¡¾Îó²îͨ¸æ¡¿Cisco Small Business VPN·ÓÉÆ÷í§Òâ´úÂëÖ´ÐÐÎó²î£¨CVE-2021-1609£©

Ðû²¼Ê±¼ä 2021-08-05

0x00 Îó²î¸ÅÊö

CVE     ID

CVE-2021-1609

ʱ      ¼ä

2021-08-04

Àà      ÐÍ

´úÂëÖ´ÐÐ

µÈ      ¼¶

ÑÏÖØ

Ô¶³ÌʹÓÃ

ÊÇ

Ó°Ïì¹æÄ£


¹¥»÷ÖØÆ¯ºó

µÍ

¿ÉÓÃÐÔ

¸ß

Óû§½»»¥

ÎÞ

ËùÐèȨÏÞ

ÎÞ

PoC/EXP

δ¹ûÕæ

ÔÚҰʹÓÃ

·ñ

 

0x01 Îó²îÏêÇé

image.png

2021Äê8ÔÂ4ÈÕ£¬£¬£¬£¬£¬£¬CiscoÐû²¼Ç徲ͨ¸æ£¬£¬£¬£¬£¬£¬ÐÞ¸´ÁËÆäSmall Business VPN ·ÓÉÆ÷ÖеĶà¸öÇå¾²Îó²î£¬£¬£¬£¬£¬£¬ÆäÖÐ×îΪÑÏÖØµÄÎó²îΪCVE-2021-1609£¨CVSSÆÀ·Ö9.8£©£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔʹÓôËÎó²îÔ¶³ÌÖ´ÐÐí§Òâ´úÂë»òÔì³É¾Ü¾øÐ§ÀÍ¡£¡£ ¡£¡£

ÓÉÓÚHTTP ÇëÇóδ׼ȷÑéÖ¤£¬£¬£¬£¬£¬£¬Cisco Small Business RV340¡¢RV340W¡¢RV345ºÍRV345PË«WANǧÕ×VPN·ÓÉÆ÷»ùÓÚWebµÄÖÎÀí½çÃæ±£´æÇå¾²Îó²î¡£¡£ ¡£¡£Î´¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß¿ÉÒÔͨ¹ýÏòÊÜÓ°ÏìµÄ×°±¸·¢ËͶñÒâHTTP ÇëÇóÀ´Ê¹ÓôËÎó²î¡£¡£ ¡£¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷ÕßÄܹ»ÔÚÊÜÓ°ÏìµÄ×°±¸ÉÏÖ´ÐÐí§Òâ´úÂë»òµ¼ÖÂ×°±¸ÖØÐ¼ÓÔØ£¬£¬£¬£¬£¬£¬´Ó¶øÔì³É¾Ü¾øÐ§ÀÍ£¨DoS£©¡£¡£ ¡£¡£

³ý´ËÖ®Í⣬£¬£¬£¬£¬£¬Cisco Small Business RV340¡¢RV340W¡¢RV345ºÍRV345PË«WANǧÕ×VPN·ÓÉÆ÷»ùÓÚWebµÄÖÎÀí½çÃæÖл¹±£´æÒ»¸öÏÂÁî×¢ÈëÎó²î£¨CVE-2021-1610£¬£¬£¬£¬£¬£¬CVSSÆÀ·Ö7.2£©£¬£¬£¬£¬£¬£¬¾­ÓÉÉí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß¿ÉÒÔͨ¹ýÏòÊÜÓ°ÏìµÄ×°±¸·¢ËͶñÒâHTTP ÇëÇóÀ´Ê¹ÓôËÎó²î£¬£¬£¬£¬£¬£¬²¢×îÖÕÄܹ»ÒÔrootÉí·ÝÔÚϵͳÉÏÖ´ÐÐí§ÒâÏÂÁî¡£¡£ ¡£¡£

 

Ó°Ïì¹æÄ£

ÈôÊÇCisco Small Business RoutersÔËÐеĹ̼þ°æ±¾Ð¡ÓÚ1.0.03.22£¬£¬£¬£¬£¬£¬ÕâЩÎó²î½«Ó°Ï죨ÊÜÓ°ÏìµÄ VPN ·ÓÉÆ÷ÐͺÅĬÈϽûÓÃÔ¶³ÌÖÎÀí¹¦Ð§£©£º

RV340Ë«WANǧÕ×VPN·ÓÉÆ÷

RV340WË«WANǧÕ×ÎÞÏßAC VPN·ÓÉÆ÷

RV345Ë«WANǧÕ×VPN·ÓÉÆ÷

RV345P Ë«WANǧÕ×VPN·ÓÉÆ÷

 

0x02 ´¦Öóͷ£½¨Òé

ÏÖÔÚ£¬£¬£¬£¬£¬£¬CiscoÒѾ­Ôڹ̼þ°æ±¾ 1.0.03.22 ¼°¸ü¸ß°æ±¾ÖÐÐÞ¸´ÁËÕâЩÎó²î£¬£¬£¬£¬£¬£¬½¨ÒéʵʱÉý¼¶¸üÐÂ:

½øÈëCisco.com ÉϵÄÈí¼þÏÂÔØÖÐÐÄ£¬£¬£¬£¬£¬£¬µ¥»÷¡°ä¯ÀÀËùÓС±²¢µ¼º½ÖÁ¡°ÏÂÔØÖ÷Ò³¡± >¡°Â·ÓÉÆ÷¡± >¡°Ð¡ÐÍÆóҵ·ÓÉÆ÷¡± >¡°Ð¡ÐÍÆóÒµ RV ϵÁзÓÉÆ÷¡±¡£¡£ ¡£¡£

ÏÂÔØÁ´½Ó£º

https://software.cisco.com/download/home

 

0x03 ²Î¿¼Á´½Ó

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-rv340-cmdinj-rcedos-pY8J3qfy

https://www.bleepingcomputer.com/news/security/cisco-fixes-critical-high-severity-pre-auth-flaws-in-vpn-routers/

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-1609

 

0x04 ¸üа汾

°æ±¾

ÈÕÆÚ

ÐÞ¸ÄÄÚÈÝ

V1.0

2021-08-05

Ê×´ÎÐû²¼

 

0x05 Îĵµ¸½Â¼

CNVD£ºwww.cnvd.org.cn

CNNVD£ºwww.cnnvd.org.cn

CVE£ºcve.mitre.org

NVD£ºnvd.nist.gov

CVSS£ºwww.first.org

 

0x06 ¹ØÓÚc7c7ÓéÀÖÆ½Ì¨

¹Ø×¢ÒÔϹ«Öںţ¬£¬£¬£¬£¬£¬»ñÈ¡¸ü¶à×ÊѶ£º

image.png