¡¾·ì϶¹«¸æ¡¿ThroughTek Kalay P2P SDKÔ¶³Ì´úÂëÖ´Ðзì϶ (CVE-2021-28372)

°ä²¼¹¦·ò 2021-08-18

0x00 ·ì϶¸ÅÊö

CVE     ID

CVE-2021-28372

ʱ      ¼ä

2021-08-18

Àà      ÐÍ

RCE

µÈ      ¼¶

ÑϳÁ

Ô¶³ÌÀûÓÃ

ÊÇ

Ó°ÏìÁìÓò


¹¥»÷¸´ÔÓ¶È

µÍ

¿ÉÓÃÐÔ

¸ß

Óû§½»»¥

ÊÇ

ËùÐèȨÏÞ

ÎÞ

PoC/EXP

Òѹ«¿ª

ÔÚÒ°ÀûÓÃ


 

0x01 ·ì϶ÏêÇé

image.png

2021Äê8ÔÂ17ÈÕ£¬£¬£¬ £¬£¬£¬£¬£¬Mandiant(FireEye)ÓëÃÀ¹úÍøÂ簲ȫºÍ»ù´¡ÉèÊ©°²È«¾Ö(CISA) ºÏ×÷Åû¶ÁËÒ»¸öÑϳÁµÄÎïÁªÍø°²È«·ì϶(CVE-2021-28372, CVSSv3ÆÀ·ÖΪ9.6) ¡£¡£¡£¡£¡£¡£¸Ã·ì϶ΪThroughTek Kalay P2P SDKÖеÄÔ¶³Ì´úÂëÖ´Ðзì϶,Ó°ÏìÁËÊý°ÙÍòʹÓÃThroughTek  Kalay IoT ÔÆÆ½Ì¨ÏνӵÄÎïÁªÍøÉ豸¡£¡£¡£¡£¡£¡£

¸Ã·ì϶ÓÉ Mandiant ºì¶ÓµÄ×êÑÐÈËÔ±ÓÚ 2020 Ëêĺ·¢ÏÖ£¬£¬£¬ £¬£¬£¬£¬£¬Ô¶³Ì¹¥»÷ÕßÄܹ»ÀûÓô˷ì϶ÈëÇÖÎïÁªÍøÉ豸¡£¡£¡£¡£¡£¡£ThroughTek°µÊ¾,Æäƽ̨ÉÏÓг¬¹ý8300Íò¸ö»îÔ¾É豸ºÍ³¬¹ý11ÒÚµÄÔÂÏνÓ,Æä¿Í»§Ô̺¬ÎïÁªÍøÉãÏñÍ·Ôì×÷ÉÌ¡¢ÖÇÄÜÓ¤¶ù¼à¶½Æ÷ºÍÊý×ÖÊÓÆµÂ¼Ïñ»ú£¨DVR£©²úÆ·¡£¡£¡£¡£¡£¡£

³É¹¦ÀûÓô˷ì϶µÄÔ¶³Ì¹¥»÷Õß¿ÉÄÜÊÕÌýʵʱÒôƵ¡¢ÅÔ¹ÛʵʱÊÓÆµÊý¾Ý¡¢·ÛËéÉ豸ʹ´¦¡¢Ô¶³Ì½ÚÔìÊÜÓ°ÏìÉ豸²¢Ö´ÐÐÆäËü²Ù×÷¡£¡£¡£¡£¡£¡£¹¥»÷ËùÐèµÄΨһÐÅÏ¢ÊÇÖ¸±êÓû§µÄKalayΨһ±êʶ·û£¨UID£©,¸Ã±êʶ·ûÄܹ»Í¨¹ýÉç»á¹¤³Ì»ñµÃ¡£¡£¡£¡£¡£¡£´Ë±í,¹¥»÷Õß»¹Äܹ»Ê¹Óà RPC£¨Ô¶³Ì¹ý³ÌŲÓã©Ö°ÄÜÀ´ÆëÈ«ÊÕÊÜÉ豸¡£¡£¡£¡£¡£¡£

image.png

 

KalayºÍ̸ÊÇÒÔÈí¼þ¿ª·¢¹¤¾ß°ü£¨SDK£©µÄ´ó¾ÖʵÏֵ쬣¬£¬ £¬£¬£¬£¬£¬Ëü±»ÄÚÖÃÓÚ¿Í»§¶ËÈí¼þ£¨ÈçÒÆ¶¯»ò×ÀÃæÀûÓ÷¨Ê½£©ºÍÁªÍøµÄÎïÁªÍøÉ豸£¬£¬£¬ £¬£¬£¬£¬£¬ÈçÖÇÄÜÏà»úÖÓ×£¡£¡£¡£¡£¡£ÓÉÓÚKalayºÍ̸ÊÇÓÉԭʼÉ豸Ôì×÷ÉÌ£¨OEM£©ºÍ¾­ÏúÉÌÔÚÉ豸´ïµ½Ïû·ÑÕß֮ǰ¼¯³ÉµÄ£¬£¬£¬ £¬£¬£¬£¬£¬Òò¶øÁÙʱÎÞ·¨È·¶¨ÊÜ´Ë·ì϶ӰÏìµÄ²úÆ·ºÍ¹«Ë¾µÄÆëÈ«Ãûµ¥¡£¡£¡£¡£¡£¡£

