¡¾·ì϶¹«¸æ¡¿Cisco Enterprise NFVISÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶ (CVE-2021-34746)

°ä²¼¹¦·ò 2021-09-02

0x00 ·ì϶¸ÅÊö

CVE     ID

CVE-2021-34746

ʱ      ¼ä

2021-09-01

Àà      ÐÍ

Éí·ÝÑéÖ¤ÈÆ¹ý

µÈ      ¼¶

ÑϳÁ

Ô¶³ÌÀûÓÃ

ÊÇ

Ó°ÏìÁìÓò


¹¥»÷¸´ÔÓ¶È

µÍ

¿ÉÓÃÐÔ

¸ß

Óû§½»»¥

ÎÞ

ËùÐèȨÏÞ

ÎÞ

PoC/EXP

Òѹ«¿ª

ÔÚÒ°ÀûÓÃ

·ñ

 

0x01 ·ì϶ÏêÇé

image.png

 

2021Äê9ÔÂ1ÈÕ£¬£¬£¬£¬£¬Cisco°ä²¼°²È«²¼¸æ£¬£¬£¬£¬£¬½¨¸´ÁËÆäÆóÒµ NFV »ù´¡ÉèÊ©Èí¼þ (NFVIS) µÄ TACACS+ÈÏÖ¤¡¢ÊÚȨºÍ¼Æ·Ñ (AAA) Ö°ÄÜÖеÄÒ»¸öÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶£¨CVE-2021-34746£©£¬£¬£¬£¬£¬¸Ã·ì϶µÄCVSSv3ÆÀ·ÖΪ9.8¡£¡£¡£¡£¡£¡£¡£

ÓÉÓÚ¶Ô´«µÝ¸øÈÏÖ¤¾ç±¾µÄÓû§ÊäÈëµÄÑéÖ¤²»ÆëÈ«£¬£¬£¬£¬£¬Ô¶³Ì¹¥»÷ÕßÄܹ»Í¨¹ýÔÚÈÏÖ¤ÒªÇóÖÐ×¢Èë²ÎÊýÀ´ÀûÓô˷ì϶¡£¡£¡£¡£¡£¡£¡£³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷ÕßÄܹ»ÈƹýÈÏÖ¤£¬£¬£¬£¬£¬²¢ÒÔÖÎÀíÔ±Éí·ÝµÇ¼ÊÜÓ°ÏìµÄÉ豸¡£¡£¡£¡£¡£¡£¡£

˼¿Æ²úÆ·°²È«ÊÂÎñÏìÓ¦ÍŶӰµÊ¾£¬£¬£¬£¬£¬ÒÑÓкÏÓÃÓÚ´Ë·ì϶µÄPoC/EXP£¬£¬£¬£¬£¬Ä¿Ç°ÔÝδ·¢ÏÖ¶ñÒâÀûÓᣡ£¡£¡£¡£¡£¡£

 

Ó°ÏìÁìÓò

ÈôÊÇÅäÖÃÁËTACACS±í²¿ÈÏÖ¤²½Ö裬£¬£¬£¬£¬´Ë·ì϶»áÓ°ÏìCisco Enterprise NFVIS °æ±¾4.5.1¡£¡£¡£¡£¡£¡£¡£

×¢£º½öʹÓÃRADIUS»ò±¾µØÈÏÖ¤µÄÅäÖò»ÊÜÓ°Ïì¡£¡£¡£¡£¡£¡£¡£

 

0x02 ´ëÖý¨Òé

ĿǰCiscoÒѾ­½¨¸´ÁË´Ë·ì϶£¬£¬£¬£¬£¬½¨ÒéÊÜÓ°ÏìÓû§ÊµÊ±Éý¼¶¸üе½Cisco Enterprise NFVIS °æ±¾ 4.6.1 »ò¸ü¸ß°æ±¾¡£¡£¡£¡£¡£¡£¡£

ÏÂÔØÁ´½Ó£º

https://software.cisco.com/download/home

 

È·¶¨ÊÇ·ñÆôÓÃTACACS±í²¿ÈÏÖ¤

1.Ҫȷ¶¨É豸ÉÏÊÇ·ñÆôÓÃÁË TACACS ±í²¿ÈÏÖ¤Ö°ÄÜ£¬£¬£¬£¬£¬ÇëʹÓà show running-config tacacs-server ºÅÁî¡£¡£¡£¡£¡£¡£¡£ÒÔÏÂʾÀýÏÔʾÁ˵±TACACS±í²¿ÈÏÖ¤±»ÆôÓÃʱ£¬£¬£¬£¬£¬Cisco Enterprise NFVISÉÏshow running-config tacacs-serverºÅÁîµÄÊä³ö£º

nfvis# show running-config tacacs-server

tacacs-server host 192.168.1.1

 key           0

 shared-secret "example!23"

 admin-priv    15

 oper-priv     1

!

nfvis#

 

ÈôÊÇshow running-config tacacs-server ºÅÁîµÄÊä³öΪNo entries found£¬£¬£¬£¬£¬ÔòδÆôÓà TACACS ±í²¿ÈÏÖ¤Ö°ÄÜ¡£¡£¡£¡£¡£¡£¡£

2.ͨ¹ýGUI²é³­ÅäÖᣡ£¡£¡£¡£¡£¡£Ñ¡ÔñÅäÖà > Ö÷»ú > °²È« > Óû§ºÍ½ÇÉ«¡£¡£¡£¡£¡£¡£¡£ÈôÊÇÔÚ±í²¿ÈÏ֤Ͻç˵ÁËTACACS+Ö÷»ú£¬£¬£¬£¬£¬ÄÇô¸ÃÉ豸ÈÝÒ×Êܵ½´Ë·ì϶µÄÓ°Ïì¡£¡£¡£¡£¡£¡£¡£

 

0x03 ²Î¿¼Á´½Ó

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-nfvis-g2DMVVh

https://www.cisco.com/

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-34746

 

0x04 ¸üа汾

°æ±¾

ÈÕÆÚ

Åú¸ÄÄÚÈÝ

V1.0

2021-09-02

³õ´Î°ä²¼

 

0x05 Îĵµ¸½Â¼

CNVD£ºwww.cnvd.org.cn

CNNVD£ºwww.cnnvd.org.cn

CVE£ºcve.mitre.org

CVSS£ºwww.first.org

NVD£ºnvd.nist.gov

 

0x06 ¹ØÓÚ8827Ì«Ñô¼¯ÍÅ

¹Ø×¢ÒÔϹ«¼ÒºÅ£¬£¬£¬£¬£¬»ñÈ¡¸ü¶à×ÊѶ£º

image.png