Cisco Small Business ·ÓÉÆ÷¶à¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²î
Ðû²¼Ê±¼ä 2021-02-040x00 Îó²î¸ÅÊö
CVE ID | ʱ ¼ä | 2021-02-04 | |
Àà ÐÍ | RCE | µÈ ¼¶ | ÑÏÖØ |
Ô¶³ÌʹÓà | ÊÇ | Ó°Ïì¹æÄ£ |
0x01 Îó²îÏêÇé

2021Äê02ÔÂ03ÈÕ£¬£¬£¬£¬£¬£¬£¬CiscoÐû²¼Ç徲ͨ¸æ£¬£¬£¬£¬£¬£¬£¬ÐÞ¸´ÁËCisco Small Business ·ÓÉÆ÷ÖеĶà¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨Îó²î×·×ÙΪCVE-2021-1289¡¢CVE-2021-1290¡¢CVE-2021-1291¡¢CVE-2021-1292¡¢CVE-2021-1293¡¢CVE-2021-1294ºÍCVE-2021-1295£©£¬£¬£¬£¬£¬£¬£¬ÆäCVSSÆÀ·Ö¾ùΪ9.8¡£¡£¡£¡£¡£¡£¡£¡£
ÓÉÓÚδ׼ȷÑéÖ¤HTTPÇëÇ󣬣¬£¬£¬£¬£¬£¬Cisco Small Business RV160¡¢RV160W¡¢RV260¡¢RV260PºÍRV260W VPN·ÓÉÆ÷»ùÓÚWebµÄÖÎÀí½çÃæÖб£´æ¶à¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£¡£¡£¡£¡£¡£¡£¡£Î´¾Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔͨ¹ý·¢ËͶñÒâµÄHTTPÇëÇóÀ´Ê¹ÓÃÕâЩÎó²î¡£¡£¡£¡£¡£¡£¡£¡£ÀֳɵÄʹÓÃÕâЩÎó²îµÄ¹¥»÷Õß¿ÉÒÔÒÔrootÓû§µÄÉí·ÝÔÚ×°±¸ÉÏÔ¶³ÌÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¡£¡£ÕâЩÎó²îÎÞÐèÓû§ÑéÖ¤¼´¿ÉÔ¶³ÌʹÓ㬣¬£¬£¬£¬£¬£¬ÏÖÔÚÒѱ»ÐÞ¸´¡£¡£¡£¡£¡£¡£¡£¡£
Ó°Ïì¹æÄ£
ÈôÊÇ×°±¸ÔËÐеĹ̼þ°æ±¾µÍÓÚ1.0.01.02£¬£¬£¬£¬£¬£¬£¬ÔòÕâЩÎó²î»áÓ°ÏìÒÔÏÂCisco Small Business ·ÓÉÆ÷£º
RV160 VPN·ÓÉÆ÷
RV160WÎÞÏßAC VPN·ÓÉÆ÷
RV260 VPN·ÓÉÆ÷
´øPOEµÄRV260P VPN·ÓÉÆ÷
RV260WÎÞÏßAC VPN·ÓÉÆ÷
0x02 ´¦Öóͷ£½¨Òé
ÏÖÔÚ£¬£¬£¬£¬£¬£¬£¬CiscoÒѾÔڹ̼þ°æ±¾1.0.01.02¼°¸ü¸ß°æ±¾ÖÐÐÞ¸´ÁËÕâЩÎó²î£¬£¬£¬£¬£¬£¬£¬½¨Òé²Î¿¼ÏÂͼʵʱÏÂÔØ¸üС£¡£¡£¡£¡£¡£¡£¡£

ÏÂÔØÁ´½Ó£º
https://software.cisco.com/download/home
0x03 ²Î¿¼Á´½Ó
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-rv160-260-rce-XZeFkNHf
https://www.bleepingcomputer.com/news/security/cisco-fixes-critical-code-execution-bugs-in-smb-vpn-routers/
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-1289
0x04 ʱ¼äÏß
2021-02-03 CiscoÐû²¼Ç徲ͨ¸æ
2021-02-04 VSRCÐû²¼Ç徲ͨ¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/



¾©¹«Íø°²±¸11010802024551ºÅ