¡¾Îó²îͨ¸æ¡¿ Cisco Jabber12Ô¶à¸öÇå¾²Îó²î

Ðû²¼Ê±¼ä 2020-12-11

0x00 Îó²î¸ÅÊö

²úÆ·Ãû³Æ

CVE ID

Àà ÐÍ

Îó²îÆ·¼¶

Ô¶³ÌʹÓÃ

 Cisco Jabber

CVE-2020-26085

RCE

ÑÏÖØ

ÊÇ

CVE-2020-27127

δÊÚȨ»á¼û

ÖÐΣ

ÊÇ

CVE-2020-27132

ÐÅϢй¶

ÖÐΣ

ÊÇ

CVE-2020-27133

ÏÂÁî×¢Èë

¸ßΣ

ÊÇ

CVE-2020-27134

¾ç±¾×¢Èë

¸ßΣ

ÊÇ

0x01 Îó²îÏêÇé

 

image.png

 

Cisco JabberÊÇÒ»¸ö¼´Ê±ÐÂÎźÍweb¾Û»á×ÀÃæÓ¦ÓóÌÐò£¬£¬£¬£¬ËüʹÓÿÉÀ©Õ¹ÐÂÎźÍ״̬ЭÒ飨XMPP£©ÔÚÓû§Ö®¼äת´ïÐÂÎÅ¡£ ¡£¡£¸ÃÓ¦ÓóÌÐò»ùÓÚChromium Embedded Framework£¨CEF£©¹¹½¨£¬£¬£¬£¬ÆäUIʹÓÃHTML¡¢CSSºÍJavaScriptµÈwebÊÖÒÕ¡£ ¡£¡£

2020Äê12ÔÂ10ÈÕ£¬£¬£¬£¬CiscoÐû²¼Ç徲ͨ¸æ£¬£¬£¬£¬JabberÖб£´æ¶à¸öÇå¾²Îó²î£¨CVE-2020-26085¡¢CVE-2020-27127¡¢CVE-2020-27132¡¢CVE-2020-27133ºÍCVE-2020-27134£©¡£ ¡£¡£ÕâЩÎó²î²¢²»Ï໥ÒÀÀµ£¬£¬£¬£¬¹¥»÷ÕßÄܹ»Ê¹ÓÃËüÃÇÔÚϵͳÉÏÖ´ÐÐí§Òâ´úÂ룬£¬£¬£¬»òÇÔÈ¡Ãô¸ÐÐÅÏ¢¡£ ¡£¡£

ҪʹÓÃCVE-2020-26085ºÍCVE-2020-27134ÕâÁ½¸öÐÂÎÅ´¦Öóͷ£Îó²î£¬£¬£¬£¬¹¥»÷ÕßÐèÒª»á¼ûͳһXMPPÓò»òʹÓÃÆäËüÒªÁìÏòCisco Jabber¿Í»§¶Ë·¢ËÍ¿ÉÀ©Õ¹ÐÂÎźÍ״̬ЭÒ飨XMPP£©ÐÂÎÅ¡£ ¡£¡£´¦ÓÚphone-onlyģʽÏÂÇÒδÆôÓÃXMPPÐÂÎÅЧÀ͵ÄCisco Jabber½ûÖ¹Ò×Êܵ½¹¥»÷¡£ ¡£¡£±ðµÄ£¬£¬£¬£¬ÈôÊǽ«Cisco JabberÉèÖÃΪʹÓÃXMPPÐÂÎÅת´ïÒÔÍâµÄÆäËüÐÂÎÅת´ïЧÀÍ£¬£¬£¬£¬ÔòÎó²îÎÞ·¨Ê¹Óᣠ¡£¡£

