¡¾·ì϶¹«¸æ¡¿Cisco FMC RADIUS Ô¶³Ì´úÂëÖ´Ðзì϶(CVE-2025-20265)

°ä²¼¹¦·ò 2025-08-19

Ò»¡¢·ì϶¸ÅÊö


·ìϼûû³Æ

Cisco FMC RADIUS Ô¶³Ì´úÂëÖ´Ðзì϶

CVE   ID

CVE-2025-20265

·ì϶ÀàÐÍ

RCE

·¢ÏÖ¹¦·ò

2025-08-19

·ì϶ÆÀ·Ö

10

·ì϶µÈ¼¶

ÑϳÁ

¹¥»÷ÏòÁ¿

ÍøÂç

ËùÐèȨÏÞ

ÎÞ

ÀûÓÃÄѶÈ

µÍ

Óû§½»»¥

²»±ØÒª

PoC/EXP

Òѹ«¿ª

ÔÚÒ°ÀûÓÃ

δ·¢ÏÖ


Cisco Secure Firewall Management Center (FMC)ÊÇÒ»¿îÓÃÓÚ¼¯ÖÐÖÎÀíºÍÅäÖÃCisco Secure Firewall²úÆ·µÄ°²È«ÖÎÀíÆ½Ì¨¡£¡£¡£¡£¡£¡£¡£¡£ËüÌṩ»ùÓÚWeb»òSSHµÄ½çÃæ£¬£¬£¬£¬£¬ÔÊÐíÖÎÀíÔ±ÅäÖᢷÀ»¤¡¢¼à¿ØºÍ¸üзÀ»ðǽÉ豸¡£¡£¡£¡£¡£¡£¡£¡£FMCÖ§³ÖÕ½ÊõÖÎÀí¡¢ÊÂÎñ¼à¿Ø¡¢Á÷Á¿·ÖÎö¼°»ã±¨Ö°ÄÜ£¬£¬£¬£¬£¬Ô®ÊÔìóÒµ¼¯ÖÐÖÎÀí¶à¸ö·À»ðǽÉ豸£¬£¬£¬£¬£¬ÌáÉýÍøÂ簲ȫ·À»¤ÄÜÁ¦¡£¡£¡£¡£¡£¡£¡£¡£¸ÃÈí¼þ»¹Ö§³Ö¼¯³ÉµÄÉí·ÝÑéÖ¤¡¢Íþв¼ì²âÓëÏìÓ¦Ö°ÄÜ£¬£¬£¬£¬£¬ºÏÓÃÓÚÆóÒµºÍµ±¾ÖÍøÂç»·¾³Öеļ¯Öл¯ÖÎÀíÐèÒª¡£¡£¡£¡£¡£¡£¡£¡£


2025Äê8ÔÂ19ÈÕ£¬£¬£¬£¬£¬8827Ì«Ñô¼¯Íż¯ÍÅVSRC¼à²âµ½Cisco Secure Firewall Management Center (FMC)Èí¼þµÄRADIUS×Óϵͳ´æÔÚÔ¶³Ì´úÂëÖ´ÐÐ(RCE)·ì϶¡£¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶ԴÓÚÉí·ÝÑéÖ¤¹ý³ÌδÄÜÕýÈ·´¦ÖÃÓû§ÊäÈ룬£¬£¬£¬£¬ÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õßͨ¹ý·¢Ë;«ÐÄ»ú¹ØµÄƾ֤ÊäÈ룬£¬£¬£¬£¬×¢Èë²¢Ö´ÐÐËÁÒâµÄshellºÅÁî¡£¡£¡£¡£¡£¡£¡£¡£³É¹¦ÀûÓø÷ì϶ºó£¬£¬£¬£¬£¬¹¥»÷Õ߿ɻñµÃ¸ßȨÏÞÖ´ÐкÅÁî¡£¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶½öÓ°ÏìÆôÓÃRADIUSÈÏÖ¤µÄFMC°æ±¾7.0.7ºÍ7.7.0£¬£¬£¬£¬£¬ÇÒ½öÔÚÅäÖÃÁËWebÖÎÀí½çÃæ¡¢SSHÖÎÀí»òÁ½ÕßµÄÇé¿öÏ¿ɱ»ÀûÓᣡ£¡£¡£¡£¡£¡£¡£·ì϶ÆÀ·Ö10£¬£¬£¬£¬£¬·ì϶¼¶±ðÑϳÁ¡£¡£¡£¡£¡£¡£¡£¡£


