Cisco Small Business·ÓÉÆ÷Ô¶³ÌºÅÁîÖ´Ðзì϶£¨CVE-2021-1287£©

°ä²¼¹¦·ò 2021-03-18

0x00 ·ì϶¸ÅÊö

CVE  ID

CVE-2021-1287

ʱ  ¼ä

2021-03-18

Àà   ÐÍ

 Ô¶³ÌºÅÁîÖ´ÐÐ

µÈ  ¼¶

¸ßΣ

Ô¶³ÌÀûÓÃ

ÊÇ

Ó°ÏìÁìÓò


 

0x01 ·ì϶ÏêÇé

image.png

 

2021Äê03ÔÂ17ÈÕ£¬£¬£¬£¬£¬£¬£¬Cisco°ä²¼°²È«²¼¸æ£¬£¬£¬£¬£¬£¬£¬¹«¿ªÁËÆäÓ×ÐÍÆóÒµRV132WºÍRV134W·ÓÉÆ÷ÖеÄÒ»¸öÔ¶³ÌºÅÁîÖ´Ðзì϶£¬£¬£¬£¬£¬£¬£¬·ì϶׷×ÙΪCVE-2021-1287£¬£¬£¬£¬£¬£¬£¬ÆäCVSSÆÀ·ÖΪ7.2¡£¡£¡£¡£¡£¡£¡£¡£

¸Ã·ì϶´æÔÚÓÚWebµÄÖÎÀí½çÃæÖУ¬£¬£¬£¬£¬£¬£¬ÓÉÓÚûÓÐÕýÈ·ÑéÖ¤Óû§µÄÊäÈ룬£¬£¬£¬£¬£¬£¬¾­¹ýÉí·ÝÑéÖ¤µÄ¹¥»÷ÕßÄܹ»Í¨¹ýÏòÊÜÓ°ÏìµÄÉ豸·¢ËͶñÒâµÄHTTPÒªÇóÀ´ÀûÓô˷ì϶¡£¡£¡£¡£¡£¡£¡£¡£³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷Õß¿ÉÄÜÒÔrootÓû§µÄÉí·ÝÔÚϵͳÉÏÖ´ÐÐËÁÒâ´úÂë¡¢µ¼ÖÂÉ豸³ÁмÓÔØ»ò»Ø¾ø·þÎñ£¨DoS£©¡£¡£¡£¡£¡£¡£¡£¡£

½ñÄê2Ô£¬£¬£¬£¬£¬£¬£¬Cisco»¹½¨¸´ÁËÆäÓ×ÐÍÆóÒµVPN·ÓÉÆ÷²úƷϵÁУ¨RV160¡¢RV160W¡¢RV260¡¢RV260PºÍRV260W VPN·ÓÉÆ÷£©ÖеĶà¸öÑϳÁ·ì϶£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÄܹ»ÀûÓÃÕâЩ·ì϶À´²é¿´¡¢´Û¸ÄÊý¾Ý£¬£¬£¬£¬£¬£¬£¬»òÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£¡£

 

Ó°ÏìÁìÓò

RV132W ADSL2 + Wireless-N VPN·ÓÉÆ÷£¨¹Ì¼þ°æ±¾ < 1.0.1.15£©

RV134W VDSL2 Wireless-AC VPN·ÓÉÆ÷£¨¹Ì¼þ°æ±¾ < 1.0.1.21£©

 

0x02 ´ëÖý¨Òé

Ŀǰ¹Ù·½Òѽ¨¸´ÁË´Ë·ì϶£¬£¬£¬£¬£¬£¬£¬½¨ÒéÉý¼¶ÖÁÒÔϰ汾£º

RV132W ADSL2 + Wireless-N VPN·ÓÉÆ÷¹Ì¼þ°æ±¾ >= 1.0.1.15

RV134W VDSL2 Wireless-AC VPN·ÓÉÆ÷¹Ì¼þ°æ±¾ >= 1.0.1.21

ÏÂÔØÁ´½Ó£º

https://software.cisco.com/download/home

 

0x03 ²Î¿¼Á´½Ó

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-rv-132w134w-overflow-Pptt4H2p

https://threatpost.com/cisco-security-hole-small-business-routers/164859/

/new_type/aqtg/20210204/22362.html

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-1287

 

0x04 ¹¦·òÏß

2021-03-17  Cisco°ä²¼°²È«²¼¸æ

2021-03-18  VSRC°ä²¼°²È«¹«¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/

image.png