CVE-2020-3161| Cisco IP PhonesÔ¶³Ì´úÂëÖ´Ðзì϶¹«¸æ
°ä²¼¹¦·ò 2020-04-210x00 ·ì϶¸ÅÊö

0x01 ·ì϶ÏêÇé
4ÔÂ15ÈÕ£¬£¬£¬£¬£¬£¬Ë¼¿Æ°ä²¼°²È«²¼¸æ£¬£¬£¬£¬£¬£¬³ÆÆä IP µç»°µÄ web ·þÎñÆ÷ÖдæÔÚÒ»¸öÑϳÁȱµã£¬£¬£¬£¬£¬£¬¿Éµ¼ÖÂδ¾Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÒÔ root ȨÏÞÖ´ÐдúÂë»ò·¢Æð»Ø¾ø·þÎñ¹¥»÷¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶ӰÏìÓÃÓÚÖÐÓׯóÒµµÄ¶à¸ö˼¿Æ IP µç»°°æ±¾£¬£¬£¬£¬£¬£¬CVSSÆÀ·Ö9.8¡£¡£¡£¡£¡£¡£¡£
¸Ã·ì϶ÊÇÓÉÓÚ²»×ã¶ÔHTTPÒªÇóµÄÕýÈ·ÊäÈëÑéÖ¤ËùÖ¡£¡£¡£¡£¡£¡£¡£ ¹¥»÷Õß½«Ò»¸öÌØÊâ»ú¹ØµÄ HTTP ÒªÇó·¢Ë͵½ /deviceconfig/setActivationCode¶Ëµã£¨ÔÚÖ¸±êÉ豸µÄ web ·þÎñÆ÷ÉÏ£©£¬£¬£¬£¬£¬£¬ÔÚ libHTTPService.so ÖУ¬£¬£¬£¬£¬£¬/deviceconfig/setActivationCode Ö®ºóµÄ²ÎÊýÓÃÓÚͨ¹ýÒ»¸ö sprint º¯ÊýŲÓô´½¨Ð嵀 URI£¬£¬£¬£¬£¬£¬¸Ã²ÎÊý×Ö·û´®µÄ³¤¶È²¢Î´µÃµ½²é³¡£¡£¡£¡£¡£¡£¡£³É¹¦ÀûÓô˷ì϶ʹ¹¥»÷Õß¿ÉÄÜÒÔrootȨÏÞÔ¶³ÌÖ´ÐдúÂ룬£¬£¬£¬£¬£¬»òµ¼Ö³ÁмÓÔØÊÜÓ°ÏìµÄIPµç»°£¬£¬£¬£¬£¬£¬µ¼Ö»ؾø·þÎñ¡£¡£¡£¡£¡£¡£¡£
EXP: https://cxsecurity.com/issue/WLB-2020040100
0x02 ´ëÖý¨Òé
Éý¼¶²¹¶¡£¡£¡£¡£¡£¡£¡£¬£¬£¬£¬£¬£¬ÏÂÔØÁ´½Ó£º
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-voip-phones-rce-dos-rB6EeRXs
һʱ´ëÊ©£º½ûÓà IP µç»°É쵀 web ½Ó¼ûȨÏÞ¡£¡£¡£¡£¡£¡£¡£
ĬÈÏÇé¿öÏ£¬£¬£¬£¬£¬£¬Web½Ó¼ûÊǽûÓõġ£¡£¡£¡£¡£¡£¡£ ÖÎÀíÔ±Äܹ»Í¨¹ýÒÔϲ½Öè´ÓCisco Unified Communications ManagerÖвé³Web½Ó¼ûÅäÖãºÑ¡ÔñDevice > Phone > Select a Phone£¬£¬£¬£¬£¬£¬¶øºó²é³Web ½Ó¼ûÊÇ·ñÉèÖÃΪ¡°ÆôÓá±»ò¡°½ûÓᱡ£¡£¡£¡£¡£¡£¡£ ÈôÊǽ«ÆäÉèÖÃΪ¡°½ûÓá±£¬£¬£¬£¬£¬£¬ÔòIPµç»°²»»áÊܵ½¹¥»÷¡£¡£¡£¡£¡£¡£¡£
0x03 ÓйØÐÂÎÅ
https://threatpost.com/critical-cisco-ip-phone-rce-flaw/154864/
0x04 ²Î¿¼Á´½Ó
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-voip-phones-rce-dos-rB6EeRXs
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-202004-1099
0x05 ¹¦·òÏß
2020-04-15 Cisco°ä²¼²¼¸æ
2020-04-15 CVE°ä²¼¸Ã·ì϶


¾©¹«Íø°²±¸11010802024551ºÅ