¡¾Â©¶´Í¨¸æ¡¿Juniper Networks SBRÔ¶³Ì´úÂëÖ´ÐЩ¶´£¨CVE-2021-0276£©
Ðû²¼Ê±¼ä 2021-07-190x00 ©¶´¸ÅÊö
CVE ID | CVE-2021-0276 | ʱ ¼ä | 2021-07-19 |
Àà ÐÍ | RCE | µÈ ¼¶ | ÑÏÖØ |
Ô¶³ÌÀûÓà | ÊÇ | Ó°Ï췶Χ | |
¹¥»÷ÅÓ´ó¶È | µÍ | ¿ÉÓÃÐÔ | ¸ß |
Óû§½»»¥ | ÎÞ | ËùÐèȨÏÞ | ÎÞ |
PoC/EXP | ÔÚÒ°ÀûÓÃ | ·ñ |
0x01 ©¶´ÏêÇé
2021Äê7ÔÂ14ÈÕ£¬Juniper NetworksÐû²¼Äþ¾²Í¨¸æ£¬ÆäSteel-Belted Radius Carrier Edition£¨SBRÔËÓªḚ́棩ÖдæÔÚÒ»¸öÔ¶³Ì´úÂëÖ´ÐЩ¶´£¨CVE-2021-0276£©£¬ÆäCVSSÆÀ·ÖΪ9.8¡£
µçÐÅÔËÓªÉÌͨ¹ýSBR¹ÜÀíÓû§·ÃÎÊÆäÍøÂçµÄ¼ÆÄ±£¬Í¨¹ý¼¯ÖÐÓû§ÈÏÖ¤¡¢ÌṩÊʵ±µÄ·ÃÎʼ¶±ð²¢È·±£×ñÊØÄþ¾²¼ÆÄ±¡£ËüʹÔËÓªÉÌÄܹ»Ìṩ²îÒ컯µÄ·þÎñˮƽ£¬²¢¹ÜÀíÍøÂç×ÊÔ´¡£
ÓÉÓÚÅäÖÃÁËEAP£¨¿ÉÀ©Õ¹ÈÏÖ¤ÐÒ飩Éí·ÝÈÏÖ¤µÄJuniper Networks SBRÖдæÔÚÒ»¸ö»ùÓÚ¶ÑÕ»µÄ»º³åÇøÒç³ö©¶´£¬¹¥»÷Õß¿ÉÒÔÀûÓôË©¶´·¢ËÍÌØ¶¨µÄÊý¾Ý°ü£¬µ¼ÖÂradiusÊØ»¤½ø³ÌÍ߽⣬´Ó¶øÔì³É¾Ü¾ø·þÎñ£¨DoS£©»òÔ¶³Ì´úÂëÖ´ÐУ¨RCE£©¡£
ÀÖ³ÉÀûÓôË©¶´½«µ¼ÖµçÐÅÌṩÉÌ£¨°üÂÞÎÞÏßÔËÓªÉÌ£©ÃæÁÙÍøÂç·þÎñÖжϻòÆäËü·çÏÕ¡£µ«¸Ã©¶´½öÔÚʹÓÃÔöÇ¿ÐÍ EAP ÈÕÖ¾ºÍ TraceLevel ÉèÖÃΪ 2 ʱӰÏìÅäÖÃÁË EAP Éí·ÝÑéÖ¤µÄ SBR¡£
<SBR_Installed_Directory>/JNPRsbr/radius/radius.ini
[Logging]
LogLevel=2
TraceLevel=2
EnhancedEAPLogging = yes
Ó°Ï췶Χ
8.4.1 °æ±¾£º< 8.4.1R19
8.5.0 °æ±¾£º< 8.5.0R10
8.6.0 °æ±¾£º< 8.6.0R4
0x02 ´¦Öý¨Òé
Ŀǰ´Ë©¶´ÒѾÐÞ¸´£¬½¨Ò鼰ʱ¸üÐÂÖÁSBR Carrier 8.4.1R19¡¢8.5.0R10¡¢8.6.0R4»ò¸ü¸ß°æ±¾¡£
ÏÂÔØÁ´½Ó£º
https://support.juniper.net/support/downloads/
0x03 ²Î¿¼Á´½Ó
https://kb.juniper.net/InfoCenter/index?page=content&id=JSA11180&cat=SIRT_1&actp=LIST
https://threatpost.com/critical-juniper-bug-dos-rce-carrier/167869/
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-0276
0x04 ¸üа汾
°æ±¾ | ÈÕÆÚ | ÐÞ¸ÄÄÚÈÝ |
V1.0 | 2021-07-19 | Ê×´ÎÐû²¼ |
0x05 Îĵµ¸½Â¼
CNVD£ºwww.cnvd.org.cn
CNNVD£ºwww.cnnvd.org.cn
CVE£ºcve.mitre.org
NVD£ºnvd.nist.gov
CVSS£ºwww.first.org
0x06 ¹ØÓÚ¶¶È¦Îª¶Ä¶øÉú
¹Ø×¢ÒÔϹ«Öںţ¬»ñÈ¡¸ü¶à×ÊѶ£º