ÐÛÂõÔÆ·þÎñÆ÷ÄÚÖÃÓ²±àÂëÕË»§·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2018-10-17

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2018-17919 £¬Î£ÏÕ¼¶±ð£º¸ßΣ £¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ8.1 £¬¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


º¼ÖÝÐÛÂõ¿Æ¼¼ÓÐÏÞ¹«Ë¾XMeye P2PÔÆ·þÎñÆ÷
ËùÓÐͨ¹ýº¼ÖÝÐÛÂõ¿Æ¼¼ÓÐÏÞ¹«Ë¾´ú¹¤µÄ»ùÓÚXMeye P2PÔÆ·þÎñÆ÷É豸


·ì϶¸ÅÊö


XMeye P2PÔÆ·þÎñÆ÷ÊÇÒ»ÖÖÓÃÓÚNVR/DVRÉ豸ÖÎÀíµÄ×é¼þ £¬Óɺ¼ÖÝÐÛÂõ¹«Ë¾³ö²ú¡£´Ë×é¼þ±»·¢ÏÖ´æÔÚÄÚÖÃÓ²±àÂëµÄÕ˺Å £¬¿É±»Ô¶³Ìͨ¹ýWeb½çÃæµÇ¼´Ó¶øÊµÏÖ·ÇÊÚȨµÄÉ豸ÖÎÀí £¬ËùÓÐʹÓôË×é¼þµÄÉ豸¾ù´Ë°²È«ÎÊÌâµÄÓ°Ï졣ͬʱÉ豸»¹´æÔÚÏÔÖøµÄĿ¼±éÀú·ì϶ £¬¹¥»÷ÕßÄܹ»¶ÁȡϵͳÖеÄËÁÒâÎļþ £¬¹¥»÷Õß¿ÉÄÜÀûÓÃÕâЩÎÊÌâ½øÒ»²½½ÚÔìϵͳ»ñȡԶ³ÌºÅÁîÖ´ÐеÄÄÜÁ¦¡£

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÖйúµØÓòÖÐÁÉÄþʡʹÓÃÓÃÊýÁ¿×î¶à £¬¹²ÓÐ4582̨ £»¹ã¶«Ê¡µÚ¶þ £¬¹²ÓÐ1838̨ £¬É½¶«Ê¡µÚÈý £¬¹²ÓÐ1566̨ £¬±±¾©ÊеÚËÄ £¬¹²ÓÐ1492̨ £¬½­ËÕÊ¡µÚÎå £¬¹²ÓÐ1232̨¡£


·ì϶ÑéÖ¤


ÔÝÎÞPOC\EXP


1¡¢Í¨¹ýWebÖÎÀí½çÃæµÇ¼ÄÚÖÃÓ²±àÂëÕ˺Å
ͨ¹ýä¯ÀÀÆ÷Ö±½Ó½Ó¼ûurl £¬Ê¹ÓÃÓ²±àÂëÕË»§¼´¿ÉÖ±½ÓµÇ¼ÊÓÆµ¼à¿Ø½çÃæ¡£Ó²±àÂëÕË»§¼°¿ÚÁîΪ£ºdefault/¿Õ¿ÚÁî»òdefault/tluafed

ÈçÏÂÑÝʾ£º


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


µÇ¼½øÈëºóµÄÖÎÀíÒ³Ãæ£º


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


2¡¢ Web ServeĿ¼±éÀú·ì϶
XMeye P2PÔÆ·þÎñÆ÷Web Server×é¼þȨÏÞÅäÖò»µ± £¬µ¼ÖÂÄܹ»±éÀúĿ¼¶ÁÈ¡ËÁÒâÎļþ¡£ÒÔÏÂÒÔ³¢ÊÔ½Ó¼û/../../../../../procΪÀý¡£


ÈçÏÂͼ£º

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

½¨¸´½¨Òé


×Բ鲽Ö裺
²é¿´XMeye P2PÔÆ·þÎñÆ÷É豸ÊÇ·ñ¿ªÆôWebÖÎÀí £¬²¢Ê¹ÓÃÄÚÖÃÕË»§ÔÚWebÖÎÀí½çÃæ³¢ÊԵǼ¡£ÈôµÇ½³É¹¦ £¬Ôò·ì϶´æÔÚ¡£

Éý¼¶²¹¶¡£º
º¼ÖÝÐÛÂõĿǰ²¢Î´¾Í´Ë·ì϶°ä²¼Èκβ¹¶¡ £¬ÓйØÊÜÓ°ÏìÓû§ÇëÁªÏµº¼ÖÝÐÛÂõ¿Æ¼¼¼°Óйس§ÉÌ»ñȡ֧³Ö¡£

һʱ´ëÖôëÊ©£º
1¡¢Ê¹Óð×Ãûµ¥·½ÃæÊ½ÏÞÔì¿É½Ó¼ûWEBÖÎÀíÆ½Ì¨µÄÆðÔ´IP»ò¹Ø¹ØWEBÖÎÀíÆ½Ì¨¡£
2¡¢±¾µØÍ¨¹ý´®¿ÚÅú¸ÄÄÚÖõÄrootÕË»§¿ÚÁî¡£

²Î¿¼Á´½Ó


https://ics-cert.us-cert.gov/advisories/ICSA-18-282-06
http://www.xiongmaitech.com/