Òâ´úÂë¡¢µ¼ÖÂ×°±¸ÖØÐ¼ÓÔØ»ò¾Ü¾øÐ§ÀÍ£¨DoS£©¡£¡£¡£¡£¡£
½ñÄê2Ô£¬£¬£¬£¬£¬£¬Cisco»¹ÐÞ¸´ÁËÆäСÐÍÆóÒµVPN·ÓÉÆ÷²úƷϵÁУ¨RV160¡¢RV160W¡¢RV260¡¢RV260PºÍRV260W VPN·ÓÉÆ÷£©ÖеĶà¸öÑÏÖØÎó²î£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔʹÓÃÕâЩÎó²îÀ´Éó²é¡¢¸Ä¶¯Êý¾Ý£¬£¬£¬£¬£¬£¬»òÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£
Ó°Ïì¹æÄ£
RV132W ADSL2 + Wireless-N VPN·ÓÉÆ÷£¨¹Ì¼þ°æ±¾ < 1.0.1.15£©
RV134W VDSL2 Wireless-AC VPN·ÓÉÆ÷£¨¹Ì¼þ°æ±¾ < 1.0.1.21£©
0x02 ´¦Öóͷ£½¨Òé
ÏÖÔÚ¹Ù·½ÒÑÐÞ¸´ÁË´ËÎó²î£¬£¬£¬£¬£¬£¬½¨ÒéÉý¼¶ÖÁÒÔϰ汾£º
RV132W ADSL2 + Wireless-N VPN·ÓÉÆ÷¹Ì¼þ°æ±¾ >= 1.0.1.15
RV134W VDSL2 Wireless-AC VPN·ÓÉÆ÷¹Ì¼þ°æ±¾ >= 1.0.1.21
ÏÂÔØÁ´½Ó£º
https://software.cisco.com/download/home
0x03 ²Î¿¼Á´½Ó
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-rv-132w134w-overflow-Pptt4H2p
https://threatpost.com/cisco-security-hole-small-business-routers/164859/
/new_type/aqtg/20210204/22362.html
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-1287
0x04 ʱ¼äÏß
2021-03-17 CiscoÐû²¼Ç徲ͨ¸æ
2021-03-18 VSRCÐû²¼Ç徲ͨ¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/