¡¾·ì϶¹«¸æ¡¿Annke NVRÔ¶³Ì´úÂëÖ´Ðзì϶ (CVE-2021-32941)

°ä²¼¹¦·ò 2021-08-30

0x00 ·ì϶¸ÅÊö

CVE     ID

CVE-2021-32941

ʱ      ¼ä

2021-08-30

Àà      ÐÍ

RCE

µÈ      ¼¶

ÑϳÁ

Ô¶³ÌÀûÓÃ

ÊÇ

Ó°ÏìÁìÓò


¹¥»÷¸´ÔÓ¶È

µÍ

¿ÉÓÃÐÔ

¸ß

Óû§½»»¥

ÎÞ

ËùÐèȨÏÞ

ÎÞ

PoC/EXP


ÔÚÒ°ÀûÓÃ


 

0x01 ·ì϶ÏêÇé

image.png

 

Annke ÊÇÒ»¼ÒÊÜ»¶Ó­µÄ¼à¿ØÏµÍ³ºÍ½â¾ö¹æ»®Ôì×÷ÉÌ£¬£¬ £¬ £¬£¬£¬£¬£¬Æä²úÆ··øÉäÈ«Çò30¶à¸ö¹ú¶ÈºÍµØÓò£¬£¬ £¬ £¬£¬£¬£¬£¬Ò»Ô¾³ÉΪ±±ÃÀ¡¢Å·ÖÞ¶à¹ú¡¢°ÄÖÞµÈÔÚÏßÊг¡³ÛÃûÆ·ÅÆ¡£¡£¡£¡£¡£¡£¡£¡£ËüŤתÁËǧÍòÓû§¶Ô¼Ò¾Ó°²·ÀµÄʹÓÃÂÄÀú£¬£¬ £¬ £¬£¬£¬£¬£¬È«Çò»îÔ¾Óû§ÊýÁ¿´ï3000Íò¡£¡£¡£¡£¡£¡£¡£¡£

2021Äê8ÔÂ26ÈÕ£¬£¬ £¬ £¬£¬£¬£¬£¬CISA°ä²¼°²È«²¼¸æ£¬£¬ £¬ £¬£¬£¬£¬£¬¹«¿ªÁËÔÚAnnke Network Video Recorder£¨NVR£©Öз¢ÏÖµÄÒ»¸öÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2021-32941£©£¬£¬ £¬ £¬£¬£¬£¬£¬ÆäCVSSv3ÆÀ·ÖΪ9.4¡£¡£¡£¡£¡£¡£¡£¡£

NVRÊÇÈκÎÁªÍø°²È«ÉãÏñ»úϵͳµÄÒ»¸ö³ÁÒª×é³É²¿ÃÅ£¬£¬ £¬ £¬£¬£¬£¬£¬ËüÃDZ»Éè¼ÆÓÃÀ´×½Äᢴ洢ºÍÖÎÀíÀ´×ÔIPÉãÏñÍ·µÄ´«ÈëÊÓÆµÔ´¡£¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶ÊÇAnnke N48PBB£¨NVR£©ÖлùÓÚ²Ö¿âµÄ»º³åÇøÒç¶Âí½Å£¬£¬ £¬ £¬£¬£¬£¬£¬Î´¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓô˷ì϶½Ó¼ûÃô¸ÐÐÅÏ¢²¢ÒÔrootȨÏÞÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÄܹ»ÀûÓô˷ì϶½Ó¼û¼ÔìµÄÊÓÆµ¡¢É¾³ý¾µÍ·¡¢¸ü¸ÄÅäÖú͹عØÄ³Ð©ÉãÏñ»úµÈ¡£¡£¡£¡£¡£¡£¡£¡£

 

Ó°ÏìÁìÓò

N48PBB (NVR) <= V3.4.106 build 200422

 

0x02 ´ëÖý¨Òé

Ŀǰ´Ë·ì϶ÒѾ­½¨¸´£¬£¬ £¬ £¬£¬£¬£¬£¬½¨ÒéʵʱÉý¼¶¸üе½×îа汾¡£¡£¡£¡£¡£¡£¡£¡£

ÏÂÔØÁ´½Ó£º

https://www.annke.com/pages/download-center

 

ͨÓð²È«½¨Òé

l  ¾¡Á¿Ï÷¼õËùÓнÚÔìϵͳÉ豸»òϵͳµÄÍøÂç¶³öÇé¿ö£¬£¬ £¬ £¬£¬£¬£¬£¬²¢È·±£ËüÃDz»ÄÜ´Ó»¥ÁªÍø½Ó¼û¡£¡£¡£¡£¡£¡£¡£¡£

l  ½«½ÚÔìÏµÍ³ÍøÂçºÍÔ¶³ÌÉ豸ÖÃÓÚ·À»ðǽ֮ºó£¬£¬ £¬ £¬£¬£¬£¬£¬²¢½«ÆäÓëóÒ×ÍøÂç¸ôÀë¡£¡£¡£¡£¡£¡£¡£¡£

l  µ±±ØÒªÔ¶³Ì½Ó¼ûʱʹÓð²È«µÄ²½Ö裬£¬ £¬ £¬£¬£¬£¬£¬ÈçÐ鹹רÓÃÍøÂ磨VPN£©£¬£¬ £¬ £¬£¬£¬£¬£¬²¢È·±£VPNÊÇ×îа汾¡£¡£¡£¡£¡£¡£¡£¡£

 

0x03 ²Î¿¼Á´½Ó

https://us-cert.cisa.gov/ics/advisories/icsa-21-238-02

https://www.nozominetworks.com/blog/new-annke-vulnerability-shows-risks-of-iot-security-camera-systems/

https://www.infosecurity-magazine.com/news/critical-iot-camera-flaw-allows/


0x04 ¸üа汾

°æ±¾

ÈÕÆÚ

Åú¸ÄÄÚÈÝ

V1.0

2021-08-30

³õ´Î°ä²¼

 

0x05 Îĵµ¸½Â¼

CNVD£ºwww.cnvd.org.cn

CNNVD£ºwww.cnnvd.org.cn

CVE£ºcve.mitre.org

NVD£ºnvd.nist.gov

CVSS£ºwww.first.org

 

0x06 ¹ØÓÚ8827Ì«Ñô¼¯ÍÅ

¹Ø×¢ÒÔϹ«¼ÒºÅ£¬£¬ £¬ £¬£¬£¬£¬£¬»ñÈ¡¸ü¶à×ÊѶ£º

image.png