Cisco SD-WAN vManage & Small Business Routers¶à¸öÄþ¾²Â©¶´
Ðû²¼Ê±¼ä 2021-04-080x00 ©¶´¸ÅÊö
2021Äê04ÔÂ07ÈÕ£¬CiscoÐû²¼Äþ¾²Í¨¸æ£¬ÐÞ¸´ÁËCisco SD-WAN vManageÈí¼þÖеÄ3¸öÄþ¾²Â©¶´ÒÔ¼°CiscoСÐÍÆóÒµRV110W¡¢RV130¡¢RV130WºÍRV215W·ÓÉÆ÷ÖеÄ1¸öÔ¶³Ì´úÂëÖ´ÐЩ¶´£¬¾¹ýÉí·ÝÑéÖ¤»òδ¾ÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔͨ¹ýÀûÓÃÕâЩ©¶´ÌáÉýȨÏÞ»òÔÚϵͳÉÏÖ´ÐÐÈÎÒâ´úÂë¡£
0x01 ©¶´ÏêÇé
©¶´ÏêÇéÈçÏ£º
Cisco SD-WAN vManage»º³åÇøÒç³ö©¶´£¨CVE-2021-1479£©
¸Ã©¶´´æÔÚÓÚCisco SD-WAN vManageÈí¼þµÄÔ¶³Ì¹ÜÀí×é¼þÖУ¬ÆäCVSSÆÀ·Ö9.8¡£
ÓÉÓÚ¶ÔÓû§µÄÊäÈëÑéÖ¤²»ÕýÈ·£¬Î´¾ÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔͨ¹ýÏòÒ×Êܹ¥»÷µÄ×é¼þ·¢ËͶñÒâµÄÁ¬½ÓÇëÇóÀ´ÀûÓôË©¶´£¬Õâ¿ÉÄܵ¼Ö»º³åÇøÒç³ö£¬ÀÖ³ÉÀûÓôË©¶´µÄ¹¥»÷ÕßÄܹ»ÒÔrootȨÏÞÔÚϵͳÉÏÖ´ÐÐÈÎÒâ´úÂë¡£
Cisco SD-WAN vManageȨÏÞÌáÉý©¶´£¨CVE-2021-1137£©
¸Ã©¶´´æÔÚÓÚCisco SD-WANÈí¼þµÄÓû§¹ÜÀí¹¦Ð§ÖУ¬ÆäCVSSÆÀ·Ö7.8¡£
ÓÉÓÚÊäÈëÑéÖ¤²»×㣬ӵÓÐÔÚvManageϵͳÉÏÌí¼ÓÐÂÓû§»ò×éµÄȨÏ޵ľ¹ýÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔͨ¹ýÐÞ¸ÄÓû§ÕË»§À´ÀûÓôË©¶´¡£ÀÖ³ÉÀûÓôË©¶´µÄ¹¥»÷Õß¿ÉÒÔ»ñµÃϵͳµÄrootȨÏÞ¡£
Cisco SD-WAN vManageȨÏÞÌáÉý©¶´£¨CVE-2021-1480£©
¸Ã©¶´´æÔÚÓÚCisco SD-WANÈí¼þµÄϵͳÎļþ´«Ê书ЧÖУ¬ÆäCVSSÆÀ·Ö7.8¡£
ÓÉÓÚ¶ÔϵͳÎļþ´«Ê书ЧµÄÊäÈëÑéÖ¤²»ÕýÈ·£¬¾¹ýÉí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔͨ¹ýÏòÒ×Êܹ¥»÷µÄϵͳ·¢ËͶñÒâÇëÇóÀ´ÀûÓôË©¶´£¬ÀÖ³ÉÀûÓôË©¶´µÄ¹¥»÷Õß¿ÉÒÔÁýÕÖÈÎÒâÎļþ²¢ÒÔrootÓû§È¨ÏÞÐÞ¸Äϵͳ¡£
Cisco Small Business routersÔ¶³Ì´úÂëÖ´ÐЩ¶´£¨CVE-2021-1459£©
¸Ã©¶´´æÔÚÓÚCisco Small Business RV110W¡¢RV130¡¢RV130WºÍRV215W·ÓÉÆ÷»ùÓÚWebµÄ¹ÜÀí½çÃæÖУ¬ÆäCVSSÆÀ·ÖΪ9.8¡£
ÓÉÓÚδÕýÈ·ÑéÖ¤Óû§ÌṩµÄÊäÈ룬¹¥»÷Õß¿ÉÒÔͨ¹ýÏòÄ¿±êÉ豸·¢ËͶñÒâµÄHTTPÇëÇóÀ´ÀûÓôË©¶´£¬ÀÖ³ÉÀûÓôË©¶´µÄ¹¥»÷ÕßÄܹ»ÒÔroot Óû§Éí·ÝÔÚÊÜÓ°ÏìÉ豸ϵͳÉÏÖ´ÐÐÈÎÒâ´úÂë ¡£
Ó°Ï췶Χ
´Ë©¶´Ó°ÏìÒÔÏÂCisco Small Business RVϵÁзÓÉÆ÷£º
RV110W Wireless-N VPN Firewall
RV130 VPN Router
RV130W Wireless-N Multifunction VPN Router
RV215W Wireless-N VPN Router
0x02 ´¦Öý¨Òé
ĿǰCisco Small Business RV110W¡¢RV130¡¢RV130WºÍRV215W·ÓÉÆ÷ÒÑÍ£Ö¹Ö§³Ö£¬¹Ù·½½«²»»áÔÙÐû²¼Äþ¾²¸üУ¬½¨ÒéÇ¨ÒÆµ½Cisco Small Business RV132W¡¢RV160»òRV160W·ÓÉÆ÷¡£Cisco SD-WAN vManage ÖеÄ3¸ö©¶´ÒѾÐÞ¸´£¬½¨Òé²Î¿¼ÏÂ±í¼°Ê±¸üУº
Cisco SD-WAN vManageÊÜÓ°Ïì°æ±¾ | ÐÞ¸´°æ±¾ | ËùÓЩ¶´µÄµÚÒ»¸öÐÞ¸´°æ±¾ |
18.4¼°¸üÔç°æ±¾ | Ç¨ÒÆµ½Àι̰汾¡£ | Ç¨ÒÆµ½Àι̰汾¡£ |
19.2 | 19.2.4 | 19.2.4 |
19.3 | Ç¨ÒÆµ½Àι̰汾¡£ | Ç¨ÒÆµ½Àι̰汾¡£ |
20.1 | Ç¨ÒÆµ½Àι̰汾¡£ | Ç¨ÒÆµ½Àι̰汾¡£ |
20.3 | 20.3.3 | 20.3.3 |
20.4 | 20.4.1 | 20.4.1 |
ÏÂÔØÁ´½Ó£º
https://software.cisco.com/download/find
0x03 ²Î¿¼Á´½Ó
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-vmanage-YuTVWqy
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-rv-rce-q3rxHnvm
https://www.bleepingcomputer.com/news/security/cisco-fixes-bug-allowing-remote-code-execution-with-root-privileges/
0x04 ʱ¼äÏß
2021-04-07 CiscoÐû²¼Äþ¾²Í¨¸æ
2021-04-08 VSRCÐû²¼Äþ¾²Í¨¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/