CVE-2020-3280 | Cisco Unified CCXÔ¶³Ì´úÂëÖ´Ðзì϶¹«¸æ
°ä²¼¹¦·ò 2020-05-220x00 ·ì϶¸ÅÊö
0x01 ·ì϶ÏêÇé
Cisco Unified Contact Center Express£¨Unified CCX£©ÊÇÃÀ¹ú˼¿Æ£¨Cisco£©¹«Ë¾µÄÒ»¿îͳһͨѶ½â¾ö¹æ»®ÖеĿͻ§¹ØÏµÖÎÀí×é¼þ¡£¸Ã×é¼þÖ§³Ö×ÔÖ÷ÓïÒô·þÎñ¡¢ºô½Ð·ÖÅäºÍ¿Í»§½Ó¼û½ÚÔìµÈÖ°ÄÜ¡£
2020Äê5ÔÂ20ÈÕ˼¿Æ£¨Cisco£©¹Ù·½°ä²¼¹«¸æ£¬½¨¸´ÁËÒ»¸öUnified Contact Center Express£¨Unified CCX£©ÖеÄÑϳÁ·ì϶£¨CVE-2020-3280£©¡£¸Ã·ì϶ԴÓÚCisco Unified CCX ÔÚÖ´Ðз´ÐòÁл¯²Ù×÷ʱ£¬JavaÔ¶³ÌÖÎÀí½çÃæÃ»ÓжÔÓû§ÊäÈë½øÐÐÑéÖ¤£¬µ¼Ö¹¥»÷ÕßÄܹ»ÔÚδÊÚȨµÄÇé¿öÏ·¢ËÍÒ»¸ö¶ñÒâµÄJava¶ÔÏ󣬲¢ÔÚÊÜÓ°ÏìÉ豸ÉÏÒÔrootȨÏÞÖ´ÐÐËÁÒâ´úÂë¡£
0x02 ´ëÖý¨Òé
˼¿Æ¹Ù·½ÒѾ°ä²¼Ð°汾½¨¸´ÁËÕâЩ·ì϶£¬ÇëÓйØÓû§¾¡¿ìÉý¼¶½øÐзÀ»¤£¬ÆäÖÐCiscoUnified CCX 12.0(1)ES03ºÍCisco Unified CCX 12.5°æ±¾²»Êܸ÷ì϶ӰÏì¡£
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-uccx-rce-GMSC6RKN
0x03 ÓйØÐÂÎÅ
https://www.zdnet.com/article/cisco-critical-java-flaw-strikes-call-center-in-a-box-patch-urgently/#ftag=RSSbaffb68
0x04 ²Î¿¼Á´½Ó
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-uccx-rce-GMSC6RKN
0x05 ¹¦·òÏß
2020-05-20 Cisco¹Ù·½°ä²¼¹«¸æ
2020-05-22 VSRC°ä²¼·ì϶¹«¸æ


¾©¹«Íø°²±¸11010802024551ºÅ