¡¾·ì϶¹«¸æ¡¿ Cisco Jabber12Ô¶à¸ö°²È«·ì϶
°ä²¼¹¦·ò 2020-12-110x00 ·ì϶¸ÅÊö
²úÆ·Ãû³Æ | CVE ID | Àà ÐÍ | ·ì϶µÈ¼¶ | Ô¶³ÌÀûÓà |
Cisco Jabber | CVE-2020-26085 | RCE | ÑϳÁ | ÊÇ |
CVE-2020-27127 | δÊÚȨ½Ó¼û | ÖÐΣ | ÊÇ | |
CVE-2020-27132 | ÐÅϢй¶ | ÖÐΣ | ÊÇ | |
CVE-2020-27133 | ºÅÁî×¢Èë | ¸ßΣ | ÊÇ | |
CVE-2020-27134 | ¾ç±¾×¢Èë | ¸ßΣ | ÊÇ |
0x01 ·ì϶ÏêÇé

Cisco JabberÊÇÒ»¸ö¼´Ê±ÐÂÎźÍweb»áÒé×ÀÃæÀûÓ÷¨Ê½£¬ËüʹÓÿÉÀ©´óÐÂÎźÍ״̬ºÍ̸£¨XMPP£©ÔÚÓû§Ö®¼ä´«µÝÐÂÎÅ¡£¸ÃÀûÓ÷¨Ê½»ùÓÚChromium Embedded Framework£¨CEF£©¹¹½¨£¬ÆäUIʹÓÃHTML¡¢CSSºÍJavaScriptµÈweb¼¼Êõ¡£
2020Äê12ÔÂ10ÈÕ£¬Cisco°ä²¼°²È«²¼¸æ£¬JabberÖдæÔÚ¶à¸ö°²È«·ì϶£¨CVE-2020-26085¡¢CVE-2020-27127¡¢CVE-2020-27132¡¢CVE-2020-27133ºÍCVE-2020-27134£©¡£ÕâЩ·ì϶²¢²»Ï໥ÒÀÀµ£¬¹¥»÷Õß¿ÉÄÜÀûÓÃËüÃÇÔÚϵͳÉÏÖ´ÐÐËÁÒâ´úÂ룬»òÇÔÈ¡Ãô¸ÐÐÅÏ¢¡£
ÒªÀûÓÃCVE-2020-26085ºÍCVE-2020-27134ÕâÁ½¸öÐÂÎÅ´¦Ö÷ì϶£¬¹¥»÷Õß±ØÒª½Ó¼ûͳһXMPPÓò»òʹÓÃÆäËü²½ÖèÏòCisco Jabber¿Í»§¶Ë·¢ËÍ¿ÉÀ©´óÐÂÎźÍ״̬ºÍ̸£¨XMPP£©ÐÂÎÅ¡£´¦ÓÚphone-onlyģʽÏÂÇÒδÆôÓÃXMPPÐÂÎÅ·þÎñµÄCisco Jabber²»ÈÝÒ×Êܵ½¹¥»÷¡£´Ë±í£¬ÈôÊǽ«Cisco JabberÅäÖÃΪʹÓÃXMPPÐÂÎÅ´«µÝÒÔ±íµÄÆäËüÐÂÎÅ´«µÝ·þÎñ£¬Ôò·ì϶ÎÞ·¨ÀûÓá£
·ì϶ÏêÇéÈçÏ£º
Cisco JabberÐÂÎÅ´¦ÖÃÖеÄËÁÒâ´úÂëÖ´Ðзì϶£¨CVE-2020-26085£©
¸Ã·ì϶ÊÇÓʼþÄÚÈÝÑéÖ¤²»ÕýÈ·µ¼Öµģ¬ÆäCVSSÆÀ·Ö9.9¡£¹¥»÷ÕßÄܹ»Í¨¹ýÏòÊÜÓ°ÏìµÄJabber¿Í»§¶Ë·¢ËͶñÒâµÄXMPPÐÂÎÅÀ´ÀûÓô˷ì϶¡£³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷Õß¿ÉÄÜÒÔÔËÐÐCisco Jabber¿Í»§¶ËµÄÕË»§È¨ÏÞÔÚÖ¸±êϵͳÉÏÖ´ÐÐËÁÒâ´úÂë¡£
Ó°ÏìÁìÓò£º
Windows °æCisco Jabber
MacOS°æCisco Jabber
Cisco Jabber for Windows×Ô½ç˵ºÍ̸´¦Ö÷¨Ê½Î´ÊÚȨ½Ó¼û·ì϶£¨CVE-2020-27127£©
¸Ã·ì϶ÊǶÔJabberºÍ̸´¦Ö÷¨Ê½µÄÊäÈë´¦Öò»µ±µ¼Öµģ¬ÆäCVSSÆÀ·Ö4.3¡£¹¥»÷ÕßÄܹ»Í¨¹ýÊèµ¼Ö¸±êÓû§µ¥»÷µç×ÓÓʼþ»òÆäËüÐÂÎÅ´«µÝƽ̨·¢Ë͵ÄÐÂÎÅÖеÄÁ´½ÓÀ´ÀûÓô˷ì϶¡£³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷ÕßÄܹ»ÏòCisco Jabber¿Í»§¶Ë·¢ËÍËÁÒâºÅÁ´Ó¶ø¿ÉÄÜʹ¹¥»÷ÕßÅú¸ÄÀûÓ÷¨Ê½ÅäÖá£
Ó°ÏìÁìÓò£º
Windows °æCisco Jabber
Cisco JabberÐÅϢй¶·ì϶£¨VE-2020-27132£©
¸Ã·ì϶ÊÇÓʼþÄÚÈÝÑéÖ¤²»ÕýÈ·µ¼Öµģ¬ÆäCVSSÆÀ·Ö6.5¡£¹¥»÷ÕßÄܹ»Í¨¹ýÏòÖ¸±êϵͳ·¢ËͶñÒâÐÂÎÅÀ´ÀûÓô˷ì϶¡£³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷ÕßÄܹ»Ê¹Jabber½«Éí·ÝÑéÖ¤µÈÃô¸ÐÐÅÏ¢·µ»Ø¸øÁíÒ»¸öϵͳ£¬ÒÔ±ãÓÚ½øÒ»²½¹¥»÷¡£
