¡¾·ì϶¹«¸æ¡¿Annke NVRÔ¶³Ì´úÂëÖ´Ðзì϶ (CVE-2021-32941)
°ä²¼¹¦·ò 2021-08-300x00 ·ì϶¸ÅÊö
CVE ID | CVE-2021-32941 | ʱ ¼ä | 2021-08-30 |
Àà ÐÍ | RCE | µÈ ¼¶ | ÑϳÁ |
Ô¶³ÌÀûÓà | ÊÇ | Ó°ÏìÁìÓò | |
¹¥»÷¸´ÔÓ¶È | µÍ | ¿ÉÓÃÐÔ | ¸ß |
Óû§½»»¥ | ÎÞ | ËùÐèȨÏÞ | ÎÞ |
PoC/EXP | ÔÚÒ°ÀûÓÃ |
0x01 ·ì϶ÏêÇé

Annke ÊÇÒ»¼ÒÊÜÓ½ÓµÄ¼à¿ØÏµÍ³ºÍ½â¾ö¹æ»®Ôì×÷ÉÌ£¬Æä²úÆ··øÉäÈ«Çò30¶à¸ö¹ú¶ÈºÍµØÓò£¬Ò»Ô¾³ÉΪ±±ÃÀ¡¢Å·ÖÞ¶à¹ú¡¢°ÄÖÞµÈÔÚÏßÊг¡³ÛÃûÆ·ÅÆ¡£ËüŤתÁËǧÍòÓû§¶Ô¼Ò¾Ó°²·ÀµÄʹÓÃÂÄÀú£¬È«Çò»îÔ¾Óû§ÊýÁ¿´ï3000Íò¡£
2021Äê8ÔÂ26ÈÕ£¬CISA°ä²¼°²È«²¼¸æ£¬¹«¿ªÁËÔÚAnnke Network Video Recorder£¨NVR£©Öз¢ÏÖµÄÒ»¸öÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2021-32941£©£¬ÆäCVSSv3ÆÀ·ÖΪ9.4¡£
NVRÊÇÈκÎÁªÍø°²È«ÉãÏñ»úϵͳµÄÒ»¸ö³ÁÒª×é³É²¿ÃÅ£¬ËüÃDZ»Éè¼ÆÓÃÀ´×½Äᢴ洢ºÍÖÎÀíÀ´×ÔIPÉãÏñÍ·µÄ´«ÈëÊÓÆµÔ´¡£¸Ã·ì϶ÊÇAnnke N48PBB£¨NVR£©ÖлùÓÚ²Ö¿âµÄ»º³åÇøÒç¶Âí½Å£¬Î´¾Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓô˷ì϶½Ó¼ûÃô¸ÐÐÅÏ¢²¢ÒÔrootȨÏÞÖ´ÐÐËÁÒâ´úÂë¡£¹¥»÷ÕßÄܹ»ÀûÓô˷ì϶½Ó¼û¼ÔìµÄÊÓÆµ¡¢É¾³ý¾µÍ·¡¢¸ü¸ÄÅäÖú͹عØÄ³Ð©ÉãÏñ»úµÈ¡£
Ó°ÏìÁìÓò
N48PBB (NVR) <= V3.4.106 build 200422
0x02 ´ëÖý¨Òé
Ŀǰ´Ë·ì϶ÒѾ½¨¸´£¬½¨ÒéʵʱÉý¼¶¸üе½×îа汾¡£
ÏÂÔØÁ´½Ó£º
https://www.annke.com/pages/download-center
ͨÓð²È«½¨Òé
l ¾¡Á¿Ï÷¼õËùÓнÚÔìϵͳÉ豸»òϵͳµÄÍøÂç¶³öÇé¿ö£¬²¢È·±£ËüÃDz»ÄÜ´Ó»¥ÁªÍø½Ó¼û¡£
l ½«½ÚÔìÏµÍ³ÍøÂçºÍÔ¶³ÌÉ豸ÖÃÓÚ·À»ðǽ֮ºó£¬²¢½«ÆäÓëóÒ×ÍøÂç¸ôÀë¡£
l µ±±ØÒªÔ¶³Ì½Ó¼ûʱʹÓð²È«µÄ²½Ö裬ÈçÐ鹹רÓÃÍøÂ磨VPN£©£¬²¢È·±£VPNÊÇ×îа汾¡£
0x03 ²Î¿¼Á´½Ó
https://us-cert.cisa.gov/ics/advisories/icsa-21-238-02
https://www.nozominetworks.com/blog/new-annke-vulnerability-shows-risks-of-iot-security-camera-systems/
https://www.infosecurity-magazine.com/news/critical-iot-camera-flaw-allows/
0x04 ¸üа汾
°æ±¾ | ÈÕÆÚ | Åú¸ÄÄÚÈÝ |
V1.0 | 2021-08-30 | ³õ´Î°ä²¼ |
0x05 Îĵµ¸½Â¼
CNVD£ºwww.cnvd.org.cn
CNNVD£ºwww.cnnvd.org.cn
CVE£ºcve.mitre.org
NVD£ºnvd.nist.gov
CVSS£ºwww.first.org
0x06 ¹ØÓÚGA»Æ½ð¼×
¹Ø×¢ÒÔϹ«¼ÒºÅ£¬»ñÈ¡¸ü¶à×ÊѶ£º



¾©¹«Íø°²±¸11010802024551ºÅ