Îó²îÏêÇéÈçÏ£º

Cisco JabberÐÂÎÅ´¦Öóͷ£ÖеÄí§Òâ´úÂëÖ´ÐÐÎó²î£¨CVE-2020-26085£©

¸ÃÎó²îÊÇÓʼþÄÚÈÝÑéÖ¤²»×¼È·µ¼ÖµÄ£¬£¬£¬£¬ÆäCVSSÆÀ·Ö9.9¡£ ¡£¡£¹¥»÷Õß¿ÉÒÔͨ¹ýÏòÊÜÓ°ÏìµÄJabber¿Í»§¶Ë·¢ËͶñÒâµÄXMPPÐÂÎÅÀ´Ê¹ÓôËÎó²î¡£ ¡£¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷ÕßÄܹ»ÒÔÔËÐÐCisco Jabber¿Í»§¶ËµÄÕË»§È¨ÏÞÔÚÄ¿µÄϵͳÉÏÖ´ÐÐí§Òâ´úÂë¡£ ¡£¡£

Ó°Ïì¹æÄ££º

Windows °æCisco Jabber

MacOS°æCisco Jabber

 

Cisco Jabber for Windows×Ô½ç˵ЭÒé´¦Öóͷ£³ÌÐòδÊÚȨ»á¼ûÎó²î£¨CVE-2020-27127£©

¸ÃÎó²îÊǶÔJabberЭÒé´¦Öóͷ£³ÌÐòµÄÊäÈë´¦Öóͷ£²»µ±µ¼ÖµÄ£¬£¬£¬£¬ÆäCVSSÆÀ·Ö4.3¡£ ¡£¡£¹¥»÷Õß¿ÉÒÔͨ¹ýÖ¸µ¼Ä¿µÄÓû§µ¥»÷µç×ÓÓʼþ»òÆäËüÐÂÎÅת´ïƽ̨·¢Ë͵ÄÐÂÎÅÖеÄÁ´½ÓÀ´Ê¹ÓôËÎó²î¡£ ¡£¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔÏòCisco Jabber¿Í»§¶Ë·¢ËÍí§ÒâÏÂÁ£¬£¬£¬´Ó¶ø¿ÉÄÜʹ¹¥»÷ÕßÐÞ¸ÄÓ¦ÓóÌÐòÉèÖᣠ¡£¡£

Ó°Ïì¹æÄ££º

Windows °æCisco Jabber

 

Cisco JabberÐÅϢй¶Îó²î£¨VE-2020-27132£©

¸ÃÎó²îÊÇÓʼþÄÚÈÝÑéÖ¤²»×¼È·µ¼ÖµÄ£¬£¬£¬£¬ÆäCVSSÆÀ·Ö6.5¡£ ¡£¡£¹¥»÷Õß¿ÉÒÔͨ¹ýÏòÄ¿µÄϵͳ·¢ËͶñÒâÐÂÎÅÀ´Ê¹ÓôËÎó²î¡£ ¡£¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔʹJabber½«Éí·ÝÑéÖ¤µÈÃô¸ÐÐÅÏ¢·µ»Ø¸øÁíÒ»¸öϵͳ£¬£¬£¬£¬ÒÔ±ãÓÚ½øÒ»²½¹¥»÷¡£ ¡£¡£

Ó°Ïì¹æÄ££º

Windows °æCisco Jabber

MacOS°æCisco Jabber

 

Cisco Jabber for Windows×Ô½ç˵ЭÒé´¦Öóͷ£³ÌÐòÏÂÁî×¢ÈëÎó²î£¨CVE-2020-27133£©

¸ÃÎó²îÊǶÔJabberЭÒé´¦Öóͷ£³ÌÐòµÄÊäÈë´¦Öóͷ£²»µ±µ¼ÖµÄ£¬£¬£¬£¬ÆäCVSSÆÀ·Ö8.8¡£ ¡£¡£¹¥»÷Õß¿ÉÒÔͨ¹ýÖ¸µ¼Ä¿µÄÓû§µ¥»÷µç×ÓÓʼþ»òÆäËüÐÂÎÅת´ïƽ̨·¢Ë͵ÄÐÂÎÅÖеÄÁ´½ÓÀ´Ê¹ÓôËÎó²î¡£ ¡£¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷ÕßÄܹ»ÒÔÔËÐÐCisco Jabber¿Í»§¶ËµÄÕË»§È¨ÏÞÔÚÄ¿µÄϵͳÉÏÖ´ÐÐí§ÒâÏÂÁî¡£ ¡£¡£

