Cisco Jabber¿Í»§¶Ë¶à¸ö°²È«·ì϶

°ä²¼¹¦·ò 2021-03-25

0x00 ·ì϶¸Å

Cisco JabberÊÇÒ»¸ö¼´Ê±ÐÂÎźÍweb»áÒé×ÀÃæÀûÓ÷¨Ê½£¬£¬£¬£¬£¬£¬£¬ËüʹÓÿÉÀ©´óÐÂÎźÍ״̬ºÍ̸£¨XMPP£©ÔÚÓû§Ö®¼ä´«µÝÐÂÎÅ¡£¡£¡£¡£¡£¡£¸ÃÀûÓ÷¨Ê½»ùÓÚChromium Embedded Framework£¨CEF£©¹¹½¨£¬£¬£¬£¬£¬£¬£¬ÆäUIʹÓÃHTML¡¢CSSºÍJavaScriptµÈweb¼¼Êõ¡£¡£¡£¡£¡£¡£

2021Äê03ÔÂ24ÈÕ£¬£¬£¬£¬£¬£¬£¬Cisco°ä²¼°²È«²¼¸æ£¬£¬£¬£¬£¬£¬£¬½¨¸´ÁËCisco JabberÖеĶà¸ö°²È«·ì϶¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÄÜÀûÓÃÕâЩ·ì϶ÔÚϵͳÉÏÖ´ÐÐËÁÒâ´úÂë¡¢½Ó¼ûÃô¸ÐÐÅÏ¢¡¢À¹½ØÊܱ£»£»£»£»£»£»¤µÄÍøÂçÁ÷Á¿»òµ¼Ö»ؾø·þÎñ£¨DoS£©¡£¡£¡£¡£¡£¡£

 

0x01 ·ì϶ÏêÇé

image.png

 

³ýÁËCVE-2021-1471±í£¬£¬£¬£¬£¬£¬£¬ÕâЩ·ì϶²»»áÓ°ÏìΪPhone-only ģʽºÍTeam Messaging ģʽµÄCisco Jabber¿Í»§¶ËÈí¼þ¡£¡£¡£¡£¡£¡£±¾´Î¹«¿ªµÄ·ì϶ÈçÏ£º

Cisco Jabberƽ̨

CVE ID

Windows

CVE-2021-1411¡¢CVE-2021-1417¡¢CVE-2021-1418¡¢CVE-2021-1469¡¢ CVE-2021-1471

MacOS

CVE-2021-1418 ¡¢CVE-2021-1471

Android ºÍ iOS

CVE-2021-1418 ¡¢ CVE-2021-1471

 

·ì϶ÏêÇéÈçÏ£º

Cisco JabberËÁÒâ´úÂëÖ´Ðзì϶£¨CVE-2021-1411£©

ÓÉÓÚÓʼþÄÚÈÝÑéÖ¤²»ÕýÈ·£¬£¬£¬£¬£¬£¬£¬Cisco Jabber for WindowsÖдæÔÚÒ»¸öËÁÒâ´úÂëÖ´Ðзì϶£¬£¬£¬£¬£¬£¬£¬ÆäCVSSÆÀ·ÖΪ9.9¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÄܹ»Í¨¹ýÏòÊÜÓ°ÏìµÄJabber¿Í»§¶ËÈí¼þ·¢ËͶñÒâµÄXMPPÐÂÎÅÀ´ÀûÓô˷ì϶£¬£¬£¬£¬£¬£¬£¬³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷Õß¿ÉÄÜÒÔÔËÐÐCisco Jabber¿Í»§¶ËÈí¼þµÄÓû§ÕÊ»§µÄȨÏÞʹÀûÓ÷¨Ê½ÔÚÖ¸±êϵͳÉÏÖ´ÐÐËÁÒⷨʽ£¬£¬£¬£¬£¬£¬£¬Õâ¿ÉÄܵ¼ÖÂËÁÒâ´úÂëÖ´ÐÓ×£¡£¡£¡£¡£¡£

µ«ÒªÀûÓô˷ì϶£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß±ØÒªÍ¨¹ýÊÜÓ°ÏìÈí¼þʹÓõÄXMPP·þÎñÆ÷½øÐÐÉí·ÝÑéÖ¤£¬£¬£¬£¬£¬£¬£¬ÄÜÁ¦½«¶ñÒâÔì×÷µÄXMPPÐÂÎÅ·¢Ë͵½Ö¸±êÉ豸¡£¡£¡£¡£¡£¡£

 

Cisco JabberËÁÒâ´úÂëÖ´Ðзì϶£¨CVE-2021-1469£©

ÓÉÓÚÓʼþÄÚÈÝÑéÖ¤²»ÕýÈ·£¬£¬£¬£¬£¬£¬£¬Cisco Jabber for WindowsÖдæÔÚÒ»¸öËÁÒâ´úÂëÖ´Ðзì϶£¬£¬£¬£¬£¬£¬£¬ÆäCVSSÆÀ·ÖΪ7.2¡£¡£¡£¡£¡£¡£Õ¼Óгö¸ñÅäÖõÄXMPP·þÎñÆ÷ÕÊ»§µÄ¹¥»÷ÕßÄܹ»Í¨¹ýÏòÊÜÓ°ÏìµÄÈí¼þ·¢ËͶñÒâµÄXMPPÐÂÎÅÀ´ÀûÓô˷ì϶¡£¡£¡£¡£¡£¡£³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷Õß¿ÉÄÜÒÔÔËÐÐCisco Jabber¿Í»§¶ËÈí¼þµÄÓû§ÕÊ»§µÄȨÏÞʹÀûÓ÷¨Ê½ÔÚÖ¸±êϵͳÉÏÖ´ÐÐËÁÒⷨʽ£¬£¬£¬£¬£¬£¬£¬Õâ¿ÉÄܵ¼ÖÂËÁÒâ´úÂëÖ´ÐÓ×£¡£¡£¡£¡£¡£

