CVE-2020-3161| Cisco IP PhonesÔ¶³Ì´úÂëÖ´ÐÐÎó²îͨ¸æ

Ðû²¼Ê±¼ä 2020-04-21

0x00 Îó²î¸ÅÊö


ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾

ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾



0x01 Îó²îÏêÇé


ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾




4ÔÂ15ÈÕ£¬£¬£¬£¬£¬ £¬£¬Ë¼¿ÆÐû²¼Ç徲ͨ¸æ£¬£¬£¬£¬£¬ £¬£¬³ÆÆä IP µç»°µÄ web ЧÀÍÆ÷Öб£´æÒ»¸öÑÏÖØÈ±ÏÝ£¬£¬£¬£¬£¬ £¬£¬¿Éµ¼ÖÂδ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÒÔ root ȨÏÞÖ´ÐдúÂë»ò·¢¶¯¾Ü¾øÐ§À͹¥»÷¡£¡£¡£ ¡£¡£¡£¡£¡£¸ÃÎó²îÓ°ÏìÓÃÓÚÖÐСÆóÒµµÄ¶à¸ö˼¿Æ IP µç»°°æ±¾£¬£¬£¬£¬£¬ £¬£¬CVSSÆÀ·Ö9.8¡£¡£¡£ ¡£¡£¡£¡£¡£

¸ÃÎó²îÊÇÓÉÓÚȱ·¦¶ÔHTTPÇëÇóµÄ׼ȷÊäÈëÑéÖ¤ËùÖ¡£¡£¡£ ¡£¡£¡£¡£¡£ ¹¥»÷Õß½«Ò»¸öÌØÊâ½á¹¹µÄ HTTP ÇëÇó·¢Ë͵½ /deviceconfig/setActivationCode¶Ëµã£¨ÔÚÄ¿µÄ×°±¸µÄ web ЧÀÍÆ÷ÉÏ£©£¬£¬£¬£¬£¬ £¬£¬ÔÚ libHTTPService.so ÖУ¬£¬£¬£¬£¬ £¬£¬/deviceconfig/setActivationCode Ö®ºóµÄ²ÎÊýÓÃÓÚͨ¹ýÒ»¸ö sprint º¯ÊýŲÓý¨ÉèÐ嵀 URI£¬£¬£¬£¬£¬ £¬£¬¸Ã²ÎÊý×Ö·û´®µÄ³¤¶È²¢Î´»ñµÃ¼ì²é¡£¡£¡£ ¡£¡£¡£¡£¡£ÀÖ³ÉʹÓôËÎó²îʹ¹¥»÷ÕßÄܹ»ÒÔrootȨÏÞÔ¶³ÌÖ´ÐдúÂ룬£¬£¬£¬£¬ £¬£¬»òµ¼ÖÂÖØÐ¼ÓÔØÊÜÓ°ÏìµÄIPµç»°£¬£¬£¬£¬£¬ £¬£¬µ¼Ö¾ܾøÐ§ÀÍ¡£¡£¡£ ¡£¡£¡£¡£¡£

EXP: https://cxsecurity.com/issue/WLB-2020040100


0x02 ´¦Öóͷ£½¨Òé


Éý¼¶²¹¶¡£¬£¬£¬£¬£¬ £¬£¬ÏÂÔØÁ´½Ó£º

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-voip-phones-rce-dos-rB6EeRXs

ÔÝʱ²½·¥£º½ûÓà IP µç»°É쵀 web »á¼ûȨÏÞ¡£¡£¡£ ¡£¡£¡£¡£¡£

ĬÈÏÇéÐÎÏ£¬£¬£¬£¬£¬ £¬£¬Web»á¼ûÊǽûÓõġ£¡£¡£ ¡£¡£¡£¡£¡£ ÖÎÀíÔ±¿ÉÒÔͨ¹ýÒÔÏÂÒªÁì´ÓCisco Unified Communications ManagerÖмì²éWeb»á¼ûÉèÖãºÑ¡ÔñDevice > Phone > Select a Phone£¬£¬£¬£¬£¬ £¬£¬È»ºó¼ì²éWeb »á¼ûÊÇ·ñÉèÖÃΪ¡°ÆôÓá±»ò¡°½ûÓᱡ£¡£¡£ ¡£¡£¡£¡£¡£ ÈôÊǽ«ÆäÉèÖÃΪ¡°½ûÓá±£¬£¬£¬£¬£¬ £¬£¬ÔòIPµç»°²»»áÊܵ½¹¥»÷¡£¡£¡£ ¡£¡£¡£¡£¡£


0x03 Ïà¹ØÐÂÎÅ


https://threatpost.com/critical-cisco-ip-phone-rce-flaw/154864/


0x04 ²Î¿¼Á´½Ó


https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-voip-phones-rce-dos-rB6EeRXs

http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-202004-1099


0x05 ʱ¼äÏß


2020-04-15 CiscoÐû²¼Í¨¸æ

2020-04-15 CVEÐû²¼¸ÃÎó²î



ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