CVE-2020-3280 | Cisco Unified CCXÔ¶³Ì´úÂëÖ´Ðзì϶¹«¸æ

°ä²¼¹¦·ò 2020-05-22

0x00 ·ì϶¸ÅÊö


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


0x01 ·ì϶ÏêÇé

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾



Cisco Unified Contact Center Express£¨Unified CCX£©ÊÇÃÀ¹ú˼¿Æ£¨Cisco£©¹«Ë¾µÄÒ»¿îͳһͨѶ½â¾ö¹æ»®ÖеĿͻ§¹ØÏµÖÎÀí×é¼þ ¡£¸Ã×é¼þÖ§³Ö×ÔÖ÷ÓïÒô·þÎñ¡¢ºô½Ð·ÖÅäºÍ¿Í»§½Ó¼û½ÚÔìµÈÖ°ÄÜ ¡£

2020Äê5ÔÂ20ÈÕ˼¿Æ£¨Cisco£©¹Ù·½°ä²¼¹«¸æ£¬½¨¸´ÁËÒ»¸öUnified Contact Center Express£¨Unified CCX£©ÖеÄÑϳÁ·ì϶£¨CVE-2020-3280£© ¡£¸Ã·ì϶ԴÓÚCisco Unified CCX ÔÚÖ´Ðз´ÐòÁл¯²Ù×÷ʱ£¬JavaÔ¶³ÌÖÎÀí½çÃæÃ»ÓжÔÓû§ÊäÈë½øÐÐÑéÖ¤£¬µ¼Ö¹¥»÷ÕßÄܹ»ÔÚδÊÚȨµÄÇé¿öÏ·¢ËÍÒ»¸ö¶ñÒâµÄJava¶ÔÏ󣬲¢ÔÚÊÜÓ°ÏìÉ豸ÉÏÒÔrootȨÏÞÖ´ÐÐËÁÒâ´úÂë ¡£


0x02 ´ëÖý¨Òé


˼¿Æ¹Ù·½ÒѾ­°ä²¼Ð°汾½¨¸´ÁËÕâЩ·ì϶£¬ÇëÓйØÓû§¾¡¿ìÉý¼¶½øÐзÀ»¤£¬ÆäÖÐCiscoUnified CCX 12.0(1)ES03ºÍCisco Unified CCX 12.5°æ±¾²»Êܸ÷ì϶ӰÏì ¡£

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-uccx-rce-GMSC6RKN


0x03 ÓйØÐÂÎÅ


https://www.zdnet.com/article/cisco-critical-java-flaw-strikes-call-center-in-a-box-patch-urgently/#ftag=RSSbaffb68


0x04 ²Î¿¼Á´½Ó


https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-uccx-rce-GMSC6RKN


0x05 ¹¦·òÏß


2020-05-20 Cisco¹Ù·½°ä²¼¹«¸æ

2020-05-22 VSRC°ä²¼·ì϶¹«¸æ


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