Cisco SD-WAN vManage & Small Business Routers¶à¸öÇå¾²Îó²î
Ðû²¼Ê±¼ä 2021-04-080x00 Îó²î¸ÅÊö
2021Äê04ÔÂ07ÈÕ£¬£¬£¬£¬£¬£¬CiscoÐû²¼Ç徲ͨ¸æ£¬£¬£¬£¬£¬£¬ÐÞ¸´ÁËCisco SD-WAN vManageÈí¼þÖеÄ3¸öÇå¾²Îó²îÒÔ¼°CiscoСÐÍÆóÒµRV110W¡¢RV130¡¢RV130WºÍRV215W·ÓÉÆ÷ÖеÄ1¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬£¬£¬£¬£¬£¬¾ÓÉÉí·ÝÑéÖ¤»òδÂÄÀúÖ¤µÄ¹¥»÷Õß¿ÉÒÔͨ¹ýʹÓÃÕâЩÎó²îÌáÉýȨÏÞ»òÔÚϵͳÉÏÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¡£
0x01 Îó²îÏêÇé
Îó²îÏêÇéÈçÏ£º
Cisco SD-WAN vManage»º³åÇøÒç³öÎó²î£¨CVE-2021-1479£©
¸ÃÎó²î±£´æÓÚCisco SD-WAN vManageÈí¼þµÄÔ¶³ÌÖÎÀí×é¼þÖУ¬£¬£¬£¬£¬£¬ÆäCVSSÆÀ·Ö9.8¡£¡£¡£¡£¡£¡£¡£
ÓÉÓÚ¶ÔÓû§µÄÊäÈëÑéÖ¤²»×¼È·£¬£¬£¬£¬£¬£¬Î´ÂÄÀúÖ¤µÄ¹¥»÷Õß¿ÉÒÔͨ¹ýÏòÒ×Êܹ¥»÷µÄ×é¼þ·¢ËͶñÒâµÄÅþÁ¬ÇëÇóÀ´Ê¹ÓôËÎó²î£¬£¬£¬£¬£¬£¬Õâ¿ÉÄܵ¼Ö»º³åÇøÒç³ö£¬£¬£¬£¬£¬£¬ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷ÕßÄܹ»ÒÔrootȨÏÞÔÚϵͳÉÏÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¡£
Cisco SD-WAN vManageȨÏÞÌáÉýÎó²î£¨CVE-2021-1137£©
¸ÃÎó²î±£´æÓÚCisco SD-WANÈí¼þµÄÓû§ÖÎÀí¹¦Ð§ÖУ¬£¬£¬£¬£¬£¬ÆäCVSSÆÀ·Ö7.8¡£¡£¡£¡£¡£¡£¡£
ÓÉÓÚÊäÈëÑé֤ȱ·¦£¬£¬£¬£¬£¬£¬ÓµÓÐÔÚvManageϵͳÉÏÌí¼ÓÐÂÓû§»ò×éµÄȨÏ޵ľÓÉÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔͨ¹ýÐÞ¸ÄÓû§ÕË»§À´Ê¹ÓôËÎó²î¡£¡£¡£¡£¡£¡£¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔ»ñµÃϵͳµÄrootȨÏÞ¡£¡£¡£¡£¡£¡£¡£
Cisco SD-WAN vManageȨÏÞÌáÉýÎó²î£¨CVE-2021-1480£©
¸ÃÎó²î±£´æÓÚCisco SD-WANÈí¼þµÄϵͳÎļþ´«Ê书ЧÖУ¬£¬£¬£¬£¬£¬ÆäCVSSÆÀ·Ö7.8¡£¡£¡£¡£¡£¡£¡£
ÓÉÓÚ¶ÔϵͳÎļþ´«Ê书ЧµÄÊäÈëÑéÖ¤²»×¼È·£¬£¬£¬£¬£¬£¬¾ÓÉÉí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔͨ¹ýÏòÒ×Êܹ¥»÷µÄϵͳ·¢ËͶñÒâÇëÇóÀ´Ê¹ÓôËÎó²î£¬£¬£¬£¬£¬£¬ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔÁýÕÖí§ÒâÎļþ²¢ÒÔrootÓû§È¨ÏÞÐÞ¸Äϵͳ¡£¡£¡£¡£¡£¡£¡£
