Cisco Jabber¿Í»§¶Ë¶à¸ö°²È«·ì϶

°ä²¼¹¦·ò 2021-03-25

0x00 ·ì϶¸Å

Cisco JabberÊÇÒ»¸ö¼´Ê±ÐÂÎźÍweb»áÒé×ÀÃæÀûÓ÷¨Ê½£¬ËüʹÓÿÉÀ©´óÐÂÎźÍ״̬ºÍ̸£¨XMPP£©ÔÚÓû§Ö®¼ä´«µÝÐÂÎÅ¡£¸ÃÀûÓ÷¨Ê½»ùÓÚChromium Embedded Framework£¨CEF£©¹¹½¨£¬ÆäUIʹÓÃHTML¡¢CSSºÍJavaScriptµÈweb¼¼Êõ¡£

2021Äê03ÔÂ24ÈÕ£¬Cisco°ä²¼°²È«²¼¸æ£¬½¨¸´ÁËCisco JabberÖеĶà¸ö°²È«·ì϶¡£¹¥»÷Õß¿ÉÄÜÀûÓÃÕâЩ·ì϶ÔÚϵͳÉÏÖ´ÐÐËÁÒâ´úÂë¡¢½Ó¼ûÃô¸ÐÐÅÏ¢¡¢À¹½ØÊܱ£»¤µÄÍøÂçÁ÷Á¿»òµ¼Ö»ؾø·þÎñ£¨DoS£©¡£

 

0x01 ·ì϶ÏêÇé

image.png

 

³ýÁËCVE-2021-1471±í£¬ÕâЩ·ì϶²»»áÓ°ÏìΪPhone-only ģʽºÍTeam Messaging ģʽµÄCisco Jabber¿Í»§¶ËÈí¼þ¡£±¾´Î¹«¿ªµÄ·ì϶ÈçÏ£º

Cisco Jabberƽ̨

CVE ID

Windows

CVE-2021-1411¡¢CVE-2021-1417¡¢CVE-2021-1418¡¢CVE-2021-1469¡¢ CVE-2021-1471

MacOS

CVE-2021-1418 ¡¢CVE-2021-1471

Android ºÍ iOS

CVE-2021-1418 ¡¢ CVE-2021-1471

 

·ì϶ÏêÇéÈçÏ£º

Cisco JabberËÁÒâ´úÂëÖ´Ðзì϶£¨CVE-2021-1411£©

ÓÉÓÚÓʼþÄÚÈÝÑéÖ¤²»ÕýÈ·£¬Cisco Jabber for WindowsÖдæÔÚÒ»¸öËÁÒâ´úÂëÖ´Ðзì϶£¬ÆäCVSSÆÀ·ÖΪ9.9¡£¹¥»÷ÕßÄܹ»Í¨¹ýÏòÊÜÓ°ÏìµÄJabber¿Í»§¶ËÈí¼þ·¢ËͶñÒâµÄXMPPÐÂÎÅÀ´ÀûÓô˷ì϶£¬³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷Õß¿ÉÄÜÒÔÔËÐÐCisco Jabber¿Í»§¶ËÈí¼þµÄÓû§ÕÊ»§µÄȨÏÞʹÀûÓ÷¨Ê½ÔÚÖ¸±êϵͳÉÏÖ´ÐÐËÁÒⷨʽ£¬Õâ¿ÉÄܵ¼ÖÂËÁÒâ´úÂëÖ´ÐС£

µ«ÒªÀûÓô˷ì϶£¬¹¥»÷Õß±ØÒªÍ¨¹ýÊÜÓ°ÏìÈí¼þʹÓõÄXMPP·þÎñÆ÷½øÐÐÉí·ÝÑéÖ¤£¬ÄÜÁ¦½«¶ñÒâÔì×÷µÄXMPPÐÂÎÅ·¢Ë͵½Ö¸±êÉ豸¡£

 

Cisco JabberËÁÒâ´úÂëÖ´Ðзì϶£¨CVE-2021-1469£©

ÓÉÓÚÓʼþÄÚÈÝÑéÖ¤²»ÕýÈ·£¬Cisco Jabber for WindowsÖдæÔÚÒ»¸öËÁÒâ´úÂëÖ´Ðзì϶£¬ÆäCVSSÆÀ·ÖΪ7.2¡£Õ¼Óгö¸ñÅäÖõÄXMPP·þÎñÆ÷ÕÊ»§µÄ¹¥»÷ÕßÄܹ»Í¨¹ýÏòÊÜÓ°ÏìµÄÈí¼þ·¢ËͶñÒâµÄXMPPÐÂÎÅÀ´ÀûÓô˷ì϶¡£³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷Õß¿ÉÄÜÒÔÔËÐÐCisco Jabber¿Í»§¶ËÈí¼þµÄÓû§ÕÊ»§µÄȨÏÞʹÀûÓ÷¨Ê½ÔÚÖ¸±êϵͳÉÏÖ´ÐÐËÁÒⷨʽ£¬Õâ¿ÉÄܵ¼ÖÂËÁÒâ´úÂëÖ´ÐС£

