CVE-2020-3161| Cisco IP PhonesÔ¶³Ì´úÂëÖ´Ðзì϶¹«¸æ

°ä²¼¹¦·ò 2020-04-21

0x00 ·ì϶¸ÅÊö


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾



0x01 ·ì϶ÏêÇé


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾




4ÔÂ15ÈÕ£¬Ë¼¿Æ°ä²¼°²È«²¼¸æ£¬³ÆÆä IP µç»°µÄ web ·þÎñÆ÷ÖдæÔÚÒ»¸öÑϳÁȱµã£¬¿Éµ¼ÖÂδ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÒÔ root ȨÏÞÖ´ÐдúÂë»ò·¢Æð»Ø¾ø·þÎñ¹¥»÷¡£¸Ã·ì϶ӰÏìÓÃÓÚÖÐÓׯóÒµµÄ¶à¸ö˼¿Æ IP µç»°°æ±¾£¬CVSSÆÀ·Ö9.8¡£

¸Ã·ì϶ÊÇÓÉÓÚ²»×ã¶ÔHTTPÒªÇóµÄÕýÈ·ÊäÈëÑéÖ¤ËùÖ¡£ ¹¥»÷Õß½«Ò»¸öÌØÊâ»ú¹ØµÄ HTTP ÒªÇó·¢Ë͵½ /deviceconfig/setActivationCode¶Ëµã£¨ÔÚÖ¸±êÉ豸µÄ web ·þÎñÆ÷ÉÏ£©£¬ÔÚ libHTTPService.so ÖУ¬/deviceconfig/setActivationCode Ö®ºóµÄ²ÎÊýÓÃÓÚͨ¹ýÒ»¸ö sprint º¯ÊýŲÓô´½¨Ð嵀 URI£¬¸Ã²ÎÊý×Ö·û´®µÄ³¤¶È²¢Î´µÃµ½²é³­¡£³É¹¦ÀûÓô˷ì϶ʹ¹¥»÷Õß¿ÉÄÜÒÔrootȨÏÞÔ¶³ÌÖ´ÐдúÂ룬»òµ¼Ö³ÁмÓÔØÊÜÓ°ÏìµÄIPµç»°£¬µ¼Ö»ؾø·þÎñ¡£

EXP: https://cxsecurity.com/issue/WLB-2020040100


0x02 ´ëÖý¨Òé


Éý¼¶²¹¶¡£¬ÏÂÔØÁ´½Ó£º

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-voip-phones-rce-dos-rB6EeRXs

һʱ´ëÊ©£º½ûÓà IP µç»°É쵀 web ½Ó¼ûȨÏÞ¡£

ĬÈÏÇé¿öÏ£¬Web½Ó¼ûÊǽûÓõÄ¡£ ÖÎÀíÔ±Äܹ»Í¨¹ýÒÔϲ½Öè´ÓCisco Unified Communications ManagerÖв鳭Web½Ó¼ûÅäÖãºÑ¡ÔñDevice > Phone > Select a Phone£¬¶øºó²é³­Web ½Ó¼ûÊÇ·ñÉèÖÃΪ¡°ÆôÓá±»ò¡°½ûÓᱡ£ ÈôÊǽ«ÆäÉèÖÃΪ¡°½ûÓá±£¬ÔòIPµç»°²»»áÊܵ½¹¥»÷¡£


0x03 ÓйØÐÂÎÅ


https://threatpost.com/critical-cisco-ip-phone-rce-flaw/154864/


0x04 ²Î¿¼Á´½Ó


https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-voip-phones-rce-dos-rB6EeRXs

http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-202004-1099


0x05 ¹¦·òÏß


2020-04-15 Cisco°ä²¼²¼¸æ

2020-04-15 CVE°ä²¼¸Ã·ì϶



GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