Ó°ÏìÁìÓò£º
Windows °æCisco Jabber
MacOS°æCisco Jabber
Cisco Jabber for Windows×Ô½ç˵ºÍ̸´¦Ö÷¨Ê½ºÅÁî×¢Èë·ì϶£¨CVE-2020-27133£©
¸Ã·ì϶ÊǶÔJabberºÍ̸´¦Ö÷¨Ê½µÄÊäÈë´¦Öò»µ±µ¼Öµģ¬ÆäCVSSÆÀ·Ö8.8¡£¹¥»÷ÕßÄܹ»Í¨¹ýÊèµ¼Ö¸±êÓû§µ¥»÷µç×ÓÓʼþ»òÆäËüÐÂÎÅ´«µÝƽ̨·¢Ë͵ÄÐÂÎÅÖеÄÁ´½ÓÀ´ÀûÓô˷ì϶¡£³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷Õß¿ÉÄÜÒÔÔËÐÐCisco Jabber¿Í»§¶ËµÄÕË»§È¨ÏÞÔÚÖ¸±êϵͳÉÏÖ´ÐÐËÁÒâºÅÁî¡£
Ó°ÏìÁìÓò£º
Windows °æCisco Jabber
Cisco JabberÐÂÎÅ´¦Öþ籾עÈë·ì϶£¨CVE-2020-27134£©
¸Ã·ì϶ÊÇÓʼþÄÚÈÝÑéÖ¤²»ÕýÈ·µ¼Öµģ¬ÆäCVSSÆÀ·Ö8.0¡£¹¥»÷ÕßÄܹ»Í¨¹ýÏòÊÜÓ°ÏìµÄJabber¿Í»§¶Ë·¢ËͶñÒâµÄXMPPÐÂÎÅÀ´ÀûÓô˷ì϶¡£Í¨¹ýÊèµ¼Ö¸±êÓû§½øÐÐÐÂÎŽ»»¥£¬¹¥»÷ÕßÄܹ»ÔÚJabberÐÂÎÅ´°¿Ú½çÃæÄÚ×¢ÈëËÁÒâ¾ç±¾´úÂë¡£³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷Õß¿ÉÄÜÒÔÔËÐÐCisco Jabber¿Í»§¶ËµÄÕË»§È¨ÏÞÔÚMacOS»òWindowsÖ¸±êϵͳÉÏÖ´ÐÐËÁÒâ´úÂë¡£ÔÚÒÆ¶¯Æ½Ì¨Éϳɹ¦ÀûÓô˷ì϶µÄ¹¥»÷ÕßÄܹ»ÔËÐнÅÕý±¾Åú¸ÄÀûÓ÷¨Ê½½çÃæ»ò´ÓJabberÀûÓ÷¨Ê½»ñÈ¡Ãô¸ÐÐÅÏ¢¡£
Ó°ÏìÁìÓò£º
Windows °æCisco Jabber
MacOS°æCisco Jabber
mobile platforms°æCisco Jabber
0x02 ´ëÖý¨Òé
ĿǰCiscoÒѾ½¨¸´ÁËÓйطì϶£¬½¨Òé²Î¿¼Ï±íʵʱ¸üС£
Windows°æCisco Jabber | ÊÜÓ°Ïì°æ±¾ | ½¨¸´°æ±¾ |
12.1֮ǰ°æ±¾ | Ǩáãµ½¹Ì¶¨°æ±¾ | |
12.1 | 12.1.4 | |
12.5 | 12.5.3 | |
12.6 | 12.6.4 | |
12.7 | 12.7.3 | |
12.8 | 12.8.4 | |
12.9 | 12.9.3 | |
MacOS°æCisco Jabber | 12.7¼°Ö®Ç°°æ±¾ | Ǩáãµ½¹Ì¶¨°æ±¾ |
12.8 | 12.8.5 | |
12.9 | 12.9.4 | |
AndroidºÍiOS°æCisco Jabber | 12.8¼°Ö®Ç°°æ±¾ | Ǩáãµ½¹Ì¶¨°æ±¾ |
12.9 | 12.9.4 |
ÏÂÔØÁ´½Ó£º
https://software.cisco.com/download/find
0x03 ²Î¿¼Á´½Ó
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-jabber-ZktzjpgO
https://threatpost.com/critical-cisco-jabber-bug-get-updated-fix/162143/
https://securityaffairs.co/wordpress/112163/hacking/cisco-jabber-rce.html?
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-26085
0x04 ¹¦·òÏß
2020-12-10 Cisco°ä²¼·ì϶²¼¸æ
2020-12-11 VSRC°ä²¼°²È«¹«¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/



¾©¹«Íø°²±¸11010802024551ºÅ