ThroughTek P2P SDKÐÅϢй¶·ì϶£¨CVE-2021-32934£©
°ä²¼¹¦·ò 2021-06-160x00 ·ì϶¸ÅÊö
CVE ID | CVE-2021-32934 | ʱ ¼ä | 2021-06-16 |
Àà ÐÍ | ÐÅϢй¶ | µÈ ¼¶ | ÑϳÁ |
Ô¶³ÌÀûÓà | ÊÇ | Ó°ÏìÁìÓò | |
¹¥»÷¸´ÔÓ¶È | µÍ | ¿ÉÓÃÐÔ | ÎÞ |
Óû§½»»¥ | ÎÞ | ËùÐèȨÏÞ | ÎÞ |
PoC/EXP | Òѹ«¿ª | ÔÚÒ°ÀûÓà | ·ñ |
0x01 ·ì϶ÏêÇé

2021Äê06ÔÂ15ÈÕ£¬£¬£¬£¬£¬£¬£¬ÃÀ¹úÍøÂ簲ȫºÍ»ù´¡ÉèÊ©°²È«¾Ö (CISA)°ä²¼Ô¤¾¯£¬£¬£¬£¬£¬£¬£¬ÊýÒÔ°ÙÍò¼ÆµÄÁªÍø°²È«ºÍ¼ÒÓÃÉãÏñÍ·Ô̺¬Ò»¸öÐÅϢй¶·ì϶£¨CVE-2021-32934£©£¬£¬£¬£¬£¬£¬£¬ÆäCVSS v3¸ù»ùÆÀ·ÖΪ9.1¡£¡£¡£¡£¡£¡£
¸Ã·ì϶´æÔÚÓÚThroughTekµÄP2P SDKÖÓ×£¡£¡£¡£¡£¡£ÓÉÓÚ±¾µØÉ豸ºÍThroughTek ·þÎñÆ÷Ö®¼äÃ÷ÎÄ´«ÊäÊý¾Ý£¬£¬£¬£¬£¬£¬£¬Ô¶³Ì¹¥»÷ÕßÄܹ»Í¨¹ýÀûÓô˷ì϶ÇÔÈ¡Ãô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£¡£²¢ÇÒ¸Ã×é¼þÒѱ»¶à¼Ò°²È«ÉãÏñÍ·µÄÔʼÉ豸Ôì×÷ÉÌ (OEM) ÒÔ¼°ÎïÁªÍøÉ豸Ôì×÷ÉÌʹÓ㬣¬£¬£¬£¬£¬£¬ÀýÈçÓ¤¶ùºÍ³èÎï¼à¿ØÉãÏñÍ·£¬£¬£¬£¬£¬£¬£¬ÒÔ¼°»úеÈËºÍµç³ØÉ豸¡£¡£¡£¡£¡£¡£
δÊÚȨ²é¿´ÕâЩÉ豸µÄÐÅÏ¢½«µ¼ÖÂÖî¶àÎÊÌ⣺¶ÔÓڹؼü»ù´¡ÉèÊ©ÔËÓªÉÌºÍÆóÒµ¶øÑÔ£¬£¬£¬£¬£¬£¬£¬ÒôÊÓÆµÐÅÏ¢»áй¼ûô¸ÐµÄÒµÎñÊý¾Ý¡¢³ö²ú»ò¾ºÕù»úÃÜ¡¢¿ÉÓÃÓÚÎïÀí¹¥»÷µÄÆ½ÃæÍ¼ÐÅÏ¢ÒÔ¼°Ô±¹¤ÐÅÏ¢µÈ£»£»£»£»£»£»£»¶ø¶ÔÓÚ¼ÒÍ¥Óû§À´Ëµ£¬£¬£¬£¬£¬£¬£¬½«Ð¹Â¶ÆäÒþÖÔ¡£¡£¡£¡£¡£¡£
Ó°ÏìÁìÓò£º
3.1.10ÒÔϰ汾
´øÓÐnossl±êÇ©µÄSDK°æ±¾
²»Ê¹ÓÃAuthKey½øÐÐIOTCÏνӵÄÉ豸¹Ì¼þ
ʹÓÃAVAPIÄ£¿£¿£¿£¿£¿£¿é¶ø²»ÆôÓÃDTLS»úÔìµÄÉ豸¹Ì¼þ
ʹÓÃP2PTunnel»òRDTÄ£¿£¿£¿£¿£¿£¿éµÄÉ豸¹Ì¼þ
0x02 ´ëÖý¨Òé
Ŀǰ´Ë·ì϶ÒѾ½¨¸´£¬£¬£¬£¬£¬£¬£¬ThroughTek½¨ÒéÓйØÔì×÷ÉÌÖ´ÐÐÒÔÏ»º½â´ëÊ©£º
ÈôÊÇ SDK°æ±¾ >= 3.1.10 £¬£¬£¬£¬£¬£¬£¬ÇëÆôÓà authkey ºÍ DTLS¡£¡£¡£¡£¡£¡£
ÈôÊÇ SDK°æ±¾< 3.1.10£¬£¬£¬£¬£¬£¬£¬Ç뽫¿âÉý¼¶µ½ v3.3.1.0 »ò v3.4.2.0 ²¢ÆôÓà authkey/DTLS¡£¡£¡£¡£¡£¡£
¹Ù·½Á´½Ó£º
https://www.throughtek.com/about-throughteks-kalay-platform-security-mechanism/
ͨÓð²È«½¨Òé
¾¡Á¿Ï÷¼õËùÓнÚÔìϵͳÉ豸»òϵͳµÄÍøÂç¶³öÇé¿ö£¬£¬£¬£¬£¬£¬£¬²¢È·±£ËüÃDz»ÄÜ´Ó»¥ÁªÍø½Ó¼û¡£¡£¡£¡£¡£¡£
½«½ÚÔìÏµÍ³ÍøÂçºÍÔ¶³ÌÉ豸ÖÃÓÚ·À»ðǽ֮ºó£¬£¬£¬£¬£¬£¬£¬²¢½«ÆäÓëóÒ×ÍøÂç¸ôÀë¡£¡£¡£¡£¡£¡£
µ±±ØÒªÔ¶³Ì½Ó¼ûʱʹÓð²È«µÄ²½Ö裬£¬£¬£¬£¬£¬£¬ÈçÐ鹹רÓÃÍøÂ磨VPN£©£¬£¬£¬£¬£¬£¬£¬²¢È·±£VPNÊÇ×îа汾¡£¡£¡£¡£¡£¡£
0x03 ²Î¿¼Á´½Ó
https://us-cert.cisa.gov/ics/advisories/icsa-21-166-01
https://threatpost.com/millions-connected-cameras-eavesdropping/166950/
https://www.throughtek.com/about-throughteks-kalay-platform-security-mechanism/
0x04 ¹¦·òÏß
2021-06-15 CISA°ä²¼°²È«²¼¸æ
2021-06-16 VSRC°ä²¼°²È«¹«¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/



¾©¹«Íø°²±¸11010802024551ºÅ