ThroughTek P2P SDKÐÅϢй¶Îó²î£¨CVE-2021-32934£©
Ðû²¼Ê±¼ä 2021-06-160x00 Îó²î¸ÅÊö
CVE ID | CVE-2021-32934 | ʱ ¼ä | 2021-06-16 |
Àà ÐÍ | ÐÅϢй¶ | µÈ ¼¶ | ÑÏÖØ |
Ô¶³ÌʹÓà | ÊÇ | Ó°Ïì¹æÄ£ | |
¹¥»÷ÖØÆ¯ºó | µÍ | ¿ÉÓÃÐÔ | ÎÞ |
Óû§½»»¥ | ÎÞ | ËùÐèȨÏÞ | ÎÞ |
PoC/EXP | ÒѹûÕæ | ÔÚҰʹÓà | ·ñ |
0x01 Îó²îÏêÇé

2021Äê06ÔÂ15ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬ÃÀ¹úÍøÂçÇå¾²ºÍ»ù´¡ÉèÊ©Çå¾²¾Ö (CISA)Ðû²¼Ô¤¾¯£¬£¬£¬£¬£¬£¬£¬£¬ÊýÒÔ°ÙÍò¼ÆµÄÁªÍøÇå¾²ºÍ¼ÒÓÃÉãÏñÍ·°üÀ¨Ò»¸öÐÅϢй¶Îó²î£¨CVE-2021-32934£©£¬£¬£¬£¬£¬£¬£¬£¬ÆäCVSS v3»ù±¾ÆÀ·ÖΪ9.1¡£¡£¡£¡£¡£¡£¡£
¸ÃÎó²î±£´æÓÚThroughTekµÄP2P SDKÖС£¡£¡£¡£¡£¡£¡£ÓÉÓÚÍâµØ×°±¸ºÍThroughTek ЧÀÍÆ÷Ö®¼äÃ÷ÎÄ´«ÊäÊý¾Ý£¬£¬£¬£¬£¬£¬£¬£¬Ô¶³Ì¹¥»÷Õß¿ÉÒÔͨ¹ýʹÓôËÎó²îÇÔÈ¡Ãô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£²¢ÇÒ¸Ã×é¼þÒѱ»¶à¼ÒÇå¾²ÉãÏñÍ·µÄÔʼװ±¸ÖÆÔìÉÌ (OEM) ÒÔ¼°ÎïÁªÍø×°±¸ÖÆÔìÉÌʹÓ㬣¬£¬£¬£¬£¬£¬£¬ÀýÈçÓ¤¶ùºÍ³èÎï¼à¿ØÉãÏñÍ·£¬£¬£¬£¬£¬£¬£¬£¬ÒÔ¼°»úеÈËºÍµç³Ø×°±¸¡£¡£¡£¡£¡£¡£¡£
δÊÚȨÉó²éÕâЩװ±¸µÄÐÅÏ¢½«µ¼ÖÂÖî¶àÎÊÌ⣺¹ØÓÚÒªº¦»ù´¡ÉèÊ©ÔËÓªÉÌºÍÆóÒµ¶øÑÔ£¬£¬£¬£¬£¬£¬£¬£¬ÒôÊÓÆµÐÅÏ¢»áй¶Ãô¸ÐµÄÓªÒµÊý¾Ý¡¢Éú²ú»ò¾ºÕùÉñÃØ¡¢¿ÉÓÃÓÚÎïÀí¹¥»÷µÄÆ½ÃæÍ¼ÐÅÏ¢ÒÔ¼°Ô±¹¤ÐÅÏ¢µÈ£»£»£»¶ø¹ØÓÚ¼ÒÍ¥Óû§À´Ëµ£¬£¬£¬£¬£¬£¬£¬£¬½«Ð¹Â¶ÆäÒþ˽¡£¡£¡£¡£¡£¡£¡£
Ó°Ïì¹æÄ££º
3.1.10ÒÔϰ汾
´øÓÐnossl±êÇ©µÄSDK°æ±¾
²»Ê¹ÓÃAuthKey¾ÙÐÐIOTCÅþÁ¬µÄ×°±¸¹Ì¼þ
ʹÓÃAVAPIÄ£¿£¿£¿£¿é¶ø²»ÆôÓÃDTLS»úÖÆµÄ×°±¸¹Ì¼þ
ʹÓÃP2PTunnel»òRDTÄ£¿£¿£¿£¿éµÄ×°±¸¹Ì¼þ
0x02 ´¦Öóͷ£½¨Òé
ÏÖÔÚ´ËÎó²îÒѾÐÞ¸´£¬£¬£¬£¬£¬£¬£¬£¬ThroughTek½¨ÒéÏà¹ØÖÆÔìÉÌʵÑéÒÔÏ»º½â²½·¥£º
ÈôÊÇ SDK°æ±¾ >= 3.1.10 £¬£¬£¬£¬£¬£¬£¬£¬ÇëÆôÓà authkey ºÍ DTLS¡£¡£¡£¡£¡£¡£¡£
ÈôÊÇ SDK°æ±¾< 3.1.10£¬£¬£¬£¬£¬£¬£¬£¬Ç뽫¿âÉý¼¶µ½ v3.3.1.0 »ò v3.4.2.0 ²¢ÆôÓà authkey/DTLS¡£¡£¡£¡£¡£¡£¡£
¹Ù·½Á´½Ó£º
https://www.throughtek.com/about-throughteks-kalay-platform-security-mechanism/
ͨÓÃÇå¾²½¨Òé
Ö»¹ÜïÔÌËùÓпØÖÆÏµÍ³×°±¸»òϵͳµÄÍøÂç̻¶ÇéÐΣ¬£¬£¬£¬£¬£¬£¬£¬²¢È·±£ËüÃDz»¿É´Ó»¥ÁªÍø»á¼û¡£¡£¡£¡£¡£¡£¡£
½«¿ØÖÆÏµÍ³ÍøÂçºÍÔ¶³Ì×°±¸ÖÃÓÚ·À»ðǽ֮ºó£¬£¬£¬£¬£¬£¬£¬£¬²¢½«ÆäÓëÉÌÒµÍøÂç¸ôÀë¡£¡£¡£¡£¡£¡£¡£
µ±ÐèÒªÔ¶³Ì»á¼ûʱʹÓÃÇå¾²µÄÒªÁ죬£¬£¬£¬£¬£¬£¬£¬ÈçÐéÄâרÓÃÍøÂ磨VPN£©£¬£¬£¬£¬£¬£¬£¬£¬²¢È·±£VPNÊÇ×îа汾¡£¡£¡£¡£¡£¡£¡£
0x03 ²Î¿¼Á´½Ó
https://us-cert.cisa.gov/ics/advisories/icsa-21-166-01
https://threatpost.com/millions-connected-cameras-eavesdropping/166950/
https://www.throughtek.com/about-throughteks-kalay-platform-security-mechanism/
0x04 ʱ¼äÏß
2021-06-15 CISAÐû²¼Ç徲ͨ¸æ
2021-06-16 VSRCÐû²¼Ç徲ͨ¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/



¾©¹«Íø°²±¸11010802024551ºÅ