 

Cisco JabberÐÅϢй¶·ì϶£¨CVE-2021-1417£©

ÓÉÓÚÓʼþÄÚÈÝÑéÖ¤²»ÕýÈ·£¬Cisco Jabber for WindowsÖдæÔÚÒ»¸öÐÅϢй¶·ì϶£¬ÆäCVSSÆÀ·ÖΪ6.5¡£¹¥»÷ÕßÄܹ»Í¨¹ý½«¶ñÒâµÄXMPPÐÂÎÅ·¢Ë͵½Ö¸±êϵͳÀ´ÀûÓô˷ì϶£¬³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷ÕßÄܹ»Ê¹ÀûÓ÷¨Ê½½«Ãô¸ÐµÄÉí·ÝÑéÖ¤ÐÅÏ¢·µ»Ø¸øÁíÒ»¸öϵͳ£¬ÒÔ½«ÆäÓÃÓÚ½øÒ»²½µÄ¹¥»÷¡£

 

Cisco JabberÖ¤ÊéÑéÖ¤·ì϶£¨CVE-2021-1471£©

ÓÉÓÚÖ¤ÊéÑéÖ¤²»ÕýÈ·£¬ ºÏÓÃÓÚWindows¡¢ MacOSºÍÒÆ¶¯Æ½Ì¨µÄCisco JabberÖдæÔÚÖ¤ÊéÑéÖ¤·ì϶£¬ÆäCVSSÆÀ·ÖΪ5.6¡£¹¥»÷ÕßÄܹ»Í¨¹ýʹÓÃȨÏÞÍøÂçµØÎ»À´À¹½ØÀ´×ÔÊÜÓ°ÏìÈí¼þµÄÍøÂçÒªÇó²¢³öʾ¶ñÒâÔì×÷µÄÖ¤ÊéÀ´ÀûÓô˷ì϶£¬³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷Õß¿ÉÄܲ鳭»òÅú¸ÄCisco Jabber¿Í»§¶ËÓë·þÎñÆ÷Ö®¼äµÄÏνÓ¡£

 

Cisco Jabber»Ø¾ø·þÎñ·ì϶£¨CVE-2021-1418£©

ÓÉÓÚÓʼþÄÚÈÝÑéÖ¤²»ÕýÈ·£¬ºÏÓÃÓÚWindows¡¢ MacOSºÍÒÆ¶¯Æ½Ì¨µÄCisco JabberÖдæÔڻؾø·þÎñ·ì϶£¬ÆäCVSSÆÀ·ÖΪ4.3¡£¹¥»÷ÕßÄܹ»Í¨¹ýÏòÖ¸±êϵͳ·¢ËͶñÒâµÄXMPPÐÂÎÅÀ´ÀûÓô˷ì϶£¬³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷Õß¿ÉÄÜʹµÃÀûÓ÷¨Ê½ÖÕÖ¹£¬´Ó¶øµ¼Ö»ؾø·þÎñ¡£

 

0x02 ´ëÖý¨Òé

ĿǰÕâЩ·ì϶ÒѾ­½¨¸´£¬½¨Òé²Î¿¼Ï±íʵʱ¸üУº

Cisco   Jabber for WindowsÊÜÓ°Ïì°æ±¾

½¨¸´°æ±¾

12.1֮ǰ

Ǩáãµ½¹Ì¶¨°æ±¾¡£

12.1

12.1.5

12.5

12.5.4

12.6

12.6.5

12.7

12.7.4

12.8

12.8.5

12.9

12.9.5

Cisco Jabber for MacOSÊÜÓ°Ïì°æ±¾

½¨¸´°æ±¾

12.7 ¼°Ö®Ç°

Ǩáãµ½¹Ì¶¨°æ±¾¡£

12.8

12.8.7

12.9

12.9.6

Cisco Jabber for Android ºÍ iOSÊÜÓ°Ïì°æ±¾

½¨¸´°æ±¾

12.9 ¼°Ö®Ç°

Ǩáãµ½¹Ì¶¨°æ±¾¡£

14.0

²»ÊÜÓ°Ïì¡£

 

ÏÂÔØÁ´½Ó£º

https://software.cisco.com/download/find

 

 

0x03 ²Î¿¼Á´½Ó

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cisco-jabber-PWrTATTC

https://www.bleepingcomputer.com/news/security/cisco-addresses-critical-bug-in-windows-macos-jabber-clients/

https://securityaffairs.co/wordpress/115931/security/cisco-jabber-critical-flaw.html?

 

0x04 ¹¦·òÏß

2021-03-24  Cisco°ä²¼°²È«²¼¸æ

2021-03-25  VSRC°ä²¼°²È«¹«¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/

image.png