CVE-2020-3495 | Cisco JabberÔ¶³Ì´úÂëÖ´Ðзì϶¹«¸æ

°ä²¼¹¦·ò 2020-09-03

0x00 ·ì϶¸ÅÊö

CVE   ID

CVE-2020-3495

ʱ    ¼ä

2020-09-03

Àà    ÐÍ

RCE

µÈ    ¼¶

¸ßΣ

Ô¶³ÌÀûÓÃ

ÊÇ

Ó°ÏìÁìÓò

ËùÓкÏÓÃWindows Cisco Jabber¿Í»§¶Ë°æ±¾£¨12.1ÖÁ12.9£©

 

2020Äê09ÔÂ02ÈÕ£¬Cisco¹Ù·½½¨¸´ÁËÒ»¸öÑϳÁµÄÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2020-3495£©£¬¸Ã·ì϶CVSSÆÀ·ÖΪ9.9·Ö¡£

CVE-2020-3495·ì϶ÓÉWatchcomµÄ°²È«×êÑÐÈËÔ±Olav Sortland Thoresen·¢ÏÖ²¢»ã±¨£¬Ë¼¿Æ²úÆ·°²È«ÊÂÎñÏìÓ¦ÍŶӣ¨PSIRT£©°µÊ¾¸Ã·ì϶µ±Ç°ÉÐδ±»¿í·ºÀûÓá£

0x01 ·ì϶ÏêÇé

 

ͼƬ4.png


 

Cisco Jabber for WindowsÊÇÒ»¿î×ÀÃæºÏ×÷ÀûÓ÷¨Ê½£¬ÖØÒªÎªÓû§Ìṩ״̬¡¢¼´Ê±ÐÂÎÅ£¨IM£©¡¢ÐÂÎÅ¡¢×ÀÃæ¹²Ïí¡¢ÊÓÆµÒôƵ»áÒéºÍWeb»áÒé·þÎñ¡£

CVE-2020-3495ÊÇÓÉÓÚÓʼþÄÚÈÝÑéÖ¤²»ÕýÈ·ÒýÆðµÄ¡£¹¥»÷Õßͨ¹ýʹÓöñÒâµÄ¿ÉÀ©´óÐÂÎźÍ״̬ºÍ̸£¨XMPP£©ÐÂÎÅÀ´ÀûÓô˷ì϶£¬Í¨¹ýÉí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÄܹ»ÔÚδ´ò²¹¶¡µÄ Cisco Jabber for Windows µÄϵͳÉÏÖ´ÐжñÒâ´úÂë¡£²¢ÇÒ£¬¸Ã·ì϶µÄÀûÓò»±ØÒªÓû§½»»¥£¬µ±Jabber for Windows¿Í»§¶ËÔÚºó¶ÜÔËÐÐʱ¸Ã·ì϶Ҳ¿É±»ÀûÓá£

µ«ÈôÊÇÒªÀûÓô˷ì϶£¬¹¥»÷Õß±ØÐë¿ÉÄÜÏòÔËÐÐWindowsµÄCisco JabberµÄ×îÖÕÓû§ÏµÍ³·¢ËÍXMPPÐÂÎÅ¡£Èô³É¹¦ÀûÓô˷ì϶£¬»áµ¼ÖÂÀûÓ÷¨Ê½ÔËÐеı¾µØÎļþõè¾¶Öб»ÉÏ´«ËÁÒâÖ´ÐÐÎļþ£¬¸Ã¿ÉÖ´ÐÐÎļþ½«»áÒÔÆô¶¯Jabber¿Í»§¶ËÀûÓ÷¨Ê½µÄÓû§µÄÌØÈ¨ÔÚÓû§ÏµÍ³ÉÏÔËÐС£

µ«½öÔÚphone-only modeģʽÏÂʹÓÃJabber²¢ÇÒûÓÐÆôÓÃXMPPÐÂÎÅ·þÎñʱϵͳ²»Ò×Êܵ½¹¥»÷£¬µ±JabberÉèÖÃΪʹÓóýXMPPÐÂÎÅ´«µÝÒÔ±íµÄÐÂÎÅ´«µÝ·þÎñʱ£¬¸Ã·ì϶ÔòÎÞ·¨±»ÀûÓá£

0x02 ´ëÖý¨Òé

½¨ÒéÉý¼¶µ½Êʵ±µÄ°æ±¾£º

ÊÜÓ°Ïì°æ±¾

¸üа汾

12.1

12.1.3

12.5

12.5.2

12.6

12.6.3

12.7

12.7.2

12.8

12.8.3

12.9

12.9.1

ÏÂÔØµØÖ·£º

https://software.cisco.com/download/home/284324806/type/284006014/release/12.6(3)

 

0x03 ÓйØÐÂÎÅ

https://www.bleepingcomputer.com/news/security/cisco-fixes-critical-code-execution-bug-in-jabber-for-windows/

https://securityaffairs.co/wordpress/107834/security/cisco-jabber-for-windows-flaw.html

 

0x04 ²Î¿¼Á´½Ó

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-jabber-UyTKCPGg

0x05 ¹¦·òÏß

2020-09-02 Cisco°ä²¼°²È«²¼¸æ

2020-09-03 VSRC°ä²¼°²È«¹«¸æ



ͼƬ5.png