Cisco Small Business routersÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-1459£©
¸ÃÎó²î±£´æÓÚCisco Small Business RV110W¡¢RV130¡¢RV130WºÍRV215W·ÓÉÆ÷»ùÓÚWebµÄÖÎÀí½çÃæÖУ¬£¬£¬£¬£¬£¬ÆäCVSSÆÀ·ÖΪ9.8¡£¡£¡£¡£¡£¡£¡£
ÓÉÓÚδ׼ȷÑéÖ¤Óû§ÌṩµÄÊäÈ룬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔͨ¹ýÏòÄ¿µÄ×°±¸·¢ËͶñÒâµÄHTTPÇëÇóÀ´Ê¹ÓôËÎó²î£¬£¬£¬£¬£¬£¬ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷ÕßÄܹ»ÒÔroot Óû§Éí·ÝÔÚÊÜÓ°Ïì×°±¸ÏµÍ³ÉÏÖ´ÐÐí§Òâ´úÂë ¡£¡£¡£¡£¡£¡£¡£
Ó°Ïì¹æÄ£
´ËÎó²îÓ°ÏìÒÔÏÂCisco Small Business RVϵÁзÓÉÆ÷£º
RV110W Wireless-N VPN Firewall
RV130 VPN Router
RV130W Wireless-N Multifunction VPN Router
RV215W Wireless-N VPN Router
0x02 ´¦Öóͷ£½¨Òé
ÏÖÔÚCisco Small Business RV110W¡¢RV130¡¢RV130WºÍRV215W·ÓÉÆ÷ÒÑ×èÖ¹Ö§³Ö£¬£¬£¬£¬£¬£¬¹Ù·½½«²»»áÔÙÐû²¼Çå¾²¸üУ¬£¬£¬£¬£¬£¬½¨ÒéǨáãµ½Cisco Small Business RV132W¡¢RV160»òRV160W·ÓÉÆ÷¡£¡£¡£¡£¡£¡£¡£Cisco SD-WAN vManage ÖеÄ3¸öÎó²îÒѾÐÞ¸´£¬£¬£¬£¬£¬£¬½¨Òé²Î¿¼Ï±íʵʱ¸üУº
Cisco SD-WAN vManageÊÜÓ°Ïì°æ±¾ | ÐÞ¸´°æ±¾ | ËùÓÐÎó²îµÄµÚÒ»¸öÐÞ¸´°æ±¾ |
18.4¼°¸üÔç°æ±¾ | Ǩáãµ½Àο¿°æ±¾¡£¡£¡£¡£¡£¡£¡£ | Ǩáãµ½Àο¿°æ±¾¡£¡£¡£¡£¡£¡£¡£ |
19.2 | 19.2.4 | 19.2.4 |
19.3 | Ǩáãµ½Àο¿°æ±¾¡£¡£¡£¡£¡£¡£¡£ | Ǩáãµ½Àο¿°æ±¾¡£¡£¡£¡£¡£¡£¡£ |
20.1 | Ǩáãµ½Àο¿°æ±¾¡£¡£¡£¡£¡£¡£¡£ | Ǩáãµ½Àο¿°æ±¾¡£¡£¡£¡£¡£¡£¡£ |
20.3 | 20.3.3 | 20.3.3 |
20.4 | 20.4.1 | 20.4.1 |
ÏÂÔØÁ´½Ó£º
https://software.cisco.com/download/find
0x03 ²Î¿¼Á´½Ó
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-vmanage-YuTVWqy
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-rv-rce-q3rxHnvm
https://www.bleepingcomputer.com/news/security/cisco-fixes-bug-allowing-remote-code-execution-with-root-privileges/
0x04 ʱ¼äÏß
2021-04-07 CiscoÐû²¼Ç徲ͨ¸æ
2021-04-08 VSRCÐû²¼Ç徲ͨ¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/