Ó°Ïì¹æÄ££º

Windows °æCisco Jabber

 

Cisco JabberÐÂÎÅ´¦Öóͷ£¾ç±¾×¢ÈëÎó²î£¨CVE-2020-27134£©

¸ÃÎó²îÊÇÓʼþÄÚÈÝÑéÖ¤²»×¼È·µ¼ÖµÄ£¬£¬£¬£¬ÆäCVSSÆÀ·Ö8.0¡£ ¡£¡£¹¥»÷Õß¿ÉÒÔͨ¹ýÏòÊÜÓ°ÏìµÄJabber¿Í»§¶Ë·¢ËͶñÒâµÄXMPPÐÂÎÅÀ´Ê¹ÓôËÎó²î¡£ ¡£¡£Í¨¹ýÖ¸µ¼Ä¿µÄÓû§¾ÙÐÐÐÂÎŽ»»¥£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔÔÚJabberÐÂÎÅ´°¿Ú½çÃæÄÚ×¢Èëí§Òâ¾ç±¾´úÂë¡£ ¡£¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷ÕßÄܹ»ÒÔÔËÐÐCisco Jabber¿Í»§¶ËµÄÕË»§È¨ÏÞÔÚMacOS»òWindowsÄ¿µÄϵͳÉÏÖ´ÐÐí§Òâ´úÂë¡£ ¡£¡£ÔÚÒÆ¶¯Æ½Ì¨ÉÏÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔÔËÐнÅÔ­À´ÐÞ¸ÄÓ¦ÓóÌÐò½çÃæ»ò´ÓJabberÓ¦ÓóÌÐò»ñÈ¡Ãô¸ÐÐÅÏ¢¡£ ¡£¡£

Ó°Ïì¹æÄ££º

Windows °æCisco Jabber

MacOS°æCisco Jabber

mobile platforms°æCisco Jabber

 

0x02 ´¦Öóͷ£½¨Òé

ÏÖÔÚCiscoÒѾ­ÐÞ¸´ÁËÏà¹ØÎó²î£¬£¬£¬£¬½¨Òé²Î¿¼Ï±íʵʱ¸üС£ ¡£¡£

Windows°æCisco Jabber

ÊÜÓ°Ïì°æ±¾

ÐÞ¸´°æ±¾

12.1֮ǰ°æ±¾

Ǩáãµ½Àο¿°æ±¾

12.1

12.1.4

12.5

12.5.3

12.6

12.6.4

12.7

12.7.3

12.8

12.8.4

12.9

12.9.3

MacOS°æCisco Jabber

12.7¼°Ö®Ç°°æ±¾

Ǩáãµ½Àο¿°æ±¾

12.8

12.8.5

12.9

12.9.4

AndroidºÍiOS°æCisco Jabber

12.8¼°Ö®Ç°°æ±¾

Ǩáãµ½Àο¿°æ±¾

12.9

12.9.4

 

ÏÂÔØÁ´½Ó£º

https://software.cisco.com/download/find

 

0x03 ²Î¿¼Á´½Ó

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-jabber-ZktzjpgO

https://threatpost.com/critical-cisco-jabber-bug-get-updated-fix/162143/

https://securityaffairs.co/wordpress/112163/hacking/cisco-jabber-rce.html?

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-26085

 

0x04 ʱ¼äÏß

2020-12-10  CiscoÐû²¼Îó²îͨ¸æ

2020-12-11  VSRCÐû²¼Ç徲ͨ¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/

image.png