CVE-2020-3161| Cisco IP PhonesÔ¶³Ì´úÂëÖ´Ðзì϶¹«¸æ
°ä²¼¹¦·ò 2020-04-210x00 ·ì϶¸ÅÊö

0x01 ·ì϶ÏêÇé
4ÔÂ15ÈÕ£¬Ë¼¿Æ°ä²¼°²È«²¼¸æ£¬³ÆÆä IP µç»°µÄ web ·þÎñÆ÷ÖдæÔÚÒ»¸öÑϳÁȱµã£¬¿Éµ¼ÖÂδ¾Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÒÔ root ȨÏÞÖ´ÐдúÂë»ò·¢Æð»Ø¾ø·þÎñ¹¥»÷¡£¸Ã·ì϶ӰÏìÓÃÓÚÖÐÓׯóÒµµÄ¶à¸ö˼¿Æ IP µç»°°æ±¾£¬CVSSÆÀ·Ö9.8¡£
¸Ã·ì϶ÊÇÓÉÓÚ²»×ã¶ÔHTTPÒªÇóµÄÕýÈ·ÊäÈëÑéÖ¤ËùÖ¡£ ¹¥»÷Õß½«Ò»¸öÌØÊâ»ú¹ØµÄ HTTP ÒªÇó·¢Ë͵½ /deviceconfig/setActivationCode¶Ëµã£¨ÔÚÖ¸±êÉ豸µÄ web ·þÎñÆ÷ÉÏ£©£¬ÔÚ libHTTPService.so ÖУ¬/deviceconfig/setActivationCode Ö®ºóµÄ²ÎÊýÓÃÓÚͨ¹ýÒ»¸ö sprint º¯ÊýŲÓô´½¨Ð嵀 URI£¬¸Ã²ÎÊý×Ö·û´®µÄ³¤¶È²¢Î´µÃµ½²é³¡£³É¹¦ÀûÓô˷ì϶ʹ¹¥»÷Õß¿ÉÄÜÒÔrootȨÏÞÔ¶³ÌÖ´ÐдúÂ룬»òµ¼Ö³ÁмÓÔØÊÜÓ°ÏìµÄIPµç»°£¬µ¼Ö»ؾø·þÎñ¡£
EXP: https://cxsecurity.com/issue/WLB-2020040100
0x02 ´ëÖý¨Òé
Éý¼¶²¹¶¡£¬ÏÂÔØÁ´½Ó£º
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-voip-phones-rce-dos-rB6EeRXs
һʱ´ëÊ©£º½ûÓà IP µç»°É쵀 web ½Ó¼ûȨÏÞ¡£
ĬÈÏÇé¿öÏ£¬Web½Ó¼ûÊǽûÓõġ£ ÖÎÀíÔ±Äܹ»Í¨¹ýÒÔϲ½Öè´ÓCisco Unified Communications ManagerÖвé³Web½Ó¼ûÅäÖãºÑ¡ÔñDevice > Phone > Select a Phone£¬¶øºó²é³Web ½Ó¼ûÊÇ·ñÉèÖÃΪ¡°ÆôÓá±»ò¡°½ûÓᱡ£ ÈôÊǽ«ÆäÉèÖÃΪ¡°½ûÓá±£¬ÔòIPµç»°²»»áÊܵ½¹¥»÷¡£
0x03 ÓйØÐÂÎÅ
https://threatpost.com/critical-cisco-ip-phone-rce-flaw/154864/
0x04 ²Î¿¼Á´½Ó
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-voip-phones-rce-dos-rB6EeRXs
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-202004-1099
0x05 ¹¦·òÏß
2020-04-15 Cisco°ä²¼²¼¸æ
2020-04-15 CVE°ä²¼¸Ã·ì϶


¾©¹«Íø°²±¸11010802024551ºÅ