¡¾·ì϶¹«¸æ¡¿Cisco¶à¸ö°²È«·ì϶
°ä²¼¹¦·ò 2021-01-140x00 ·ì϶¸ÅÊö
2021Äê01ÔÂ13ÈÕ£¬Cisco°ä²¼°²È«²¼¸æ£¬¹«¿ªÁËÆä¶à¸ö²úÆ·ÖеÄ67¸ö·ì϶²¹¶¡£¬ÕâЩ·ìÏ¶Éæ¼°AnyConnect°²È«Òƶ¯¿Í»§¶Ë¡¢RV110W¡¢RV130¡¢RV130WºÍRV215WÓ×ÐÍÆóҵ·ÓÉÆ÷¼°Cisco»¥ÁªÒƶ¯ÂÄÀú£¨CMX£©µÈ¡£
0x01 ·ì϶ÏêÇé

Cisco»¥ÁªÒƶ¯ÂÄÀúȨÏÞÉý¼¶·ì϶£¨CVE-2021-1144£©
¸Ã·ì϶´æÔÚÓÚ˼¿Æ»¥ÁªÒƶ¯ÂÄÀú£¨CMX£©ÖУ¬ÊǶԸü¸ÄÃÜÂëµÄÊÚȨ²é³´¦Öò»µ±µ¼Öµģ¬ÆäCVSSÆÀ·Ö8.8¡£¾¹ýÉí·ÝÑéÖ¤µÄ¹¥»÷ÕßÄܹ»Í¨¹ý·¢ËͶñÒâHTTPÒªÇóÀ´ÀûÓô˷ì϶¡£³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷ÕßÄܹ»¸ü¸ÄϵͳÉÏÈκÎÓû§£¨Ô̺¬ÖÎÀíÓû§£©µÄÃÜÂëÀ´¼ÙÒâ¸ÃÓû§¡£µ«ÒªÀûÓô˷ì϶£¬¹¥»÷Õß±ØÐëÕ¼Óо¹ýÉí·ÝÑéÖ¤µÄCMXÕÊ»§¡£
Ó°ÏìÁìÓò
Cisco CMX°æ±¾10.6.0¡¢10.6.1ºÍ10.6.2
½¨¸´°æ±¾
10.6.3¼°¸ü¸ß°æ±¾
Cisco AnyConnect Secure Mobility Client for Windows DLL ×¢Èë·ì϶£¨CVE-2021-1237£©
Ä£¿é»¯¶ËµãÈí¼þ²úÆ·AnyConnect Secure Mobility ClientΪ¶ËµãÌṩÁË¿í·ºµÄ°²È«·þÎñ£¬ÈçÔ¶³Ì½Ó¼û¡¢Web°²È«Ö°ÄܺÍÖÜÓα£»¤¡£
¸Ã·ì϶´æÔÚÓÚWindows°æCisco AnyConnect°²È«Òƶ¯¿Í»§¶ËµÄÍøÂç½Ó¼ûÖÎÀíÆ÷ºÍWeb°²È«´úÀí×é¼þÖУ¬ÊÇÀûÓ÷¨Ê½¶ÔÔËÐÐʱ¼ÓÔØµÄ×ÊÔ´ÑéÖ¤²»¼°µ¼Öµģ¬ÆäCVSSÆÀ·Ö7.8¡£¹¥»÷ÕßÄܹ»Í¨¹ýÔÚϵͳµÄÌØ¶¨õè¾¶ÖвåÈëÅäÖÃÎļþÀ´ÀûÓô˷ì϶£¬´Ó¶øµ¼ÖÂÀûÓ÷¨Ê½Æô¶¯Ê±¼ÓÔØ¶ñÒâµÄDLLÎļþ¡£³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷ÕßÄܹ»Ê¹ÓÃSYSTEMȨÏÞÔÚÊÜÓ°ÏìµÄÍÆËã»úÉÏÖ´ÐÐËÁÒâ´úÂë¡£µ«ÒªÀûÓô˷ì϶£¬¹¥»÷Õß±ØÒªÔÚWindowsϵͳÉÏÓµÓÐÓÐЧµÄÍ´´¦¡£
Ó°ÏìÁìÓò
Cisco AnyConnect Secure Mobility Client for Windows 4.9.04043֮ǰµÄ°æ±¾
½¨¸´°æ±¾
Cisco AnyConnect Secure Mobility Client for Windows 4.9.04043¼°¸ü¸ß°æ±¾
´Ë±í£¬Ë¼¿ÆÓ×ÐÍÆóÒµRV110W¡¢RV130¡¢RV130WºÍRV215W·ÓÉÆ÷ÖдæÔÚ5¸öºÅÁî×¢Èë·ì϶£¨CVE-2021-1146¡¢CVE-2021-1147¡¢CVE-2021-1148¡¢CVE-2021-1149ºÍCVE-2021-1150£©£¬Ô¶³Ì¹¥»÷ÕßÄܹ»Í¨¹ýÀûÓÃÕâЩ·ì϶עÈëËÁÒâºÅÁî¡£
³ýÉÏÊö·ì϶±í£¬Ë¼¿ÆÓ×ÐÍÆóÒµRV110W¡¢RV130¡¢RV130WºÍRV215W»¹´æÔÚ60¸ö·ì϶£¬¹¥»÷ÕßÄܹ»Í¨¹ýÏòÊÜÓ°ÏìµÄÉ豸·¢ËͶñÒâµÄHTTPÒªÇóÀ´ÀûÓÃÕâЩ·ì϶£¬³É¹¦ÀûÓÃÕâЩ·ì϶µÄ¹¥»÷Õß¿ÉÄÜÒÔrootÓû§Éí·ÝÔڵײã²Ù×÷ϵͳÉÏÖ´ÐÐËÁÒâ´úÂë¡¢µ¼ÖÂÉ豸³ÁмÓÔØ»ò»Ø¾ø·þÎñ¡£
0x02 ´ëÖý¨Òé
½¨Òé²Î¿¼Cisco¹Ù·½°ä²¼µÄ°²È«²¼¸æÉý¼¶ÖÁ×îа汾¡£
ÏÂÔØÁ´½Ó£º
https://software.cisco.com/download/find
0x03 ²Î¿¼Á´½Ó
https://tools.cisco.com/security/center/publicationListing.x?product=Cisco&sort=-day_sir#~Vulnerabilities
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-anyconnect-dll-injec-pQnryXLf
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cmxpe-75Asy9k
https://threatpost.com/cisco-flaw-cmx-software-retailers/163027/
0x04 ¹¦·òÏß
2021-01-13 Cisco°ä²¼°²È«¸üÐÂ
2021-01-14 VSRC°ä²¼°²È«¹«¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/



¾©¹«Íø°²±¸11010802024551ºÅ