¶þ¡¢Ó°ÏìÁìÓò


7.0.7 <= FMC <= 7.7.0 (½öÔÚÆôÓÃRADIUSÈÏ֤ʱ)¡£¡£¡£¡£¡£¡£¡£¡£


Èý¡¢°²È«´ëÊ©





Cisco¹Ù·½ÒѰ䲼°²È«²¹¶¡£¬£¬£¬£¬£¬ÇëÉý¼¶ÖÁCisco FMC7.7.0ÒÔÉϰ汾


ÏÂÔØÁ´½Ó£º
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-radius-rce-TNBKf79


3.2 һʱ´ëÊ©


ÈôÊÇÎÞ·¨Á¢¼´Éý¼¶£¬£¬£¬£¬£¬Çë½ûÓÃRADIUSÈÏÖ¤£¬£¬£¬£¬£¬²¢Ê¹ÓÃÆäËûÉí·ÝÑéÖ¤·½Ê½£¬£¬£¬£¬£¬Èç±¾µØÓû§ÕË»§¡¢±í²¿LDAPÈÏÖ¤»òSAMLµ¥µãµÇ¼(SSO)¡£¡£¡£¡£¡£¡£¡£¡£


3.3 ͨÓý¨Òé


? ¶¨ÆÚ¸üÐÂϵͳ²¹¶¡£¬£¬£¬£¬£¬Ï÷¼õϵͳ·ì϶£¬£¬£¬£¬£¬ÌáÉý·þÎñÆ÷µÄ°²È«ÐÔ¡£¡£¡£¡£¡£¡£¡£¡£
¼ÓǿϵͳºÍÍøÂçµÄ½Ó¼û½ÚÔ죬£¬£¬£¬£¬Åú¸Ä·À»ðǽսÊõ£¬£¬£¬£¬£¬¹Ø¹Ø·Ç±ØÒªµÄÀûÓö˿ڻò·þÎñ£¬£¬£¬£¬£¬Ï÷¼õ½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Â¶³öµ½¹«Íø£¬£¬£¬£¬£¬Ï÷¼õ¹¥»÷Ãæ¡£¡£¡£¡£¡£¡£¡£¡£
ʹÓÃÆóÒµ¼¶°²È«²úÆ·£¬£¬£¬£¬£¬ÌáÉýÆóÒµµÄÍøÂ簲ȫ»úÄÜ¡£¡£¡£¡£¡£¡£¡£¡£
¼ÓǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬£¬£¬£¬£¬ÆôÓöà³É·ÖÈÏÖ¤»úÔìºÍ×îÓ×ȨÏÞ×¼Ôò£¬£¬£¬£¬£¬Óû§ºÍÈí¼þȨÏÞӦά³ÖÔÚ×îµÍÏÞ¶È¡£¡£¡£¡£¡£¡£¡£¡£
ÆôÓÃÇ¿ÃÜÂëÕ½Êõ²¢ÉèÖÃΪ¶¨ÆÚÅú¸Ä¡£¡£¡£¡£¡£¡£¡£¡£


3.4 ²Î¿¼Á´½Ó


https://www.bleepingcomputer.com/news/security/cisco-warns-of-max-severity-flaw-in-firewall-management-center/
https://nvd.nist.gov/vuln/detail/CVE-2025-20265
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-radius-rce-TNBKf79