 

Ó°ÏìÁìÓò

ÒÔϰ汾µÄ Kalay P2P SDKÊÜ´Ë·ì϶ӰÏ죺

l  3.1.5 ¼°¸üÔç°æ±¾

l  ´øÓÐ nossl ±êÇ©µÄ SDK °æ±¾

l  ²»Ê¹Óà AuthKey ½øÐÐ IOTC ÏνӵÄÉ豸¹Ì¼þ

l  ʹÓà AVAPI Ä£¿£¿£¿£¿£¿£¿£¿£¿é¶ø²»ÆôÓà DTLS »úÔìµÄÉ豸¹Ì¼þ

l  ʹÓà P2PTunnel »ò RDT Ä£¿£¿£¿£¿£¿£¿£¿£¿éµÄÉ豸¹Ì¼þ

 

0x02 ´ëÖý¨Òé

ĿǰThroughTek ÒѰ䲼ÁË SDK ¸üÐÂ,½¨Òé²Î¿¼ÒÔÏ·½Ê½ÊµÊ±½¨¸´»òÉý¼¶:

l  ÈôÊÇʹÓÃThroughTek SDK v3.1.10¼°ÒÔÉϰ汾£¬£¬£¬ £¬£¬£¬£¬£¬Ç뿪ÆôAuthKeyºÍDTLS£»£»£»£»£»£»£»

l  ÈôÊÇʹÓÃv3.1.10֮ǰµÄ¾É°æ±¾ThroughTek SDK£¬£¬£¬ £¬£¬£¬£¬£¬Ç뽫¿âÉý¼¶µ½v3.3.1.0»òv3.4.2.0£¬£¬£¬ £¬£¬£¬£¬£¬²¢ÆôÓÃAuthKeyºÍDTLS¡£¡£¡£¡£¡£¡£

 

ͨÓð²È«½¨Òé

l  ¾¡Á¿Ï÷¼õËùÓнÚÔìϵͳÉ豸»òϵͳµÄÍøÂç¶³öÇé¿ö£¬£¬£¬ £¬£¬£¬£¬£¬²¢È·±£ËüÃDz»ÄÜ´Ó»¥ÁªÍø½Ó¼û¡£¡£¡£¡£¡£¡£

l  ½«½ÚÔìÏµÍ³ÍøÂçºÍÔ¶³ÌÉ豸ÖÃÓÚ·À»ðǽ֮ºó£¬£¬£¬ £¬£¬£¬£¬£¬²¢½«ÆäÓëóÒ×ÍøÂç¸ôÀë¡£¡£¡£¡£¡£¡£

l  µ±±ØÒªÔ¶³Ì½Ó¼ûʱʹÓð²È«µÄ²½Ö裬£¬£¬ £¬£¬£¬£¬£¬ÈçÐ鹹רÓÃÍøÂ磨VPN£©£¬£¬£¬ £¬£¬£¬£¬£¬²¢È·±£VPNÊÇ×îа汾¡£¡£¡£¡£¡£¡£

 

ÏÂÔØÁ´½Ó£º

https://www.throughtek.com/please-update-the-sdk-version-to-minimize-the-risk-of-sensitive-information-being-accessed-by-unauthorized-third-party/

 

0x03 ²Î¿¼Á´½Ó

https://www.fireeye.com/blog/threat-research/2021/08/mandiant-discloses-critical-vulnerability-affecting-iot-devices.html

https://us-cert.cisa.gov/ics/advisories/icsa-21-229-01

https://securityaffairs.co/wordpress/121226/hacking/kalay-cloud-platform-critical-flaw.html?

 

0x04 ¸üа汾

°æ±¾

ÈÕÆÚ

Åú¸ÄÄÚÈÝ

V1.0

2021-08-18

³õ´Î°ä²¼

 

0x05 Îĵµ¸½Â¼

CNVD£ºwww.cnvd.org.cn

CNNVD£ºwww.cnnvd.org.cn

CVE£ºcve.mitre.org

NVD£ºnvd.nist.gov

CVSS£ºwww.first.org

 

0x06 ¹ØÓÚ8827Ì«Ñô¼¯ÍÅ

¹Ø×¢ÒÔϹ«¼ÒºÅ£¬£¬£¬ £¬£¬£¬£¬£¬»ñÈ¡¸ü¶à×ÊѶ£º

image.png