¡¾·ì϶¹«¸æ¡¿Cisco Small Business VPN·ÓÉÆ÷ËÁÒâ´úÂëÖ´Ðзì϶£¨CVE-2021-1609£©
°ä²¼¹¦·ò 2021-08-050x00 ·ì϶¸ÅÊö
CVE ID | CVE-2021-1609 | ʱ ¼ä | 2021-08-04 |
Àà ÐÍ | ´úÂëÖ´ÐÐ | µÈ ¼¶ | ÑϳÁ |
Ô¶³ÌÀûÓà | ÊÇ | Ó°ÏìÁìÓò | |
¹¥»÷¸´ÔÓ¶È | µÍ | ¿ÉÓÃÐÔ | ¸ß |
Óû§½»»¥ | ÎÞ | ËùÐèȨÏÞ | ÎÞ |
PoC/EXP | δ¹«¿ª | ÔÚÒ°ÀûÓà | ·ñ |
0x01 ·ì϶ÏêÇé

2021Äê8ÔÂ4ÈÕ£¬£¬£¬£¬£¬Cisco°ä²¼°²È«²¼¸æ£¬£¬£¬£¬£¬½¨¸´ÁËÆäSmall Business VPN ·ÓÉÆ÷ÖеĶà¸ö°²È«·ì϶£¬£¬£¬£¬£¬ÆäÖÐ×îΪÑϳÁµÄ·ì϶ΪCVE-2021-1609£¨CVSSÆÀ·Ö9.8£©£¬£¬£¬£¬£¬¹¥»÷ÕßÄܹ»ÀûÓô˷ì϶Զ³ÌÖ´ÐÐËÁÒâ´úÂë»òÔì³É»Ø¾ø·þÎñ¡£¡£¡£¡£¡£¡£
ÓÉÓÚHTTP ÒªÇóδÕýÈ·ÑéÖ¤£¬£¬£¬£¬£¬Cisco Small Business RV340¡¢RV340W¡¢RV345ºÍRV345PË«WANǧÕ×VPN·ÓÉÆ÷»ùÓÚWebµÄÖÎÀí½çÃæ´æÔÚ°²È«·ì϶¡£¡£¡£¡£¡£¡£Î´¾Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÄܹ»Í¨¹ýÏòÊÜÓ°ÏìµÄÉ豸·¢ËͶñÒâHTTP ÒªÇóÀ´ÀûÓô˷ì϶¡£¡£¡£¡£¡£¡£³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷Õß¿ÉÄÜÔÚÊÜÓ°ÏìµÄÉ豸ÉÏÖ´ÐÐËÁÒâ´úÂë»òµ¼ÖÂÉ豸³ÁмÓÔØ£¬£¬£¬£¬£¬´Ó¶øÔì³É»Ø¾ø·þÎñ£¨DoS£©¡£¡£¡£¡£¡£¡£
³ý´ËÖ®±í£¬£¬£¬£¬£¬Cisco Small Business RV340¡¢RV340W¡¢RV345ºÍRV345PË«WANǧÕ×VPN·ÓÉÆ÷»ùÓÚWebµÄÖÎÀí½çÃæÖл¹´æÔÚÒ»¸öºÅÁî×¢Èë·ì϶£¨CVE-2021-1610£¬£¬£¬£¬£¬CVSSÆÀ·Ö7.2£©£¬£¬£¬£¬£¬¾¹ýÉí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÄܹ»Í¨¹ýÏòÊÜÓ°ÏìµÄÉ豸·¢ËͶñÒâHTTP ÒªÇóÀ´ÀûÓô˷ì϶£¬£¬£¬£¬£¬²¢×îÖÕ¿ÉÄÜÒÔrootÉí·ÝÔÚϵͳÉÏÖ´ÐÐËÁÒâºÅÁî¡£¡£¡£¡£¡£¡£
Ó°ÏìÁìÓò
ÈôÊÇCisco Small Business RoutersÔËÐеĹ̼þ°æ±¾Ó×ÓÚ1.0.03.22£¬£¬£¬£¬£¬ÕâЩ·ì϶½«Ó°Ï죨ÊÜÓ°ÏìµÄ VPN ·ÓÉÆ÷ÐͺÅĬÈϽûÓÃÔ¶³ÌÖÎÀíÖ°ÄÜ£©£º
RV340Ë«WANǧÕ×VPN·ÓÉÆ÷
RV340WË«WANǧÕ×ÎÞÏßAC VPN·ÓÉÆ÷
RV345Ë«WANǧÕ×VPN·ÓÉÆ÷
RV345P Ë«WANǧÕ×VPN·ÓÉÆ÷
0x02 ´ëÖý¨Òé
Ŀǰ£¬£¬£¬£¬£¬CiscoÒѾÔڹ̼þ°æ±¾ 1.0.03.22 ¼°¸ü¸ß°æ±¾Öн¨¸´ÁËÕâЩ·ì϶£¬£¬£¬£¬£¬½¨ÒéʵʱÉý¼¶¸üÐÂ:
½øÈëCisco.com ÉϵÄÈí¼þÏÂÔØÖÐÐÄ£¬£¬£¬£¬£¬µ¥»÷¡°ä¯ÀÀÈ«Êý¡±²¢µ¼º½ÖÁ¡°ÏÂÔØÖ÷Ò³¡± >¡°Â·ÓÉÆ÷¡± >¡°Ó×ÐÍÆóҵ·ÓÉÆ÷¡± >¡°Ó×ÐÍÆóÒµ RV ϵÁзÓÉÆ÷¡±¡£¡£¡£¡£¡£¡£
ÏÂÔØÁ´½Ó£º
https://software.cisco.com/download/home
0x03 ²Î¿¼Á´½Ó
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-rv340-cmdinj-rcedos-pY8J3qfy
https://www.bleepingcomputer.com/news/security/cisco-fixes-critical-high-severity-pre-auth-flaws-in-vpn-routers/
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-1609
0x04 ¸üа汾
°æ±¾ | ÈÕÆÚ | Åú¸ÄÄÚÈÝ |
V1.0 | 2021-08-05 | ³õ´Î°ä²¼ |
0x05 Îĵµ¸½Â¼
CNVD£ºwww.cnvd.org.cn
CNNVD£ºwww.cnnvd.org.cn
CVE£ºcve.mitre.org
NVD£ºnvd.nist.gov
CVSS£ºwww.first.org
0x06 ¹ØÓÚ8827Ì«Ñô¼¯ÍÅ
¹Ø×¢ÒÔϹ«¼ÒºÅ£¬£¬£¬£¬£¬»ñÈ¡¸ü¶à×ÊѶ£º



¾©¹«Íø°²±¸11010802024551ºÅ