Verizon Fios Quantum Gateway·ÓÉÆ÷¶à¸ö·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2019-04-10

·ì϶±àºÅºÍ¼¶±ð



CVE±àºÅ£ºCVE-2019-3914£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º8.5£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-3915£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º8.5£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-3916£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º8.5£¬¹Ù·½Î´ÆÀ¶¨



Ó°Ïì°æ±¾



Fios Quantum Gateway£¨G1100£©Â·ÓÉÆ÷<02.02.00.13



·ì϶¸ÅÊö



×îÐÂ×êÑз¢ÏÖVerizon Fios Quantum Gateway·ÓÉÆ÷´æÔÚ¶à¸ö·ì϶¡£ÈôÊDZ»ÀûÓã¬ÕâЩ·ì϶½«Ê¹¹¥»÷Õ߯ëÈ«½ÚÔì·ÓÉÆ÷²¢²é¿´ÓëÆäÓйصÄËùÓÐÄÚÈÝ¡£


·ÓÉÆ÷²àÃæÓÐÒ»¸öÌùÖ½¡£ÎªÃ¿¸ö¿Í»§Ìṩ·ÖÆçµÄÎÞÏßÍøÂçÃû³Æ£¬ÎÞÏßÃÜÂëºÍÖÎÀíÔ±ÃÜÂë¡£ÕâЩ·ìÏ¶ÖØÒªÝÓÈÆÖÎÀíÔ±ÃÜÂ룬¶ø²»ÊÇÄúÓÃÓÚÏνÓWi-FiµÄÃÜÂë¡£ÖÎÀíÔ±ÃÜÂëÓÃÓÚVerizon¿Í»§µÇ¼·ÓÉÆ÷ÒÔÖ´ÐнçËµÍøÂçµÄ¸÷À๤×÷¡£·ì϶Ô̺¬£º


CVE-2019-3914 - ¾­¹ýÉí·ÝÑéÖ¤µÄÔ¶³ÌºÅÁî×¢Èë


Äܹ»Í¨¹ýΪӵÓо«ÐÄÉè¼ÆµÄÖ÷»úÃûµÄÍøÂç¶ÔÏóÔö³¤·À»ðǽ½Ó¼û½ÚÔì¹æ¶¨À´´¥·¢´Ë·ì϶¡£±ØÐë¶ÔÉ豸µÄÖÎÀíWebÀûÓ÷¨Ê½½øÐÐÉí·ÝÑéÖ¤ÄÜÁ¦Ö´ÐкÅÁî×¢Èë¡£ÔÚ´óÎÞÊýÇé¿öÏ£¬Ö»ÓÐÓµÓб¾µØÍøÂç½Ó¼ûȨÏ޵Ĺ¥»÷ÕßÄÜÁ¦ÀûÓô˷ì϶¡£µ«ÊÇ£¬ÈôÊÇÆôÓÃÔ¶³ÌÖÎÀí£¬Ôò»ùÓÚInternetµÄ¹¥»÷ÊÇ¿ÉÐеÄ£¬ËüĬÈÏÊǽûÓõÄ¡£


ÀýÈ磬ÈôÊÇÔö³¤Ö÷»úÃûΪ¡°`whoami`¡±µÄÍøÂç¶ÔÏ󣨰ÑÎÈ·´ÒýºÅ£©£¬²¢ÇҴ˶ÔÏóÓÃÓÚ·À»ðǽ½Ó¼û½ÚÔì¹æ¶¨£¬Ôò½«Ö´ÐÓ×®whoami¡¯ºÅÁî¡£


ÏÂͼÊÇ/ chroot / mnt / log / userÖеÄÈÕÖ¾Ìõ¿î¡£Çë°ÑÎÈ£¬`whoami`Òѹ鲢µ½iptablesºÅÁîÖС£


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


HTTPÒªÇóÈçÏÂͼ£¬Çë°ÑÎÈ£¬²»»á·µ»Ø¸ÃºÅÁîµÄÁ˾Ö£¬Äܹ»»ñµÃroot shell¡£


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


CVE-2019-3915 - µÇ¼³Á²¥


ÓÉÓÚÔÚWebÖÎÀí½çÃæÖÐδǿÔìÖ´ÐÐHTTPS£¬Òò¶ø±¾µØÍø¶ÎÉϵĹ¥»÷ÕßÄܹ»Ê¹ÓÃÊý¾Ý°üÐá̽Æ÷À¹½ØµÇ¼ҪÇó¡ £Äܹ»³Á²¥ÕâЩҪÇóÒÔʹ¹¥»÷ÕßÖÎÀíÔ±½Ó¼ûWeb½çÃæ¡£ÀýÈ磬µÇ¼ҪÇóÈçÏÂͼËùʾ£º


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


CVE-2019-3916 - ÃÜÂëSaltй¶


δ¾­Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÖ»Ðè½Ó¼ûWebä¯ÀÀÆ÷ÖеÄURL¼´¿É¼ìË÷ÃÜÂësaltµÄÖµ¡£¼øÓڹ̼þ²»Ç¿ÔìʹÓÃHTTPS£¬¹¥»÷ÕßÄܹ»²¶»ñ£¨Ðá̽£©µÇ¼ҪÇ󡣵ǼҪÇóÔ̺¬saltedÃÜÂë¹þÏ££¨SHA-512£©£¬Òò¶ø¹¥»÷ÕßÄܹ»Ö´ÐÐÍÑ»ú×ֵ乥»÷ÒÔ»Ö¸´Ô­Ê¼ÃÜÂë¡£ÏÂͼÏÔʾÁËÒ»¸öHTTPÒªÇó/ÏìÓ¦¶Ô£¬Çë°ÑÎÈ£¬·µ»Ø'passwordSalt'¡£


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


 

·ì϶ÑéÖ¤



ĿǰÒÑÓÐPoC£ºhttps://github.com/tenable/poc/blob/master/verizon/verizon_g1100_cmd_injection.py£¬ËüÄܹ»Ê¹ÓÃÃ÷ÎÄÃÜÂë»ò×÷ΪºÅÁîÐвÎÊýÔö³¤µÄ¹þÏ£Öµ¡£Ñ¡ÔñÈκβ½Öè³ÇÊе¼Ö³ɹ¦µÇ¼·ÓÉÆ÷µÄWeb½çÃæ¡£ÀûÓóɹ¦ÈçÏÂͼ£º


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾




½¨¸´½¨Òé



Verizon°ä²¼Á˹̼þ°æ±¾02.02.00.13À´½¨¸´ÕâЩ·ì϶¡£



²Î¿¼Á´½Ó



https://www.tenable.com/security/research/tra-2019-17
https://www.tenable.com/blog/verizon-fios-quantum-gateway-routers-patched-for-multiple-vulnerabilities
https://www.bleepingcomputer.com/news/security/verizon-fixes-bugs-allowing-full-control-of-fios-quantum-router/