¡¾·ì϶¹«¸æ¡¿Cisco Small Business VPN·ÓÉÆ÷ËÁÒâ´úÂëÖ´Ðзì϶£¨CVE-2021-1609£©
°ä²¼¹¦·ò 2021-08-050x00 ·ì϶¸ÅÊö
CVE ID | CVE-2021-1609 | ʱ ¼ä | 2021-08-04 |
Àà ÐÍ | ´úÂëÖ´ÐÐ | µÈ ¼¶ | ÑϳÁ |
Ô¶³ÌÀûÓà | ÊÇ | Ó°ÏìÁìÓò | |
¹¥»÷¸´ÔÓ¶È | µÍ | ¿ÉÓÃÐÔ | ¸ß |
Óû§½»»¥ | ÎÞ | ËùÐèȨÏÞ | ÎÞ |
PoC/EXP | δ¹«¿ª | ÔÚÒ°ÀûÓà | ·ñ |
0x01 ·ì϶ÏêÇé

2021Äê8ÔÂ4ÈÕ£¬Cisco°ä²¼°²È«²¼¸æ£¬½¨¸´ÁËÆäSmall Business VPN ·ÓÉÆ÷ÖеĶà¸ö°²È«·ì϶£¬ÆäÖÐ×îΪÑϳÁµÄ·ì϶ΪCVE-2021-1609£¨CVSSÆÀ·Ö9.8£©£¬¹¥»÷ÕßÄܹ»ÀûÓô˷ì϶Զ³ÌÖ´ÐÐËÁÒâ´úÂë»òÔì³É»Ø¾ø·þÎñ¡£
ÓÉÓÚHTTP ÒªÇóδÕýÈ·ÑéÖ¤£¬Cisco Small Business RV340¡¢RV340W¡¢RV345ºÍRV345PË«WANǧÕ×VPN·ÓÉÆ÷»ùÓÚWebµÄÖÎÀí½çÃæ´æÔÚ°²È«·ì϶¡£Î´¾Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÄܹ»Í¨¹ýÏòÊÜÓ°ÏìµÄÉ豸·¢ËͶñÒâHTTP ÒªÇóÀ´ÀûÓô˷ì϶¡£³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷Õß¿ÉÄÜÔÚÊÜÓ°ÏìµÄÉ豸ÉÏÖ´ÐÐËÁÒâ´úÂë»òµ¼ÖÂÉ豸³ÁмÓÔØ£¬´Ó¶øÔì³É»Ø¾ø·þÎñ£¨DoS£©¡£
³ý´ËÖ®±í£¬Cisco Small Business RV340¡¢RV340W¡¢RV345ºÍRV345PË«WANǧÕ×VPN·ÓÉÆ÷»ùÓÚWebµÄÖÎÀí½çÃæÖл¹´æÔÚÒ»¸öºÅÁî×¢Èë·ì϶£¨CVE-2021-1610£¬CVSSÆÀ·Ö7.2£©£¬¾¹ýÉí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÄܹ»Í¨¹ýÏòÊÜÓ°ÏìµÄÉ豸·¢ËͶñÒâHTTP ÒªÇóÀ´ÀûÓô˷ì϶£¬²¢×îÖÕ¿ÉÄÜÒÔrootÉí·ÝÔÚϵͳÉÏÖ´ÐÐËÁÒâºÅÁî¡£
Ó°ÏìÁìÓò
ÈôÊÇCisco Small Business RoutersÔËÐеĹ̼þ°æ±¾Ó×ÓÚ1.0.03.22£¬ÕâЩ·ì϶½«Ó°Ï죨ÊÜÓ°ÏìµÄ VPN ·ÓÉÆ÷ÐͺÅĬÈϽûÓÃÔ¶³ÌÖÎÀíÖ°ÄÜ£©£º
RV340Ë«WANǧÕ×VPN·ÓÉÆ÷
RV340WË«WANǧÕ×ÎÞÏßAC VPN·ÓÉÆ÷
RV345Ë«WANǧÕ×VPN·ÓÉÆ÷
RV345P Ë«WANǧÕ×VPN·ÓÉÆ÷
0x02 ´ëÖý¨Òé
Ŀǰ£¬CiscoÒѾÔڹ̼þ°æ±¾ 1.0.03.22 ¼°¸ü¸ß°æ±¾Öн¨¸´ÁËÕâЩ·ì϶£¬½¨ÒéʵʱÉý¼¶¸üÐÂ:
½øÈëCisco.com ÉϵÄÈí¼þÏÂÔØÖÐÐÄ£¬µ¥»÷¡°ä¯ÀÀÈ«Êý¡±²¢µ¼º½ÖÁ¡°ÏÂÔØÖ÷Ò³¡± >¡°Â·ÓÉÆ÷¡± >¡°Ó×ÐÍÆóҵ·ÓÉÆ÷¡± >¡°Ó×ÐÍÆóÒµ RV ϵÁзÓÉÆ÷¡±¡£
ÏÂÔØÁ´½Ó£º
https://software.cisco.com/download/home
0x03 ²Î¿¼Á´½Ó
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-rv340-cmdinj-rcedos-pY8J3qfy
https://www.bleepingcomputer.com/news/security/cisco-fixes-critical-high-severity-pre-auth-flaws-in-vpn-routers/
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-1609
0x04 ¸üа汾
°æ±¾ | ÈÕÆÚ | Åú¸ÄÄÚÈÝ |
V1.0 | 2021-08-05 | ³õ´Î°ä²¼ |
0x05 Îĵµ¸½Â¼
CNVD£ºwww.cnvd.org.cn
CNNVD£ºwww.cnnvd.org.cn
CVE£ºcve.mitre.org
NVD£ºnvd.nist.gov
CVSS£ºwww.first.org
0x06 ¹ØÓÚGA»Æ½ð¼×
¹Ø×¢ÒÔϹ«¼ÒºÅ£¬»ñÈ¡¸ü¶à×ÊѶ£º



¾©¹«Íø°²±¸11010802024551ºÅ