 

Cisco JabberÐÅϢй¶·ì϶£¨CVE-2021-1417£©

ÓÉÓÚÓʼþÄÚÈÝÑéÖ¤²»ÕýÈ·£¬£¬£¬£¬£¬£¬£¬Cisco Jabber for WindowsÖдæÔÚÒ»¸öÐÅϢй¶·ì϶£¬£¬£¬£¬£¬£¬£¬ÆäCVSSÆÀ·ÖΪ6.5¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÄܹ»Í¨¹ý½«¶ñÒâµÄXMPPÐÂÎÅ·¢Ë͵½Ö¸±êϵͳÀ´ÀûÓô˷ì϶£¬£¬£¬£¬£¬£¬£¬³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷ÕßÄܹ»Ê¹ÀûÓ÷¨Ê½½«Ãô¸ÐµÄÉí·ÝÑéÖ¤ÐÅÏ¢·µ»Ø¸øÁíÒ»¸öϵͳ£¬£¬£¬£¬£¬£¬£¬ÒÔ½«ÆäÓÃÓÚ½øÒ»²½µÄ¹¥»÷¡£¡£¡£¡£¡£¡£

 

Cisco JabberÖ¤ÊéÑéÖ¤·ì϶£¨CVE-2021-1471£©

ÓÉÓÚÖ¤ÊéÑéÖ¤²»ÕýÈ·£¬£¬£¬£¬£¬£¬£¬ ºÏÓÃÓÚWindows¡¢ MacOSºÍÒÆ¶¯Æ½Ì¨µÄCisco JabberÖдæÔÚÖ¤ÊéÑéÖ¤·ì϶£¬£¬£¬£¬£¬£¬£¬ÆäCVSSÆÀ·ÖΪ5.6¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÄܹ»Í¨¹ýʹÓÃȨÏÞÍøÂçµØÎ»À´À¹½ØÀ´×ÔÊÜÓ°ÏìÈí¼þµÄÍøÂçÒªÇó²¢³öʾ¶ñÒâÔì×÷µÄÖ¤ÊéÀ´ÀûÓô˷ì϶£¬£¬£¬£¬£¬£¬£¬³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷Õß¿ÉÄܲ鳭»òÅú¸ÄCisco Jabber¿Í»§¶ËÓë·þÎñÆ÷Ö®¼äµÄÏνӡ£¡£¡£¡£¡£¡£

 

Cisco Jabber»Ø¾ø·þÎñ·ì϶£¨CVE-2021-1418£©

ÓÉÓÚÓʼþÄÚÈÝÑéÖ¤²»ÕýÈ·£¬£¬£¬£¬£¬£¬£¬ºÏÓÃÓÚWindows¡¢ MacOSºÍÒÆ¶¯Æ½Ì¨µÄCisco JabberÖдæÔڻؾø·þÎñ·ì϶£¬£¬£¬£¬£¬£¬£¬ÆäCVSSÆÀ·ÖΪ4.3¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÄܹ»Í¨¹ýÏòÖ¸±êϵͳ·¢ËͶñÒâµÄXMPPÐÂÎÅÀ´ÀûÓô˷ì϶£¬£¬£¬£¬£¬£¬£¬³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷Õß¿ÉÄÜʹµÃÀûÓ÷¨Ê½ÖÕÖ¹£¬£¬£¬£¬£¬£¬£¬´Ó¶øµ¼Ö»ؾø·þÎñ¡£¡£¡£¡£¡£¡£

 

0x02 ´ëÖý¨Òé

ĿǰÕâЩ·ì϶ÒѾ­½¨¸´£¬£¬£¬£¬£¬£¬£¬½¨Òé²Î¿¼Ï±íʵʱ¸üУº

Cisco   Jabber for WindowsÊÜÓ°Ïì°æ±¾

½¨¸´°æ±¾

12.1֮ǰ

Ǩáãµ½¹Ì¶¨°æ±¾¡£¡£¡£¡£¡£¡£

12.1

12.1.5

12.5

12.5.4

12.6

12.6.5

12.7

12.7.4

12.8

12.8.5

12.9

12.9.5

Cisco Jabber for MacOSÊÜÓ°Ïì°æ±¾

½¨¸´°æ±¾

12.7 ¼°Ö®Ç°

Ǩáãµ½¹Ì¶¨°æ±¾¡£¡£¡£¡£¡£¡£

12.8

12.8.7

12.9

12.9.6

Cisco Jabber for Android ºÍ iOSÊÜÓ°Ïì°æ±¾

½¨¸´°æ±¾

12.9 ¼°Ö®Ç°

Ǩáãµ½¹Ì¶¨°æ±¾¡£¡£¡£¡£¡£¡£

14.0

²»ÊÜÓ°Ïì¡£¡£¡£¡£¡£¡£

 

ÏÂÔØÁ´½Ó£º

https://software.cisco.com/download/find

 

 

0x03 ²Î¿¼Á´½Ó

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cisco-jabber-PWrTATTC

https://www.bleepingcomputer.com/news/security/cisco-addresses-critical-bug-in-windows-macos-jabber-clients/

https://securityaffairs.co/wordpress/115931/security/cisco-jabber-critical-flaw.html?

 

0x04 ¹¦·òÏß

2021-03-24  Cisco°ä²¼°²È«²¼¸æ

2021-03-25  VSRC°ä²¼°²È«¹«¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/

image.png